Picture of Manage SSL Certificates & Domain Bindings in Infigo Admin

Manage SSL Certificates & Domain Bindings in Infigo Admin

The Certificate Management area in Infigo Admin lets you create, upload, renew, and delete SSL certificates and control which domains they’re bound to—directly from the UI. This replaces slow, manual infrastructure requests with a guided, self-service workflow.

Key points

  • Centralized & platform-wide: One certificate pool for the entire platform (shared across all storefronts).

  • Access via Support: Access is controlled by an internal permission. Request access from Support and they’ll enable it for you.

  • Capacity-aware UI: The list shows how many free certificate slots remain.

  • Health indicators: The Status field reflects certificate health (e.g., active, expiring soon, expired, pending application).

  • Bindings: Manage domain bindings per certificate (add/delete).

  • Connection info: Quickly view the CNAME and IP to point your DNS.

  • CSR support: Generate a Certificate Signing Request to procure a new certificate from your CA.

Behind the scenes, requests are handled by a secure proxy that runs scripts to apply changes. Any action can error; the UI will surface the details so you can resolve them.


Key Settings

  • If you don’t currently have access to Certificate Management, contact Support to enable it for your account.

  • Platform scope: Certificates are managed for the whole platform. A single certificate can cover multiple domains/storefronts if the SANs match.

  • Capacity limits: Your maximum number of certificates is limited by platform constraints. If you hit capacity, contact Support to review options.

  • Certificate actions available:

    • Add Certificate (upload certificate + private key)

    • CSR (enter details to generate a CSR)

    • Edit certificate (name, description, contacts)

    • Update certificate (upload a renewed/reissued certificate)

    • Delete certificate (remove the entry)

    • Manage Bindings (per domain: add/delete)

  • Displayed certificate info:

    • Name (required)

    • Description (required)

    • Certificate info (required, text/file)

    • CSR (optional downloadable text if generated)

    • Contact (required, email/text)

    • Status (string)

    • Connection info (CNAME + IP via popup)

    • Domains list is not shown here; manage via Manage Bindings.


Use Cases

  1. Upload an existing certificate + private key you already purchased from a CA.

  2. Generate a CSR in Admin, submit it to your CA, then upload the issued certificate.

  3. Renew an expiring certificate flagged as “expiring soon” using Update certificate.

  4. Bind a domain to a certificate after confirming the cert covers that domain, then update DNS to point to the provided CNAME/IP.


Step-by-Step Implementation Guide

1) Get access (one-time)

  1. If Certificate Management isn’t visible in Admin, contact Support and request access for your user(s).

  2. Once Support enables it, sign in and open Certificate Management.

You’ll see a list of managed certificates and a Free slots indicator.


2) Add a certificate (upload certificate + private key)

  1. In Certificate Management, select Add Certificate (button appears only if a free slot is available).

  2. Complete all required fields:

    • Name – A clear internal label.

    • Description – Purpose/context (e.g., covered domains).

    • Certificate info – Provide the certificate as required by the UI.

    • Contact – Email or text contact for notifications/follow-up.

  3. Upload the private key when prompted (must match the certificate).

  4. Submit. The new certificate appears with a Status reflecting its current state.


3) Create a CSR (to obtain a new certificate)

  1. Select CSR.

  2. Fill in the required details (e.g., Common Name, Organization, Country—fields shown in the UI).

  3. Generate the CSR.

  4. Use Download CSR to get the CSR text and submit it to your Certificate Authority.

  5. When your CA issues the certificate, return to the entry and choose Update certificate to upload the issued certificate.


4) Edit certificate metadata

  1. From the list, click Edit certificate.

  2. Update Name, Description, and Contact.

  3. Save.


5) Update (renew/reissue) a certificate

  1. On the target certificate, select Update certificate.

  2. Upload the renewed/reissued certificate (follow UI prompts).

  3. Save and monitor Status until healthy.


6) Delete a certificate

  1. Select Delete certificate on the entry.

  2. Confirm deletion.

  3. The entry is removed and a free slot is released.

Don’t delete certificates that are still bound to active domains—this will break HTTPS.


7) View connection info (DNS targets)

  1. Open the certificate entry and click Connection info.

  2. A popup shows CNAME and IP.

  3. In your DNS provider, point your hostname to the provided values as instructed.


8) Manage domain bindings

Domains aren’t listed in the info panel. Use Manage Bindings for domain control.

Add binding

  1. Click Manage BindingsAdd binding.

  2. Enter the domain (e.g., store.example.com) covered by the certificate.

  3. Save.

  4. Ensure DNS points to the Connection info target.

Delete binding

  1. In Manage Bindings, select the domain → Delete binding.

  2. Confirm.

There is no edit for a binding. To change it, delete and re-add.


9) Interpret status & health

  • Active – Valid and applied.

  • Expiring soon – Renew via Update certificate.

  • Expired – Replace immediately to avoid TLS errors.

  • Pending / Not applied – Processing or waiting on prerequisites (often DNS).

  • Error – Open the entry to view details and resolve (e.g., key mismatch, invalid PEM).


Troubleshooting & Tips

  • “Add Certificate” / “CSR” button missing

    • You’ve likely reached capacity. Delete unused certificates or contact Support to review capacity options.

  • Upload/validation errors

    • The certificate must match the uploaded private key.

    • All fields in dialogs are required (unless explicitly marked optional).

    • For renewals, upload the correct reissued certificate from your CA.

  • Binding not taking effect

    • Confirm the domain is included in the certificate (CN/SAN).

    • Verify DNS points to the Connection info values.

    • Allow for DNS propagation.

  • Don’t see Certificate Management

    • Contact Support to request access.


FAQs

Is there a 1:1 relationship between certificates and storefronts?
No. The certificate pool is platform-wide. Capacity is constrained by platform limits. One certificate can serve multiple domains if it covers them.

What if I hit the certificate limit?
Delete unused certificates to free slots or contact Support to review capacity.

Can I change a binding without deleting it?
No. Update isn’t available for bindings. Delete the old binding and Add a new one.

Do I need domain verification?
If your environment requires it, complete verification in the Domain Verification area. (Steps depend on your setup.)


Post-Setup Checklist

  • Certificate appears with correct Name/Description/Contact.

  • Status shows a healthy/active state.

  • Connection info (CNAME/IP) is configured in DNS and resolves as expected.

  • Bound domains load over HTTPS without warnings.

  • Free slots reflects your additions/deletions.


Notes & Limitations

  • All fields in dialogs/popups are required unless explicitly marked optional (CSR download is optional).

  • Domains aren’t listed in the certificate info panel; manage them via Manage Bindings.

  • Actions are processed by background services; the UI displays success/error when complete.

  • Customers cannot change permissions or capacity settings themselves—contact Support for access or capacity reviews.

Incomplete
Alternate Search Terms

add SSL to my storefront, enable HTTPS on my domain, renew an expiring SSL certificate, upload SSL certificate and private key, generate a CSR in Infigo Admin, bind a domain to a certificate, update DNS (CNAME/IP) for Infigo, check certificate status or errors (active/expired/pending), manage SSL for multiple storefronts (platform-wide), reached certificate limit / no free slots available