Let’s Encrypt is a certificate authority that is public, free, API-driven, and trusted by browsers/clients. Integrating Let's Encrypt certificate with SMA enhances the security and eases the deployment process. Let's Encrypt certificates are valid for 90 days and are renewed automatically after 60 days.
In addition, integrating Let's Encrypt certificate with SMA helps to obtain the appropriate SSL certificates when configuring and deploying CMS with GTO.
Let's Encrypt certificates can be configured for standalone and CMS/GTO deployments where CMS manages the Let’s Encrypt certificate(s) for the cluster.
Prerequisites:
Prerequisites:
To create a Let's Encrypt certificate in CMS
Click SSL Settings.
The SSL Settings page displays,
Under the SSL Certificates group, click Edit.
In the General tab, click + New and select Create Let's Encrypt certificateoption.
In the Fully qualified domain name field, enter the complete domain name. The FQDN entered here appears in the certificate and visible to users.
Wildcard characters are not supported in the FQDN field.
In the Alternatives names field, the SAN list is prepopulated for all the required domain names or enter any other name for FQDN. The alternative name entered here appears in the certificate using the SAN certificate extension.
Let's Encrypt supports up to 100 SANs per certificate.
In order to use the Let's Encrypt free certificate authority service, you must agree to their terms of service. Select I agree to the Let's Encrypt terms of service check box.
The Let's Encrypt certificate is created. You can view and modify the Let's Encrypt certificate.
To view the certificate
Navigate to Management Server > Configure.
Click SSL Settings.
The SSL Settings page displays,
Under the SSL Certificates group, click Edit.
In the General tab, under Certificate Usageoption.
Once you completed creating a Let's Encrpyt certificate, browse to the host name and ensure that the certificate is valid and verified
Click More information to view the validity period and other details.
The Let's Encrypt certificates are valid for 90 days and is renewed automatically after 60 days. You can also renew it manually based on your requirements.
To renew the certificate manually
Click Edit under the SSL Certificates group.
In the General tab, select the certificate you want to renew and click .
A success message is displayed and the certificate is renewed for the next 90 days. You can view the certificate validity displayed under Valid Through field.