Automatic renewal of certificates

April 17, 2024

ID 267936

Automatic certificate renewal is available for certificates, that have connected resources.

Certificates are required for encrypted connection to web resources. Automatic renewal allows to issue a new TLS certificate for connected domain names without help of a technical specialist. Certificate s are issued by Let's Encrypt certificate authority. A new certificate is valid for 90 days and is automatically renewed in 32 days before the certificate expires.

Автообновление_сертификатов_1

A certificate is successfully automatically renewed if the following conditions are met:

  • All resources connected to the certificate have a TCP\80 filtering profile with a configured HTTP proxying protocol.
  • All domain names connected to the certificate have a DNS A record specifying the IP address issued by KDP.

It is possible to self-check for compliance with the conditions. To do this, follow these steps:

  1. Ensure that IP address specified in the resource settings is presented in DNS A records for all domain names.
  2. Ensure the configuration is correct. To do this, follow these steps:
    1. Navigate to the Resources section.
    2. Select the required resource.
    3. Navigate to the Settings tab.
    4. Click Download full config.
    5. In the downloaded .txt file, check for a filtering profile to which the certificate is connected.

If a user needs help enabling automatic certificate renewal, contact KDP Network Operations Service.

To enable automatic renewal of a certificate, follow these steps:

  1. For certificates which should be renewed, select the Автообновление_сертификатов_2 checkbox. The following pop-up window appears:

    Автообновление_сертификатов_3

  2. Click Continue. The certificate will be added to the list for automatic renewal.

In case of an error, the certificate is highlighted as follows:

Автообновление_сертификатов_4

To resolve the error, check that conditions for successful certificate renewal are met. After resolving the error, follow these steps:

  1. Click the Автообновление_сертификатов_5 button. A window with details about the certificate opens:

    Автообновление_сертификатов_6

  2. Click Renew certificate now. The certificate is renewed.

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.