> ## Documentation Index
> Fetch the complete documentation index at: https://developers.aptranet.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Domains and TLS

> Attach custom hostnames, configure HTTPS, HTTP/3, protocol versions, SNI, and origin validation.

Every distribution has an Aptranet hostname. Add custom hostnames under the distribution's **Network** configuration, then configure visitor and origin TLS separately.

## Attach a hostname

<Steps>
  <Step title="Add the hostname">
    Open the distribution's **Network** page and add a fully qualified hostname such as `cdn.example.com`.
  </Step>

  <Step title="Save and copy the target">
    Save the network configuration and note the distribution's root hostname.
  </Step>

  <Step title="Create DNS">
    Create a CNAME from the custom hostname to the distribution hostname. For an apex name, use the record type or flattening behavior supported by your authoritative DNS provider.
  </Step>

  <Step title="Wait for availability">
    The hostname can pass through draft or provisioning before it becomes active. Verify its certificate before redirecting all HTTP traffic.
  </Step>
</Steps>

## Visitor TLS

* `enable_https` serves the distribution over HTTPS.
* `https_redirect` redirects HTTP clients to HTTPS.
* `enable_http3` enables HTTP/3 where supported.
* Protocol switches control SSL 3.0 and TLS 1.0–1.3 support.

<Warning>
  Keep SSL 3.0, TLS 1.0, and TLS 1.1 disabled unless a documented legacy requirement outweighs their security risk.
</Warning>

## Origin TLS

* **Origin protocol** controls whether edge nodes use HTTP, HTTPS, or the visitor's protocol.
* **Custom SNI hostname** can match the Host header or use a fixed hostname.
* **Origin TLS validation** verifies the certificate presented by the origin.

Enable origin validation in production. If validation fails, correct the origin certificate chain, hostname, or SNI value rather than disabling verification.

## Certificate selection

Use **TLS Manager** to inspect managed certificate issuance or [import a certificate](/tls-manager/import-certificates). In the distribution's TLS configuration, select a certificate from the same project. HTTPS must be enabled before you attach one.

The API accepts optional `certificate_id`. A positive ID selects a project certificate. An explicit `0` selects automatic management and can replace an imported certificate. Omitting the field preserves the existing binding when HTTPS is already enabled; it does not force an imported certificate back to managed mode.

Review [certificate lifecycle](/tls-manager/lifecycle) for expiry, renewal, and troubleshooting.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.