Skip to main content

TLS (SSL) Certificates for User Domains

To access objects in a bucket using a custom domain over HTTPS, you must add a TLS (SSL) certificate. You can manage certificates using the control panel or the User Certificates API.

You can issue a certificate from any provider. When using Servercore DNS hosting, you can quickly issue a Let’s Encrypt certificate, but after each Let’s Encrypt renewal, the certificate must be added manually.

The certificate is added at the country level: it will only work for buckets located in the region of the selected country. A single certificate cannot be used across multiple projects.

Only one certificate can be active for a single domain. If multiple certificates are added for a domain, the last uploaded one will be active. If the active certificate is deleted or expires, the previous one is automatically activated, but only if it has not expired.

TLS Protocol

The Transport Layer Security (TLS) protocol is a newer version of the SSL protocol and is used in conjunction with the HTTP protocol. Using HTTP and TLS together ensures data encryption, authentication, and integrity.

For your information

We recommend using TLS protocol version 1.2 or higher. Versions below 1.2 are deprecated (more details on the IETF website) and have not been supported by S3 since May 1, 2023.

You can view the TLS version in use in the logs.

Learn more about configuring TLS version 1.2 in the Amazon documentation:

Add certificate

You can add up to 100 certificates per project.

  1. In the control panel, in the top menu, click Products and select S3.

  2. Go to the SSL certificates section.

  3. Click Add certificate.

  4. Select the country for buckets in which the certificate will work.

  5. Enter a name for the certificate; it must be unique within the project.

  6. Add a primary certificate:

    -----BEGIN CERTIFICATE-----
    <certificate.crt>
    -----END CERTIFICATE-----

    Specify <certificate.crt> — private key in PKCS#1 format.

  7. Add a private key:

    -----BEGIN PRIVATE KEY-----
    <private_key.key>
    -----END PRIVATE KEY-----

    Specify <private_key.key> — private key in PKCS#1 format.

  8. Click Add certificate. The certificate will be activated within five minutes.

Certificate statuses

in progressThe certificate is being validated (up to five minutes). If validation is successful, the status will change to active, and in case of an error, to error
errorCertificate validation failed; to view the reason, hover over the status. Fix the error, delete the certificate and add it again
activeCertificate is active
expiredThe certificate has expired. Delete the certificate and add a new one

Delete certificate

You cannot delete certificates that are currently being added.

  1. In the control panel, in the top menu, click Products and select S3.
  2. Go to the SSL certificates section.
  3. In the certificate row, click .
  4. Enter the certificate name and click Delete.