Configure ShangMi for HTTPS

Updated at:

Alibaba Cloud Dynamic Content Delivery Network (DCDN) provides the ShangMi for HTTPS feature for enhanced security. This topic describes how to enable ShangMi for HTTPS for an accelerated domain name.

Prerequisites

  • You have purchased and deployed an SM certificate on the SSL Certificates Service console. For more information, see Step 6.

    Note

    You must purchase an SM certificate in the SSL Certificates Service console. You cannot upload a custom SM certificate.

  • You have configured an SSL certificate for your domain name. For more information, see Configure an SSL certificate.

Background information

  • ShangMi for HTTPS uses the SM2 elliptic curve public key cryptography algorithm and ShangMi security protocols. It establishes highly secure SSL-encrypted connections, authenticates server identities, and supports browsers that use ShangMi algorithms.

  • DCDN supports the SM2 (elliptic curve cryptography algorithm) and SM3 (hash algorithm) standards to provide enhanced security for HTTPS transmissions.

  • Supported cipher suites (used for ShangMi algorithm verification): ECC-SM2-WITH-SM4-SM3, ECDHE-SM2-WITH-SM4-SM3, and RSA-SM4-CBC-SM3.

  • ShangMi for HTTPS is supported only on the Linux operating system. If you use AliOS, you must deploy BabaSSL.

Procedure

  1. Log on to the DCDN console.

  2. In the left-side navigation pane, choose Content Delivery > Domain Names.

  3. On the Domain Names page, find the domain name and click Configure in the Actions column.

  4. In the navigation pane for the domain name, click HTTPS Settings.

  5. In the ShangMi for HTTPS section, turn on ShangMi for HTTPS.

  6. Optional: If the "No SSL certificate is available" message appears, click Buy and Configure Certificate and do the following:

    1. Purchase a certificate on the SSL Certificates Service console.

    2. Upload the certificate. For more information, see Upload, sync, and share SSL certificates.

    3. Deploy the certificate. For more information, see Deploy an SSL certificate to an Alibaba Cloud service.

  7. If the system detects an available certificate, select the certificate and click OK to enable ShangMi for HTTPS.

  8. Optional: To disable ShangMi for HTTPS, turn off the ShangMi for HTTPS switch in the ShangMi for HTTPS section.

Related API

API

Description

SetDcdnDomainSMCertificate

Configures the SM certificate for a specified domain name.

DescribeDcdnSMCertificateDetail

Queries the details of an SM certificate.

DescribeDcdnSMCertificateList

Queries the SM certificates for a specified accelerated domain name.