Auto-Deployment of SSL Certificates
Introduction
This article explains in detail how to use auto-deployment for SSL certificates. With auto-deployment, SSL certificates can be automatically deployed to the target servers both when they are issued and when they are renewed. For supported services, the respective service is then automatically restarted.
Prerequisites
- SSL certificate in the Customer Center
- Server with a supported service
- Domain / DNS zone managed via the Customer Center
Currently Supported Services for Auto-Deployment of SSL Certificates
- Plesk
- NGINX
- Apache2
- HaProxy
Setting Up Auto-Deployment of SSL Certificates
To set up auto-deployment, navigate to account.creoline.com in our Customer Center and go to Certificates → SSL Certificate for which you want to set up auto-deployment → Auto-Deployment.
You can then use the + Auto-Deployment button to set up auto-deployment for the desired certificate.
Setting Up Auto-Deployments
NGINX
If you are running a server with NGINX, you can select NGINX under Type and will receive the necessary information required to set up auto-deployment.
| Name | Custom name for the auto-deployment |
|---|---|
| Type | The service for which auto-deployment is to be set up |
| Target Server | The target server on which the SSL certificate is to be automatically installed |
| Path to Private Key File | Path to the private key (.key), located by default at the pre-filled path |
| Path to the certificate file | Path to the certificate file (.crt), located by default at the pre-filled path |
| Description | Customizable description for the auto-deployment |
The paths for the private key file and the certificate file are already pre-filled based on the selected type. If you want to use a different path, you can, of course, specify your own path here.
Plesk
If the SSL certificate is to be installed on a Plesk server, different settings are required compared to the NGINX type.
| Name | Custom name for the auto-deployment |
|---|---|
| Type | The service for which the auto-deployment is to be set up |
| Target Server | The target server on which the SSL certificate is to be automatically installed |
| Subscription | The subscription in the Plesk Control Panel under which the SSL certificate is to be installed |
| Protect Webmail | If Webmail is to be protected, the SSL certificate will also be used for webmail.* |
| Protect Emails | Not currently available |
| Description | Customizable description for the auto-deployment |
HaProxy
| Name | Customizable name for auto-deployment |
|---|---|
| Type | The service for which auto-deployment is to be configured |
| Target Server | The target server on which the SSL certificate is to be automatically installed |
| PEM File Path in the Certificate Pool | The path where the certificate is to be installed as a .pem file |
| Description | Customizable description for the auto-deployment |
The paths for the private key file and the certificate file are already pre-filled based on the selected type. If you want to use a different path, you can, of course, specify your own path here.
Run Now
If you want the deployment to run immediately, you can select the Run Now checkbox here so that the auto-deployment runs after you click the button. Alternatively, you can save the auto-deployment and run it at a time of your choosing.
Advantages of SSL Auto-Deployment
No longer requires an SSL installation service for the pre-selected services
If you have previously used our SSL installation service to install SSL certificates for, say, Plesk servers, this service is no longer required. The installation can be performed directly using our auto-deployment feature.
Faster and Easier Renewal and Subsequent Installation of the New Certificate
The process of renewing SSL certificates on the server has been simplified, so that after renewal, auto-deployment can be triggered to install the SSL certificate on the server in no time.
Auto-Deployment of Let’s Encrypt Certificates on Load Balancers
In the future, the introduction of this feature will also allow us to support Let’s Encrypt certificates on load balancers (HaProxy). The short 90-day validity period of Let’s Encrypt certificates can be easily circumvented through our automatic installation.