This article describes how to install a storefront SSL certificate on the Salesforce Commerce B2C platform for storefront sites.
Environment: All PIG instances (Production, Development & Staging)
NOTE: This article does NOT apply to sandboxes because they do NOT currently support custom SSL certificates and only serve the default demandware.net certificate.
Before installing, choose your certificate type based on your zone configuration:
| Self-Managed Certificate | eCDN Managed Certificate | |
| Available for | All zone types (proxy and legacy) | Proxy zones only |
| Who manages renewal | Merchant | Salesforce / eCDN (auto-renewed) |
| CSR generation required | Yes | No |
| Private key required | Yes (PEM format, decrypted RSA) | No |
| Intermediate certificate required | No | No |
Your zone type determines which certificate options are available. To check:
Administration → Embedded CDN Settings| CNAME Pattern | Zone Type | eCDN Managed Cert Available? |
Starts with commcloud, ends with cc-ecdn.net | Proxy zone | Yes |
| Any other pattern | Legacy zone | No — self-managed only |
Legacy zone? Legacy zones can be migrated to proxy zones to gain access to eCDN managed certificates and other eCDN features. See the eCDN Proxy Zone FAQ for migration details.
If using a self-managed certificate, complete these preparation steps before uploading to Business Manager:
-----BEGIN CERTIFICATE----------BEGIN ENCRYPTED PRIVATE KEY-----), decrypt it using the following command:openssl pkcs8 -in key.pem -out rsakey.pem
This produces rsakey.pem — a decrypted RSA-format private key. Upload rsakey.pem (not key.pem) as the private key in Business Manager.
To verify your files are in the correct format before uploading:
# Verify certificate file
openssl x509 -in certificate.pem -text -noout
# Verify private key is decrypted and valid
openssl rsa -in rsakey.pem -check
Intermediate certificate: Business Manager does not have a field for intermediate certificates and one is not required. Upload only the certificate and private key.
Administration → Sites → Embedded CDN Settings
Follow the steps in Use the CDN Zones API to Configure eCDN.
getCertificates API command to retrieve the ID of the certificate to be replaced:GET /cdn/zones/{zone-id}/certificates
updateCertificate API command to install the new certificate:PUT /cdn/zones/{zone-id}/certificates/{certificate-id}
Business Manager (Administration → Embedded CDN Settings) does not include a field for intermediate certificates, and an intermediate certificate is not required. Upload only:
This is consistent with Cloudflare's certificate chain handling methodology, which B2C Commerce's eCDN uses.
Sandboxes do not support custom SSL certificate installation. Sandbox instances serve only the default *.demandware.net certificate provided by the platform. If you are testing HTTPS functionality on a Sandbox, use the demandware.net hostname directly rather than a custom domain.
If you need custom SSL support, deploy to a PIG instance (Development, Staging, or Production).
Issue: Certificate upload fails with "private key is encrypted" or similar error.
Cause: The private key file is still in encrypted PKCS#8 format rather than decrypted RSA format.
Resolution: Run the following command to decrypt the key before uploading:
openssl pkcs8 -in key.pem -out rsakey.pem
Upload rsakey.pem as the private key in Business Manager.
Issue: Certificate upload fails with a PEM format error.
Cause: The certificate or private key file is not in PEM format (e.g., it is in DER, PKCS#12/.pfx, or another binary format).
Resolution: Convert to PEM format using OpenSSL:
# Convert DER to PEM
openssl x509 -inform DER -in certificate.der -out certificate.pem
# Convert PKCS#12 to PEM (extracts cert and key separately)
openssl pkcs12 -in certificate.pfx -nokeys -out certificate.pem
openssl pkcs12 -in certificate.pfx -nocerts -nodes -out key.pem
Issue: Zone type check shows the CNAME does not end with cc-ecdn.net — eCDN managed certificate option is not available.
Cause: The storefront is on a legacy zone rather than a proxy zone.
Resolution: Use a self-managed certificate, or migrate the legacy zone to a proxy zone. See the eCDN Proxy Zone FAQ for migration instructions.
Issue: Certificate is installed but the storefront is still showing the old/default certificate.
Cause: DNS propagation may not be complete, or the old certificate has not been deleted from Business Manager.
Resolution: Wait for DNS propagation (typically up to 48 hours). If using Business Manager, confirm the old certificate has been deleted after the new one was installed.
A merchant is launching a new B2C Commerce storefront at www.example-store.com. In Business Manager under Administration → Embedded CDN Settings, they check their CNAME and confirm it ends with cc-ecdn.net, confirming they are on a proxy zone. Because they are on a proxy zone, they opt for an eCDN managed certificate — Salesforce manages provisioning and auto-renewal, so the merchant does not need to generate a CSR or manage a private key. They follow the Add Managed SSL Certificates steps in Business Manager and the certificate is provisioned within minutes.
A merchant's self-managed SSL certificate is expiring in 14 days. They generate a new CSR, obtain a new certificate from their CA, and attempt to upload the private key to Business Manager. The upload fails with an error about an encrypted key. The merchant runs openssl pkcs8 -in key.pem -out rsakey.pem to decrypt the key to RSA format, re-uploads rsakey.pem as the private key alongside the new certificate, and the installation succeeds. They then delete the old certificate from Business Manager.
A merchant contacts Support because they cannot find the "Add Managed SSL Certificate" option in Business Manager — only the self-managed option appears. Troubleshooting confirms that their CNAME does not end with cc-ecdn.net, meaning they are on a legacy zone. They have two options: use a self-managed certificate on their current legacy zone, or migrate to a proxy zone to gain access to eCDN managed certificates and auto-renewal.
000391588

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.