Loading...

CDN.com.tr Help

Issue a certificate before switching DNS (zero downtime)

Get a valid wildcard certificate ready while your domain still points to the old provider, so HTTPS works from the first second after the DNS switch.

Issue a certificate before switching DNS (zero downtime)

Get a valid wildcard certificate ready while your domain still points to the old provider, so HTTPS works from the first second after the DNS switch.

Panel path

  1. Management Panel
  2. CDN
  3. Distribution Settings
  4. Domain row SSL shield
  5. Issue a new certificate — no downtime
  6. Add TXT record at current DNS provider
  7. Check propagation
  8. Verify and issue
  9. Automatic deploy

Use cases

A customer is about to move a live production domain behind CDN.com.tr and cannot accept the usual 5–15 minute HTTPS gap while the automatic certificate is issued after the switch.

Workflow

  1. Open Distribution settings and click the SSL shield on the domain row.
  2. Choose "Issue a new certificate — no downtime".
  3. The wizard finds the root domain on the account and prepares a wildcard certificate request covering all subdomains.
  4. Copy the DNS TXT record(s) shown by the wizard and add them at your current DNS provider. Two values under the same record name are normal — add both.
  5. Click Check Propagation until the records are confirmed (usually 1–15 minutes).
  6. Click Verify with Let's Encrypt, then Issue Certificate. The certificate deploys to the CDN edges automatically.
  7. Switch your DNS whenever you are ready; the domain is served over HTTPS immediately.

Checks

  • The TXT record name is always based on the root domain (for example `_acme-challenge.example.com`), even when you start from a subdomain.
  • The issued certificate is a wildcard covering the root domain and all first-level subdomains.
  • The certificate cannot renew automatically while DNS stays outside CDN.com.tr — re-run the wizard or move DNS before it expires (about 90 days).

Frequently asked questions

Why are there two TXT values with the same name?

A wildcard certificate needs two separate validations — one for the root domain and one for the wildcard. Both values must exist at the same time under the same record name; add them as two separate TXT records.

Check Propagation keeps failing — what should I check?

Confirm the record name matches exactly (no double prefixes), both values are published, and enough time passed for your DNS provider TTL. You can verify with `dig TXT _acme-challenge.example.com` or an online DNS lookup tool.

Does this work if my domain is already on CDN DNS?

If the domain is already fully transferred, you do not need this flow — Auto SSL issues and renews certificates without any manual TXT records.

Will the certificate renew automatically?

Not while your DNS is at another provider. Before the expiry date shown in the panel, either complete the Full DNS Transfer (renewal becomes automatic) or run this wizard again.

Related pages

Use Auto SSL

Let CDN.com.tr request and renew certificates after DNS and verification are ready.