Skip to main content

Set up Let's Encrypt certificate

Follow these steps to create and use a Let’s Encrypt certificate:

  1. Navigate to Traffic Management, then select Traffic Configuration

  2. Create a new Traffic Configuration (HTTP Proxy with TLS disabled)

  3. Fill in the required fields in the form, with Port 80 as the Frontend Port. (These are the only fields you are required to fill in at this point).

    1. Name: The HTTP proxy service name
    2. Frontend IPv4: Your assigned Threat Protection Anycast IPv4
    3. Frontend IPv6: Your assigned Threat Protection Anycast IPv6
    4. Port: The Frontend Port (Port 80)
    5. Allowed Host Headers: The hostname (SNI) that will be allowed. For example: test.com and
      www.test.com
  4. Select Install

  5. Test the Traffic Configuration & Modify the DNS record (see step 3 and 4 in Configure new proxy)

  6. In the Threat Protection Portal navigate to Traffic Management, then select Certificate Management

  7. Choose New, then select Let’s Encrypt

  8. Fill in your Fully Qualified Domain Name

  9. Select Create

  10. When the certificate is installed, select to edit the newly created HTTP Proxy, change the Frontend Port to port 443 (from port 80), enable TLS, and use the new Let’s Encrypt certificate (as described in Step 2).

Certificate Management screenshot

Figure 1: Create Let's Encrypt Certificate