Configure ShangMi for HTTPS
Alibaba Cloud Dynamic Content Delivery Network (DCDN) provides the ShangMi for HTTPS feature for enhanced security. This topic describes how to enable ShangMi for HTTPS for an accelerated domain name.
Prerequisites
You have purchased and deployed an SM certificate on the SSL Certificates Service console. For more information, see Step 6.
NoteYou must purchase an SM certificate in the SSL Certificates Service console. You cannot upload a custom SM certificate.
You have configured an SSL certificate for your domain name. For more information, see Configure an SSL certificate.
Background information
ShangMi for HTTPS uses the SM2 elliptic curve public key cryptography algorithm and ShangMi security protocols. It establishes highly secure SSL-encrypted connections, authenticates server identities, and supports browsers that use ShangMi algorithms.
DCDN supports the SM2 (elliptic curve cryptography algorithm) and SM3 (hash algorithm) standards to provide enhanced security for HTTPS transmissions.
Supported cipher suites (used for ShangMi algorithm verification): ECC-SM2-WITH-SM4-SM3, ECDHE-SM2-WITH-SM4-SM3, and RSA-SM4-CBC-SM3.
ShangMi for HTTPS is supported only on the Linux operating system. If you use AliOS, you must deploy BabaSSL.
Procedure
Log on to the DCDN console.
In the left-side navigation pane, choose Content Delivery > Domain Names.
On the Domain Names page, find the domain name and click Configure in the Actions column.
In the navigation pane for the domain name, click HTTPS Settings.
In the ShangMi for HTTPS section, turn on ShangMi for HTTPS.
Optional: If the "No SSL certificate is available" message appears, click Buy and Configure Certificate and do the following:
Purchase a certificate on the SSL Certificates Service console.
Upload the certificate. For more information, see Upload, sync, and share SSL certificates.
Deploy the certificate. For more information, see Deploy an SSL certificate to an Alibaba Cloud service.
If the system detects an available certificate, select the certificate and click OK to enable ShangMi for HTTPS.
Optional: To disable ShangMi for HTTPS, turn off the ShangMi for HTTPS switch in the ShangMi for HTTPS section.
Related API
API |
Description |
Configures the SM certificate for a specified domain name. |
|
Queries the details of an SM certificate. |
|
Queries the SM certificates for a specified accelerated domain name. |