Back to blog
Tencent CloudEdgeOneAuto-renewal

How to Auto-Renew SSL Certificates on Tencent Cloud CDN and EdgeOne

Tencent Cloud's free certificates have lasted only 90 days since April 2024, so certificates on CDN and EdgeOne need replacing four or five times a year. This guide compares EdgeOne's built-in free certificates, certificate hosting, your own scripts, and automation tools.

2026-10-057 min
Illustration of a 90-day Tencent Cloud free certificate being auto-renewed and deployed to CDN, EdgeOne, and load balancers

The Current Rules for Tencent Cloud Free Certificates

Since April 25, 2024, free certificates from Tencent Cloud's SSL Certificate Service have been valid for 3 months instead of 12, with a quota of 50 per account. They are single-domain DV certificates issued by TrustAsia, with no wildcard support. These rules come from the China site (cloud.tencent.com); the international site may differ.

The quota is generous. The number of replacements is what adds up. With a 90-day certificate replaced two or three weeks early, each domain needs a new certificate four or five times a year. For a domain on CDN, that means applying, waiting for validation, and swapping the certificate in the CDN console every time.

CDN and EdgeOne work differently, so they are covered separately below.

EdgeOne Only: Use Its Built-In Free Certificate

If your domain is already on EdgeOne, the simplest option is to choose "Apply for free certificate" in the domain's HTTPS settings. According to the official documentation, the certificate is issued by TrustAsia or Let's Encrypt, lasts 90 days, renews automatically 15 days before expiry, and deploys itself. There is nothing to maintain.

Its limits:

  • The certificate cannot be downloaded and only works on EdgeOne. If your origin or load balancer needs a certificate for the same domain, you have to get one separately.
  • Wildcard certificates require DNS delegation validation. After a site switches from NS access to CNAME access, its existing wildcard certificate cannot renew automatically.
  • With CNAME access and automatic validation, the domain must point its CNAME to EdgeOne within an hour, and split-horizon (per-line) DNS is not allowed.
  • No SLA. Certificates issued by Let's Encrypt do not support OCSP stapling.

If the certificate only ever lives on EdgeOne, none of this gets in your way. Use it and skip the rest of this article.

Tencent Cloud CDN: Certificate Hosting Only Handles Replacement

CDN has no one-click free certificate like EdgeOne. The usual flow is to get a certificate from the SSL Certificate Service and then deploy it to the CDN domain.

Tencent Cloud's certificate hosting covers half the work. Once enabled, when a new certificate is issued, it gets deployed at a time you choose to the cloud resources the old one was attached to, such as CDN and load balancers. Free certificates can be hosted too. The fully automatic setup in the docs is "auto-renewal plus hosting", and auto-renewal applies to paid certificates; the docs do not say that a free certificate will apply for its successor on its own. With free certificates, you still apply for a new one and complete validation every 90 days. Hosting only does the final swap.

Hosting has one more requirement: the old and new certificates must cover the same domains. Pick the wrong one and production is affected directly.

Writing Your Own Script

If you would rather not depend on the console, you can issue certificates yourself and deploy them through Tencent Cloud's API. Issuance is a solved problem: the dns_tencent plugin in acme.sh completes DNS validation through the DNSPod API and can get a wildcard certificate from Let's Encrypt.

Deployment is on you. The deploy directory in acme.sh has hooks for Alibaba Cloud CDN (ali_cdn.sh), Qiniu, and Baidu Cloud CDN, but none for Tencent Cloud. Calling the API yourself, you upload the certificate to the SSL Certificate Service to get a certificate ID, then bind it to CDN or EdgeOne:

text
# 1. Upload the certificate. With Repeatable=false, an identical certificate
#    is not uploaded twice; the existing ID is returned instead.
ssl.UploadCertificate
  CertificatePublicKey  = contents of fullchain.pem
  CertificatePrivateKey = contents of privkey.pem
  Repeatable            = false

# 2a. Tencent Cloud CDN: update only the certificate ID path
cdn.ModifyDomainConfig
  Domain = cdn.example.com
  Route  = Https.CertInfo.CertId
  Value  = {"update":"<certificate ID from step 1>"}

# 2b. EdgeOne: swap the certificate on the acceleration domain
teo.ModifyHostsCertificate
  ZoneId         = <zone ID>
  Hosts          = ["www.example.com"]
  Mode           = sslcert
  ServerCertInfo = [{"CertId":"<certificate ID>"}]

The CDN step is easy to get wrong. If you call UpdateDomainConfig with an Https object that contains only the certificate and private key, you run into this rule from the API documentation: for complex configuration items, "you must pass all properties of the object; properties not passed will use default values." In other words, HSTS, OCSP stapling, and TLS version restrictions that were enabled on the domain get reset to defaults on every renewal. ModifyDomainConfig updates a single path and leaves everything else unchanged, which makes it the safer call for swapping certificates.

Updating only Https.CertInfo.CertId assumes HTTPS is already enabled on the domain. If it is not, changing the certificate ID alone has no effect, and setting Https.Switch to on by itself is rejected because there is no certificate yet. In that case, set Route to Https and Value to {"update":{"Switch":"on","CertInfo":{"CertId":"<certificate ID>"}}}. Your script can check Https.Switch with DescribeDomainsConfig first and pick the right call.

Once the script works, you still need scheduling, retries, and alerting. Use a CAM sub-user for credentials, with permissions limited to DNSPod, SSL certificate upload, and CDN / EdgeOne configuration.

Ways to Stop Replacing Certificates by Hand

OptionGood forCost
EdgeOne free certificateEdgeOne onlyNo download, wildcard limits
SSL Service + hostingCertificates on Tencent onlyFree certs still applied by hand
acme.sh + your own scriptTeams happy to own codeDeploy, retry, alerts all on you
Self-hosted CertimateFully open source setupsYou deploy, upgrade, back up
Hosted automation serviceNothing to maintainCloud credentials held by them

Certimate is an MIT-licensed open-source project. Once self-hosted, it issues certificates and deploys them to Tencent Cloud CDN, EdgeOne, CLB, COS, and more, along with Alibaba Cloud and other providers. Certificates, private keys, and cloud credentials stay on your own server; the trade-off is that you maintain that server and Certimate itself.

With only one or two CDN domains, replacing certificates by hand looks manageable. But four or five times a year, someone has to remember every time, and eventually nobody will. If you can automate it for free, it is worth setting up even for a few domains.

Auto-Renewing and Deploying to Tencent Cloud with LapseZero

LapseZero is a hosted certificate automation service. It issues certificates from Let's Encrypt, renews them before expiry, and deploys them to cloud products on Alibaba Cloud, Tencent Cloud, and AWS, or to your own servers. On Tencent Cloud it currently supports CDN, EdgeOne, and HTTPS listeners on CLB load balancers.

  1. Add the domain. If DNS is on DNSPod, provide keys for a CAM sub-user with DNS permissions only, and the platform writes the validation records. If you would rather not hand over DNS access, use DNS delegation, which only needs CNAME records added once, when you add the domain. The differences are covered in HTTP-01 vs DNS-01 vs DNS delegation.
  2. Issue the certificate. Wildcards are supported, and Tencent Cloud's 50-certificate quota is not touched.
  3. Add deploy targets. The platform lists the CDN domains and EdgeOne acceleration domains in your account; select the ones that match the certificate. The same certificate can go to CDN, CLB, and your own servers at once.
  4. Renew automatically. By default it renews 30 days before expiry and deploys to every target after issuance. Each target's result is recorded separately, and failures are sent to you by email, Slack, Telegram, or other channels.

Two things to know. A successful deployment means Tencent Cloud's API accepted the new certificate; the platform does not visit the domain afterwards to confirm it is live, and CDN edge nodes take time to pick it up, so check it a little later with the SSL certificate expiry checker. Your cloud credentials are stored by the platform, so use a CAM sub-user with minimal permissions. The free plan includes 3 domains and 5 deploy targets.

Certificate lifetimes keep shrinking: from March 15, 2027, every public certificate maxes out at 100 days, and 47 days from 2029, paid certificates included. See 47-day SSL certificates.

Auto-renew certificates on Tencent Cloud CDN and EdgeOne
LapseZero issues free certificates with wildcard support, renews them before expiry, and deploys to Tencent Cloud CDN, EdgeOne, and CLB, as well as Alibaba Cloud, AWS, and your own servers. Start on the free plan.
Get started free