Find answers to your eCDN proxy zone questions.
What is a CDN Proxy Zone?
cc-ecdn.net
What is a legacy zone?
A legacy zone, also known as a root zone, is a zone that includes the customer domain name. For example, brand.com.
How Do I determine if a zone is a root zone or a proxy zone?
In Business Manager, select
and find the hostname. If the DNS CNAME starts with commcloud the zone is a proxy zone.What problems does an eCDN Proxy Zone solve?
Proxy Zones are configured on a per instance level. Legacy zones were configured
at a domain name level. If you have multiple realms, you can assign different
hostnames to different realms. For example, you can manage the eCDN configurations
for us.mystore.com
and eu.mystore.com
separately.
All Proxy zones support auto renewing certificates. B2C Commerce merchants have the option to configure eCDN managed SSL certificates to auto-renew. Auto-renew keeps your certificates valid and makes managing eCDN on development, staging, and production instances easier.
On which B2C Commerce instance can I configure eCDN managed certificates?
You can configure eCDN Managed certificates for development, staging, and production instances.
How do eCDN legacy and proxy zones work together?
Both legacy and proxy zones can exist only in different realms and Cloudflare accounts. For example, if you have a legacy zone for brand.com in account A, and also created the proxy zone for the hostname in account B. The zones can’t co-exist in the same realm and cloudflare account.
To route traffic to the hostnames, both the legacy and proxy zones require an SSL certificate. In a proxy zone you’re required to specify the hostname when uploading the certificate. In a legacy zone the SSL certificate only serves the hostname that matches the SAN in the uploaded certificate.
What happens if I have a legacy root zone and proxy zone for the same hostname?
An SSL certificate is required for any hostname serving traffic in the proxy zone. Configure the proxy zone with a hostname, for example us.brand.com, and a valid SSL certificate.
You can upload a valid SSL certificate or use an eCDN managed auto renewing certificate.
Is there a limit to the number of certificates installed for root zones and proxy zones?
Root or Legacy zones (domain.com), are limited to four custom certificate slots per realm, shared between Production, Development, and Staging.
Proxy zones support both self-manage custom and eCDN Managed auto renewing SSL certificates for any of your sites. You can use a combination of up to five self-managed SSL certificates or eCDN managed auto-renewing certificates per realm at no additional cost.
Additional certificates in legacy or proxy zones have a monthly subscription cost. New terms will be discussed with you during your next contract renewal cycle.
Can I switch from self-managed custom SSL certificates to eCDN managed certificates in Proxy Zones?
If you have self-managed custom certificates, issued by a certificate authority, in a proxy zone, you can configure SSL certificates for automatic renewal in any zone within the realm. You can also continue to upload SSL certificates for development, staging, and production instances.
You can switch to eCDN managed auto renewing certificates or self-managed custom SSL certificates anytime.
You can configure self-managed SSL certificates, issued by a certificate authority, in Business Manager or with the CDN-API. You can configure eCDN managed only with the CDN-API.
Can I use eCDN managed certificates in eCDN Legacy or Root Zones?
No, The eCDN managed certificates feature is only available in eCDN proxy zones. All legacy zones, for example brand.com, require a custom certificate. You can use Business Manager to upload and renew a certificate before it expires.
When is eCDN Proxy Zone for Business Manager available?>
All new zones created after B2C Commerce 22.8 release by default are proxy zones.
Can I configure eCDN managed certificates in eCDN Proxy Zones via Business Manager UI?
No, Business Manager doesn’t support configuring eCDN Managed certificates.
How do I activate the eCDN Proxy Zone feature in Business Manager?
All merchants can create eCDN proxy zones. There are no additional steps required to activate or enable this feature.
Are there any requirements to qualify for the eCDN proxy zone?
There are no requirements to qualify for eCDN proxy zone.
How do I configure an eCDN proxy zone?
A progress message displays. The Proxy Zone is created on the Commerce Cloud Cloudflare account.
What are the steps to add eCDN managed certificates to my storefront custom hostnames?
What are the steps to switch from managed custom certificates to eCDN managed certificates?
What are the steps to add SSL certificates to the merchant’s storefront hostnames?
Can I update an existing certificate with a new certificate that covers existing and new hostnames?
For an existing hostname with a certificate, you can use the update certificate option to update the certificate.
If the hostname is removed from the merchant’s realm, does Salesforce remove a hostname from the SSL certificate?
No. if you removed a hostname from the alias file, Salesforce doesn't remove the hostname from a certificate.
Assuming I have a Cloudflare DNS, What DNS configuration changes do I make?
When do I update DNS changes on my Cloudflare Account to point to the eCDN?
Update your DNS settings on your Cloudflare account when you’re ready to go-live on your B2C Commerce production environment. To run tests before changing your production storefront hostname, you can update your DNS on your custom dev hostname.