Skip to content

Commit 1e05a6e

Browse files
committed
Merge branch 'patch-61' of https://github.com/jessie-jyy/azure-docs-pr into afd-cert
2 parents f6a0a74 + 5d6e4bd commit 1e05a6e

File tree

1 file changed

+8
-48
lines changed

1 file changed

+8
-48
lines changed

articles/cdn/cdn-custom-ssl.md

Lines changed: 8 additions & 48 deletions
Original file line numberDiff line numberDiff line change
@@ -54,10 +54,6 @@ Before you can complete the steps in this tutorial, create a CDN profile and at
5454

5555
Associate an Azure CDN custom domain on your CDN endpoint. For more information, see [Tutorial: Add a custom domain to your Azure CDN endpoint](cdn-map-content-to-custom-domain.md).
5656

57-
> [!IMPORTANT]
58-
> CDN-managed certificates are not available for root or apex domains. If your Azure CDN custom domain is a root or apex domain, you must use the Bring your own certificate feature.
59-
>
60-
6157
---
6258

6359
## TLS/SSL certificates
@@ -66,11 +62,13 @@ To enable HTTPS on an Azure CDN custom domain, you use a TLS/SSL certificate. Yo
6662

6763
# [Option 1 (default): Enable HTTPS with a CDN-managed certificate](#tab/option-1-default-enable-https-with-a-cdn-managed-certificate)
6864

69-
Azure CDN handles certificate management tasks such as procurement and renewal. After you enable the feature, the process starts immediately.
70-
71-
If the custom domain is already mapped to the CDN endpoint, no further action is needed. Azure CDN processes the steps and completes your request automatically.
65+
Using a certificate managed by Azure CDN allows you to enable HTTPS with a few settings changes. Azure CDN handles all certificate management tasks, including procurement and renewal. This is supported for custom domains with direct CNAME to Azure CDN endpoint.
66+
> [!IMPORTANT]
7267
73-
If your custom domain is mapped elsewhere, use email to validate your domain ownership.
68+
> - As of May 8, 2025, DigiCert no longer supports the WHOIS-based domain validation method. Hence, if your domains with indirect CNAME to Azure CDN endpoint, you must use the Bring your own certificate feature.
69+
> - Due to the WHOIS-based domain validation, managed certificate issued using WHOIS-based domain validation can't be auto renewed until you have direct CNAME pointed to Azure CDN.
70+
> - CDN-managed certificates are not available for root or apex domains. If your Azure CDN custom domain is a root or apex domain, you must use the Bring your own certificate feature.
71+
> - Managed certificate autorenewal requires that your custom domain be directly mapped to your CDN endpoint by a CNAME record.
7472
7573
To enable HTTPS on a custom domain, follow these steps:
7674

@@ -143,12 +141,6 @@ Follow the steps in [Configure managed identity for Azure CDN](managed-identity.
143141

144142
## Validate the domain
145143

146-
If you have a custom domain in use mapped to your custom endpoint with a CNAME record or you're using your own certificate, continue to [Custom domain mapped to your Content Delivery Network endpoint](#custom-domain-is-mapped-to-your-cdn-endpoint-by-a-cname-record).
147-
148-
Otherwise, if the CNAME record entry for your endpoint no longer exists or it contains the cdnverify subdomain, continue to [Custom domain not mapped to your CDN endpoint](#custom-domain-isnt-mapped-to-your-cdn-endpoint).
149-
150-
### Custom domain is mapped to your CDN endpoint by a CNAME record
151-
152144
When you added a custom domain to your endpoint, you created a CNAME record in the DNS domain registrar mapped to your CDN endpoint hostname.
153145

154146
If that CNAME record still exists and doesn't contain the cdnverify subdomain, the DigiCert CA uses it to automatically validate ownership of your custom domain.
@@ -166,44 +158,12 @@ Your CNAME record should be in the following format:
166158

167159
For more information about CNAME records, see [Create the CNAME DNS record](./cdn-map-content-to-custom-domain.md).
168160

169-
If your CNAME record is in the correct format, DigiCert automatically verifies your custom domain name and creates a certificate for your domain. DigitCert doesn't send you a verification email and you don't need to approve your request. The certificate is valid for one year and will be autorenewed before it expires. Continue to [Wait for propagation](#wait-for-propagation).
170-
171-
Automatic validation typically takes a few hours. If you don't see your domain validated in 24 hours, open a support ticket.
161+
If your CNAME record is in the correct format, DigiCert automatically verifies your custom domain name and creates a certificate for your domain. The certificate is valid for one year and will be autorenewed before it expires. Automatic validation typically takes a few hours. If you don't see your domain validated in 24 hours, open a support ticket.
162+
Continue to [Wait for propagation](#wait-for-propagation).
172163

173164
>[!NOTE]
174165
> If you have a Certificate Authority Authorization (CAA) record with your DNS provider, it must include the appropriate CAs for authorization. DigiCert is the CA for Azure CDN profiles. For information about managing CAA records, see [Manage CAA records](https://support.dnsimple.com/articles/manage-caa-record/). For a CAA record tool, see [CAA Record Helper](https://sslmate.com/caa/).
175166
176-
### Custom domain isn't mapped to your CDN endpoint
177-
178-
If the CNAME record entry contains the cdnverify subdomain, follow the rest of the instructions in this step.
179-
180-
DigiCert sends a verification email to the following email addresses. Verify that you can approve directly from one of the following addresses:
181-
182-
183-
184-
185-
186-
187-
188-
You should receive an email in a few minutes for you to approve the request. In case you're using a spam filter, add [email protected] to its allowlist. If you don't receive an email within 24 hours, contact Microsoft support.
189-
190-
:::image type="content" source="./media/cdn-custom-ssl/domain-validation-email.png" alt-text="Screenshot of the domain validation email.":::
191-
192-
When you select the approval link, you're directed to the following online approval form:
193-
194-
:::image type="content" source="./media/cdn-custom-ssl/domain-validation-form.png" alt-text="Screenshot of the domain validation form.":::
195-
196-
Follow the instructions on the form; you have two verification options:
197-
198-
- You can approve all future orders placed through the same account for the same root domain; for example, contoso.com. This approach is recommended if you plan to add other custom domains for the same root domain.
199-
200-
- You can approve just the specific host name used in this request. Another approval is required for later requests.
201-
202-
After approval, DigiCert completes the certificate creation for your custom domain name. The certificate is valid for one year. If the CNAME record for your custom domain is added or updated to map to your endpoint hostname after verification, then it will be autorenewed before it's expired.
203-
204-
>[!NOTE]
205-
> Managed certificate autorenewal requires that your custom domain be directly mapped to your CDN endpoint by a CNAME record.
206-
207167
## Wait for propagation
208168

209169
After the domain name is validated, it can take up to 6-8 hours for the custom domain HTTPS feature to be activated. When the process completes, the custom HTTPS status in the Azure portal is changed to **Enabled**. The four operation steps in the custom domain dialog are marked as complete. Your custom domain is now ready to use HTTPS.

0 commit comments

Comments
 (0)