- First, purchase the SSL certificate for either [web].mycompany.com or *.mycompany.com [web] is just an example of a CNAME but of course, the choice is up to you.
- Then, you will need to set up a CNAME within your domain provider's settings. For all regions, this CNAME needs to point to: cd-analytics.azurefd.net
- Once this is done, you will need to generate the SSL certificate and upload this certificate using the SSL Certificates option on the ClickDimensions Settings page.
- You can then enter your certificate's password (if it has one set) and enter the CNAME in the domain section so the one used in your SSL certificate (but not the *.mycompnay.com) to complete the upload process.
- Once you have filled in these fields, you will then have the option to 'Confirm and Add' your certificate and the state will show “Enabling - Deploying Certificate”
-
You should then be able to use HTTPS with Web Content using this CNAME 1 hour after this process completes and if you check the SSL Certificate settings it should show under the State Enabled - certificate deployed”
In the highlighted below section, the web content CNAME needs to be added:
e.g. web.mycompany.com
Important to know:
If you upload the certificate to multiple environments and remove the certificate, it will remove it from all orgs across all regions.
If you didn’t have the Web Content CNAME already set up within the domain record, AFTER the SSL certificate has been uploaded, you will then need to create a new Domain record for your CNAME in CRM for this process to complete properly (so the domain will be web.mycompany.com and don’t associate a CNAME to it).
Please note that this step must be done AFTER uploading the certificate as this will allow the certificate to process on our end
Wildcard certificates are supported, however, you must use a CNAME that points to cd-analytics.azurefd.net and does NOT contain a wildcard character in the domain field highlighted below (ex. *.clickdimensions.com cannot be used as the domain)
In addition, the certificate's validity period must be greater than 30 days, and the currently supported file types for your SSL certificate are:
- Pfx format contains one or more X509 certificate files.
- pem format is an archive file format for storing several cryptographic objects in a single file i.e. server certificate (issued for your domain), a matching private key, and may optionally include an intermediate CA
The pem file should contain a public or private key or both. To set up azure front door (service we using to enable HTTPS links with CNAMES) we need that private key. If your certificate is missing the private key, the certificate will fail to upload.
We currently do not support this SSL Subject Alternative Names
Supported CNAME and SSL CN Examples:
- SSL CN: *.mycompany.com
- CNAME: web.mycompany.com, survey.mycompany.com, form.mycompany.com etc.
- SSL CN: web.mycompany.com
- CNAME: web.mycompany.com
- SSL CN: *.web.mycompany.com
-
CNAME: survey.web.mycompany.com, form.web.mycompany.com
Once the SSL certificate is set up:
- You should re-save forms
- Then embed those forms again and make sure that
- Embed dialogue shows HTTPS link
- Form load and post as expected over HTTPS
- Re-save landing pages that host those forms - if any.
- Links in their respective websites will need to be changed to HTTPS.
Please note that if you have uploaded the same SSL certificate into multiple environments, then removing the SSL certificate from one environment will remove the certificate from ALL environments. Due to this, you may want to consider using a different set of certificates for the environments where applicable and check each of your environments after removing a certificate to ensure that all of the appropriate certificates are still present.
Please note: We bypass restrictions of subject line and manual upload certificate but we are working to check for alternative subject name.
FAQs
Which Certificate Authorities do we allow?
The allowed authorities are listed here. These certificate authorities are determined by Azure FrontDoor, which is a Microsoft Service utilized by Click for the creation of this service.
If I already have an existing Domain record in CRM with a Web Content alias, do I still need to create a new Domain record?
No, you do not need to create a new Domain record. Instead, you can simply purchase a certificate for that existing alias, point that CNAME alias to the cd-analytics.azurefd.net URL in your domain provider's settings, and then upload your certificate using the SSL Certificate option on the ClickDimensions Settings page.
| Feature Added: 2023.07 |
| Feature Updated: 2023.07 |
| Click Version Needed: 2023.07 |