Yandex Cloud
Search
Discuss with expertTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
    • Cloud Interconnect
    • Cloud Backup
    • Cloud Registry
    • Yandex AI Studio
    • Compute Cloud
    • Object Storage
    • Managed Service for Kubernetes®
    • Yandex BareMetal
    • Smart Web Security
    • Security Deck
    • Managed Service for PostgreSQL
    • Managed Service for ClickHouse®
    • Monium
    • Cloud CDN
    • Network Load Balancer
    • Virtual Private Cloud
    • Cloud DNS
    • Application Load Balancer
    • Yandex Cloud Video
    • Stackland
    • Yandex Cloud Router
    • Yandex Managed Service for Trino
    • Managed Service for MySQL®
    • Managed Service for Valkey™
    • Managed Service for Apache Spark™
    • Yandex StoreDoc
    • Managed Service for OpenSearch
    • Managed Service for Apache Kafka®
    • Data Transfer
    • Yandex MPP Analytics Engine for PostgreSQL
    • Yandex Managed Service for Apache Airflow®
    • Data Processing
    • Yandex MetaData Hub
    • Managed Service for YDB
    • Managed Service for Sharded PostgreSQL
    • Managed Service for YTsaurus
    • Yandex WebSQL
    • DataLens
    • Yandex Search API
    • SpeechSense
    • SpeechKit
    • DataSphere
    • Vision OCR
    • Translate
    • Yandex Identity Hub
    • Key Management Service
    • Certificate Manager
    • Yandex Lockbox
    • Audit Trails
    • SmartCaptcha
    • Cloud Desktop
    • SourceCraft Code Assistant
    • Container Registry
    • Managed Service for GitLab
    • Managed Service for Prometheus®
    • Cloud Functions
    • API Gateway
    • Yandex Cloud Postbox
    • Message Queue
    • Serverless Integrations
    • IoT Core
    • Data Streams
    • Serverless Containers
    • Cloud Notification Service
    • Yandex Query
    • Identity and Access Management
    • Yandex Cloud Console
    • Resource Manager
    • Yandex Cloud Billing
    • Yandex Cloud Quota Manager
    • Cloud Apps
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Yandex Cloud CDN
    • Overview
    • Points of presence
    • Resource
    • Origins and origin groups
      • Overview
      • TLS certificates
      • CORS
      • Content compression
    • Request redirect
    • Content caching
    • Secure tokens
    • IP-based access policy
    • Dedicated IP addressing
    • Location rules
    • Log export
    • Labels
    • Quotas and limits
  • Access management
  • Pricing policy
  • Terraform reference
  • Metrics Monitoring
  • Request logs
  • Audit Trails events
  • Release notes
  • Troubleshooting

In this article:

  • TLS profiles
  • Domain ownership verification
  • Use cases
  1. Concepts
  2. Data exchange between clients and the CDN
  3. TLS certificates

Configuring TLS certificates for HTTPS connections between clients and the CDN

Written by
Yandex Cloud
Updated at July 20, 2026
View in Markdown
  • TLS profiles
  • Domain ownership verification
  • Use cases

To enable clients to request files over HTTPS (e.g., if you use a URI with the https scheme or enabled redirection from HTTP to HTTPS in the CDN resource settings), you need to configure a TLS certificate for the domain name used to distribute content specified in the resource.

Certificates from Yandex Certificate Manager are supported. You can issue a new Let's Encrypt® certificate or upload one of your own.

The certificate must be located in the same folder as your CDN resource.

The certificate is configured when creating a resource. You can change it afterwards together with other basic resource settings. For more information, see these guides:

  • Creating a resource
  • Updating the basic settings of a resource

TLS profilesTLS profiles

Cloud CDN supports TLS 1.0 and higher for client connections.

For added CDN resource security, configure a dedicated profile to restrict the allowed TLS versions.

Supported security profiles:

  • PROFILE_STRICT: Only TLS 1.3-compatible ciphers.

    Note

    All TLS 1.3 ciphers are considered secure.

  • PROFILE_SECURE: Ciphers compatible with TLS 1.2+ that support PFS (Perfect Forward Secrecy) and AEAD (Authenticated Encryption with Asssociated Data).

  • PROFILE_COMPATIBLE: Ciphers compatible with TLS 1.2+ that have no known critical vulnerabilities.

    This profile is used by default.

  • PROFILE_LEGACY: Ciphers compatible with TLS 1.0+ that have no known critical vulnerabilities.

You can customize this setting via the API when creating or updating a CDN resource. For more information, see Configuring a TLS profile for a CDN resource.

Domain ownership verificationDomain ownership verification

If you issued a Let's Encrypt certificate in Certificate Manager and use it in a CDN resource, you need to pass the domain ownership verification procedure. Cloud CDN supports only the DNS type verification with the help of a TXT or CNAME DNS record. The CDN load balancer will return the 404 status code in response to file requests over paths formatted as /.well-known/acme-challenge/<file_name> that are used for HTTP domain rights checks.

If you use a certificate of your own uploaded to Certificate Manager in a CDN resource, no domain rights check is required.

Use casesUse cases

  • Migrating to Yandex Cloud CDN from a third-party CDN provider
  • Providing secure access to content in Cloud CDN

Was the article helpful?

Previous
Overview
Next
CORS
© 2026 Direct Cursus Technology L.L.C.