CDN custom SSL
Certificates live with the distribution, not on a box you patch.
Origin certificates, forgotten renewals and mixed-content warnings still show up when TLS is treated as a server chore instead of part of delivery.
Map the hostname to Cloud CDN. Use a managed Let's Encrypt certificate or upload a custom certificate. Force HTTPS, control TLS versions and keep SNI explicit.
Why teams use Aptranet
What CDN custom SSL looks like on this network.
Cloud CDN caches and accelerates eligible content on 210+ points of presence, with Origin Shield when the origin must stay out of the way.
TLS 1.3 with 0-RTT
Modern transport on the public hostname, including HTTP/3.
Managed or custom certificates
Let's Encrypt for ordinary hostnames, custom SSL when you bring your own.
Forced HTTPS at the edge
Redirects happen before origin, so HTTP never needs to reach the app.
How to set it up
A cutover you can validate before DNS moves.
Create the Cloud CDN configuration, prove it on an Aptranet hostname, then point production DNS when the path looks correct.
- 1Map the custom domain
Add the hostname to the distribution.
- 2Choose managed or custom SSL
Managed Let's Encrypt, or upload the certificate you already operate.
- 3Force HTTPS
Redirect HTTP at the edge and set TLS version policy.
- 4Validate origin TLS
Cloud CDN can validate the origin over TLS as well.
Outcomes
What changes once the hostname is on Aptranet.
- The public certificate sits on Cloud CDN
- HTTP is redirected at the edge
- Custom certificates are supported
- Origin TLS can be validated independently
Keep reading
Related pages
More CDN use cases on the same Cloud CDN footprint.
Frequently Asked Questions
Yes. Upload a custom SSL certificate on the distribution.
Yes. Cloud CDN includes managed Let's Encrypt certificates.
Custom certificates can cover the names you need. Confirm the current managed-certificate coverage for wildcards before you depend on it.
Cloud CDN supports custom IP and ASN (BYOIP) when you need the hostname on addresses you announce.
