Skip to content

Custom TLS certificates with a non-VIP CSR

To install a custom TLS certificate for a domain with a CSR that was not generated by VIP, customers must have in their possession a complete certificate chain generated by a Certificate Authority (CA).

A complete certificate chain includes:

Prerequisite

Access the custom certificate installer

  1. Navigate to the VIP Dashboard.
  2. Select the environment that the domain points to (e.g., Production, Develop) from the dropdown located at the upper left of the dashboard.
  3. Select “Domains & TLS” from the sidebar navigation at the left of the screen.
  4. Add the domain by selecting the “Add Domain” button in the upper right if it does not yet appear in the Domains list.
  5. A button labeled “Install Certificate” will be displayed to the right of newly added domains in the Domains & TLS panel.
  6. Select the “Install Certificate” button to access and select the “Custom Certificate” option in the dropdown.
  7. Select the text “Have your own CSR and Private Key?” near the top of the screen.
Screenshot of the text Have your own CSR and Private Key?” near the top of the screen

Upload a certificate chain

To populate the “Upload a Certificate Chain” fields with all four parts of the complete certificate chain, a user can either “Copy and paste” or “Upload a PEM file”.

Copy and paste

For customers who have obtained separate files for all four parts of the complete certificate chain:

  1. Open the complete certificate chain files in a text editor.
  2. One at a time, copy the contents of a complete certificate chain file from the text editor and paste the contents into its corresponding field.
  3. Repeat for all four files.
  4. Select “Upload“.

Upload a PEM file

For customers who have obtained a single PEM file that contains all four parts of the complete certificate chain:

  1. Select the linked text “Select a PEM file“.
  2. Select the file source from the local machine.
  3. Select “Upload“.
Screenshot example of the fields for the four parts of a complete certificate chain

Activate a custom certificate

The installation of a TLS certificate is not complete until it has been activated for a domain.

Choose your domains

After uploading a certificate chain:

  1. Select the dropdown below the “Domains” label.
  2. Select the domain for which the new custom TLS certificate is being installed.
  3. Select “Activate Certificates“.
Screenshot of the “Choose your domains” step and the “Activate Certificates” button in the VIP Dashboard

Confirm the certificate is working

  • New TLS certificates may require up to 10 minutes to be enabled for a domain.
  • Use a free online TLS testing tool such as SSLShopper or DigiCert.
  • Browsers such as Firefox and Chrome provide tools for checking if a site’s connection is secure.

Last updated: December 22, 2023

Relevant to

  • Node.js
  • WordPress