Find the desired product help

SSL Configuration

 

  • Select a website from the drop-down at top-left and choose 'SSL'
          • SSL/TLS certificates identify a website’s owner, and encrypt all data that passes between the site and a visitor's browser.

            • Sites that use an SSL/TLS certificate have a URL that begins with HTTPS. For example, https://www.example.com.
            • Comodo strongly recommends you use a certificate on your site.

            There are two ways to deploy a certificate with cWatch Web:

            • Bring your own SSL
              • Upload your site’s existing certificate to the cWatch CDN edge servers. Recommended for most customers.

                • This will secure the traffic between your site (the origin server) and the cWatch CDN.
                • Complimentary Comodo SSL
                • Get a free SSL from Comodo deployed on the CDN Edge servers. Again, this will encrypt traffic between your site and the CDN
                • You need to configure your site to use Comodo DNS in order to get the free SSL certificate. There are two ways you can do this:
                1. Change your domain's authoritative DNS servers to Comodo DNS

                2. Enter DNS records explicitly

                  Upload your own SSL Certificate

                  • Open the cWatch dashboard
                  • Select the target website from the menu at top-left
                  • Click the 'SSL' tab




                  • Click 'Order SSL Certificate' if you do not already have a certificate on your site

                  • You will be taken to SSL purchase page to buy a new certificate
                  • You can install the certificate on your web-server then upload it to cWatch
                  • Click 'Upload Your SSL Certificate' to submit your existing certificate:



                   

                  Upload Your Certificate - Form Parameters

                  Parameter

                  Description

                  Certificate

                  Paste the content of your certificate. The content you are looking for is something like this:

                  –––––BEGIN CERTIFICATE–––––

                   

                  MIICUTCCAfugAwIBAgIBADANBgkqhkiG9w0BAQQFADBXMQswCQYDVQQGEwJDTjEL
                  MAkGA1UECBMCUE4xCzAJBgNVBAcTAkNOMQswCQYDVQQKEwJPTjELMAkGA1UECxMC
                  VU4xFDASBgNVBAMTC0hlcm9uZyBZYW5nMB4XDTA1MDcxNTIxMTk0N1oXDTA1MDgx
                  NDIxMTk0N1owVzELMAkGA1UEBhMCQ04xCzAJBgNVBAgTAlBOMQswCQYDVQQHEwJD
                  TjELMAkGA1UEChMCT04xCzAJBgNVBAsTAlVOMRQwEgYDVQQDEwtIZXJvbmcgWWFu
                  ZzBcMA0GCSqGSIb3DQEBAQUAA0sAMEgCQQCp5hnG7ogBhtlynpOS21cBewKE/B7j
                  V14qeyslnr26xZUsSVko36ZnhiaO/zbMOoRcKK9vEcgMtcLFuQTWDl3RAgMBAAGj
                  gbEwga4wHQYDVR0OBBYEFFXI70krXeQDxZgbaCQoR4jUDncEMH8GA1UdIwR4MHaA
                  FFXI70krXeQDxZgbaCQoR4jUDncEoVukWTBXMQswCQYDVQQGEwJDTjELMAkGA1UE
                  CBMCUE4xCzAJBgNVBAcTAkNOMQswCQYDVQQKEwJPTjELMAkGA1UECxMCVU4xFDAS
                  BgNVBAMTC0hlcm9uZyBZYW5nggEAMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQEE
                  BQADQQA/ugzBrjjK9jcWnDVfGHlk3icNRq0oV7Ri32z/+HQX67aRfgZu7KWdI+Ju
                  Wm7DCfrPNGVwFWUQOmsPue9rZBgO

                  –––––END CERTIFICATE–––––

                  SSL Chain Certificate

                  If your certificate contains an intermediate certificate then paste it here. If not, leave this field blank.

                  Certificate Key

                  Private key of your certificate


                  • Click 'Upload Your SSL Certificate'

                  The SSL certificate will be uploaded to the CDN edge servers.



                  Once uploaded, traffic between the CDN and your website visitors is encrypted. Since the certificate is already installed on your site, the communication between the origin and the CDN is also encrypted.


                  Install Complementary SSL Certificate

                  • Open the cWatch dashboard
                  • Select the target website from the menu at top-left
                  • Click the 'SSL' tab
                  • Scroll down to 'Complimentary Comodo SSL (Edge Certificate)':



                   

                  You have two options to enable the free certificate:


                  Option A - Change your domain's authoritative DNS servers to Comodo

                   

                  Prerequisite –  You have configured the site to use Comodo DNS by adding the name server (NS) records.

                  • The NS records are available in 'CDN' > 'Settings' > 'Activation', and in the 'DNS' pages of the site.

                  See Activate CDN for a Website and DNS Configuration for more details.

                  • Scroll to 'Option A - Change your domain's authoritative DNS servers to Comodo'
                  • Select 'Click here for more details'



                  • Click the 'Activate Basic SSL Now' button
                  • The process will take a few minutes to complete
                  • Once activated, you can see the certificate in 'Settings' > 'SSL', listed under 'Complimentary Comodo SSL (Edge Certificate)'.



                  • The certificate is valid for one year and is set for auto-renewal.
                  • Note – This certificate encrypts the connection between the CDN servers, which host a copy of your site, and your website visitors.
                  • It does not encrypt the traffic between your web-server and the CDN edge servers.

                  Option B - Create CNAME record pointed back to Comodo

                  • Scroll to 'Option B - Create CNAME record pointed back to Comodo'
                  • Select 'Click here for more details'
                  • Select 'Click here for more details' beside 'Option B - Create CNAME record pointed back to Comodo'




                  • Click the 'Activate Basic SSL Now' button:




                  cWatch generates a CNAME record for domain control validation.

                  • Note down the 'CNAME KEY' and 'CNAME VALUE' records
                  • Go to your website's DNS management page and enter the 'CNAME KEY' and 'CNAME VALUE' records
                  • After the CNAME records are added to your domain's DNS settings, the certificate will be activated and deployed to the edge servers. It may take up to two hours to complete.

                  Once activated, you can see the certificate listed under 'Complimentary Comodo SSL (Edge Certificate)'.




                  • Note - This certificate encrypts the connection between the CDN servers, which host a copy of your site, and your website visitors.
                  • It does not encrypt the traffic between your web-server and the CDN servers.
                  • You need to upload your own certificate to encrypt CDN <--> origin site traffic. See 'Upload your own SSL Certificate' for more details. See 'Upload your own SSL Certificate' for more details.