Loading
시스템 관리자에 대한 피싱 방지 MFA 및 전 직원사용자 MFA 적용 안내 더 많이 읽기

Install a SSL Certificate on B2C Commerce

게시 일자: Jul 30, 2026
상세 설명

This article describes how to install a storefront SSL certificate on the Salesforce Commerce B2C platform for storefront sites.

 

Environment: All PIG instances (Production, Development & Staging)

 

NOTE: This article does NOT apply to sandboxes because they do NOT currently support custom SSL certificates and only serve the default demandware.net certificate.

솔루션

Certificate Type Comparison

Before installing, choose your certificate type based on your zone configuration:

Self-Managed CertificateeCDN Managed Certificate
Available forAll zone types (proxy and legacy)Proxy zones only
Who manages renewalMerchantSalesforce / eCDN (auto-renewed)
CSR generation requiredYesNo
Private key requiredYes (PEM format, decrypted RSA)No
Intermediate certificate requiredNoNo

 

Step 1 — Determine Your Zone Type

Your zone type determines which certificate options are available. To check:

  1. In Business Manager, navigate to Administration → Embedded CDN Settings
  2. Locate the DNS CNAME value for your storefront hostname
  3. Evaluate the CNAME:
CNAME PatternZone TypeeCDN Managed Cert Available?
Starts with commcloud, ends with cc-ecdn.netProxy zoneYes
Any other patternLegacy zoneNo — self-managed only

 

Legacy zone? Legacy zones can be migrated to proxy zones to gain access to eCDN managed certificates and other eCDN features. See the eCDN Proxy Zone FAQ for migration details.

 

Step 2 — Prepare Your Certificate (Self-Managed Only)

If using a self-managed certificate, complete these preparation steps before uploading to Business Manager:

  1. Generate a Certificate Signing Request (CSR) using a CSR generator tool
  2. Submit the CSR to your Certificate Authority (CA) of choice and obtain the signed certificate
  3. Ensure the certificate file is in PEM format — PEM files begin with -----BEGIN CERTIFICATE-----
  4. Ensure the private key is in PEM format and decrypted in old RSA format. If your private key is encrypted (i.e., it begins with -----BEGIN ENCRYPTED PRIVATE KEY-----), decrypt it using the following command:
openssl pkcs8 -in key.pem -out rsakey.pem

This produces rsakey.pem — a decrypted RSA-format private key. Upload rsakey.pem (not key.pem) as the private key in Business Manager.
To verify your files are in the correct format before uploading:

# Verify certificate file
openssl x509 -in certificate.pem -text -noout

# Verify private key is decrypted and valid
openssl rsa -in rsakey.pem -check

 

Intermediate certificate: Business Manager does not have a field for intermediate certificates and one is not required. Upload only the certificate and private key.

 

Install via Business Manager

New SSL Certificate Installation

  1. Review the Configure the Embedded CDN topic to ensure eCDN prerequisites are complete
  2. Complete the Configure the eCDN Hostname Alias and Create a Zone in B2C Commerce steps
  3. Prepare your certificate files per Step 2 above (self-managed only)
  4. In Business Manager, navigate to Administration → Sites → Embedded CDN Settings
  5. Choose your installation path:
    1. Self-managed certificate: Follow the Add Self-Managed SSL Certificates steps
    2. eCDN managed certificate (proxy zones only): Follow the Add Managed SSL Certificates steps
  6. Complete the remaining steps: Configure a Zone for B2C Commerce and Add Hostnames (Subdomains)

SSL Certificate Renewal

  1. Follow the instructions in Update an eCDN Zone's Certificate
  2. After the new certificate is installed and confirmed active, delete the old/replaced certificate from Business Manager

 

Install via CDN API

New SSL Certificate Installation

Follow the steps in Use the CDN Zones API to Configure eCDN.

SSL Certificate Renewal

  1. Use the getCertificates API command to retrieve the ID of the certificate to be replaced:
GET /cdn/zones/{zone-id}/certificates
  1. Use the updateCertificate API command to install the new certificate:
PUT /cdn/zones/{zone-id}/certificates/{certificate-id}
  1. For realms created prior to June 2023: complete the post-migration steps to validate eCDN traffic flow and setup after renewal.

 

Intermediate Certificate Policy

Business Manager (Administration → Embedded CDN Settings) does not include a field for intermediate certificates, and an intermediate certificate is not required. Upload only:

  • The signed certificate (PEM format)
  • The private key (PEM format, decrypted RSA)

This is consistent with Cloudflare's certificate chain handling methodology, which B2C Commerce's eCDN uses.

 

Sandbox Limitation

Sandboxes do not support custom SSL certificate installation. Sandbox instances serve only the default *.demandware.net certificate provided by the platform. If you are testing HTTPS functionality on a Sandbox, use the demandware.net hostname directly rather than a custom domain.
If you need custom SSL support, deploy to a PIG instance (Development, Staging, or Production).

 

Troubleshooting

Issue: Certificate upload fails with "private key is encrypted" or similar error.
Cause: The private key file is still in encrypted PKCS#8 format rather than decrypted RSA format.
Resolution: Run the following command to decrypt the key before uploading:

openssl pkcs8 -in key.pem -out rsakey.pem

Upload rsakey.pem as the private key in Business Manager.


Issue: Certificate upload fails with a PEM format error.
Cause: The certificate or private key file is not in PEM format (e.g., it is in DER, PKCS#12/.pfx, or another binary format).
Resolution: Convert to PEM format using OpenSSL:

# Convert DER to PEM
openssl x509 -inform DER -in certificate.der -out certificate.pem

# Convert PKCS#12 to PEM (extracts cert and key separately)
openssl pkcs12 -in certificate.pfx -nokeys -out certificate.pem
openssl pkcs12 -in certificate.pfx -nocerts -nodes -out key.pem

Issue: Zone type check shows the CNAME does not end with cc-ecdn.net — eCDN managed certificate option is not available.
Cause: The storefront is on a legacy zone rather than a proxy zone.
Resolution: Use a self-managed certificate, or migrate the legacy zone to a proxy zone. See the eCDN Proxy Zone FAQ for migration instructions.


Issue: Certificate is installed but the storefront is still showing the old/default certificate.
Cause: DNS propagation may not be complete, or the old certificate has not been deleted from Business Manager.
Resolution: Wait for DNS propagation (typically up to 48 hours). If using Business Manager, confirm the old certificate has been deleted after the new one was installed.

Real-World Scenarios

Scenario 1 — New proxy zone storefront going live with eCDN managed certificate

A merchant is launching a new B2C Commerce storefront at www.example-store.com. In Business Manager under Administration → Embedded CDN Settings, they check their CNAME and confirm it ends with cc-ecdn.net, confirming they are on a proxy zone. Because they are on a proxy zone, they opt for an eCDN managed certificate — Salesforce manages provisioning and auto-renewal, so the merchant does not need to generate a CSR or manage a private key. They follow the Add Managed SSL Certificates steps in Business Manager and the certificate is provisioned within minutes.

Scenario 2 — Self-managed certificate renewal with encrypted private key failure

A merchant's self-managed SSL certificate is expiring in 14 days. They generate a new CSR, obtain a new certificate from their CA, and attempt to upload the private key to Business Manager. The upload fails with an error about an encrypted key. The merchant runs openssl pkcs8 -in key.pem -out rsakey.pem to decrypt the key to RSA format, re-uploads rsakey.pem as the private key alongside the new certificate, and the installation succeeds. They then delete the old certificate from Business Manager.

Scenario 3 — Legacy zone merchant cannot find eCDN managed certificate option

A merchant contacts Support because they cannot find the "Add Managed SSL Certificate" option in Business Manager — only the self-managed option appears. Troubleshooting confirms that their CNAME does not end with cc-ecdn.net, meaning they are on a legacy zone. They have two options: use a self-managed certificate on their current legacy zone, or migrate to a proxy zone to gain access to eCDN managed certificates and auto-renewal.

추가 자원
Knowledge 기사 번호

000391588

 
로드 중
Salesforce Help | Article