Updating SSL certificates in Adobe Experience Manager with staged validation

To reduce the risk of service disruption, deploy and validate a new SSL certificate in a staging environment before updating it in production for a domain in Adobe Experience Manager (AEM).

Description description

Environment

Adobe Experience Manager (AEM)

Issue/Symptoms

Applying a new SSL certificate directly to a production environment carries a risk of service disruption if a problem with the certificate isn’t caught beforehand. Validating the certificate in a staging environment first reduces this risk.

Resolution resolution

A certificate file in PFX format and the corresponding install passcode are required for this process.

Update the SSL certificate using a staged validation approach:

  1. Obtain the new SSL certificate file for your domain in PFX format, along with the install passcode.
  2. If the certificate file has a .txt extension, remove it so the file ends with .pfx.
  3. Import the new certificate into your AEM staging environment using the standard SSL certificate import process for your deployment model.
  4. Restart or reload the relevant AEM services to apply the new certificate in staging.
  5. Validate and test the staging environment to ensure the new certificate is functioning as expected.
  6. Once validation is successful, repeat the import and application steps for your AEM production environment.
  7. Confirm that the production environment is operating correctly with the new certificate.
  8. Monitor both environments and report any issues if they arise.
recommendation-more-help
experience-cloud-kcs-help-kbarticles