Create an SSL certificate
After purchasing a certificate, you must create one and bind it to a domain name. Selecting Quick Issue when you create the certificate automatically submits your application to the Certificate Authority (CA), simplifying the issuance process.
SSL Certificate Management V2.0 automatically creates a certificate in the pending application state after purchase. You do not need to create a certificate. This document applies only to SSL Certificates Service (new purchases for V1.0 are discontinued).
Prerequisites
You have purchased a paid certificate or a personal test certificate.
If you specified a domain name when you purchased the paid certificate, the system automatically creates the certificate. The process is as follows:
If you have provided the Certificate-related Information, the system automatically submits a certificate application to the CA. You only need to complete domain name ownership verification.
If you have not provided the Certificate-related Information, you must manually submit a certificate application. For more information, see Submit an application to the CA (Certificate Authority).
Workflow
Procedure
Create an individual test certificate
Individual Test Certificates are Domain Validated (DV) certificates.
Log on to the Certificate Management Service console. In the left-side navigation pane, choose . On the Individual Test Certificate (Formerly Free Certificate) tab, click Create Certificate.
Step 1: Configure basic information
Follow the instructions to configure the basic parameters. If you do not select Quick Issue, the certificate enters the Pending Application state after you provide the required information and click OK. You will need to submit an application to the Certificate Authority (CA) later.
Certificate Type
Individual Test Certificate (Free): A free certificate that is valid for three months.
Individual Test Certificate (Pro): A paid certificate.
Remaining Certificate Quota/Total
Displays the number of certificates you can create and the total quota available for the selected certificate type. If your certificate quota is insufficient, see What do I do if my certificate quota is insufficient when I create a certificate?.
Domain Name
Domain name limits: You can apply for a personal test certificate only for a single domain name. You cannot apply for a personal test certificate for a public IP address, a domain name with a special suffix, a wildcard domain name, or a hybrid domain name. To apply for a certificate for one of these, you must purchase a commercial certificate.
Length limits: The total length of a single domain name cannot exceed 253 characters. The length of each label in the domain name, which is the part separated by a period (
.), cannot exceed 63 characters.Chinese domain names: If you want to secure a Chinese domain name, you must convert it to Punycode as prompted in the console before you can apply for a certificate. You can also use a transcoding tool to convert the domain name. For more information, see Chinese domain name conversion.
NotevTrus-branded certificates do not support Chinese domain names.
Complimentary domain name: If your domain name is eligible, Alibaba Cloud provides a complimentary domain name.
Validity Period (Years)
If the certificate type is Individual Test Certificate (Free), the value is fixed at 1 and cannot be changed.
If the certificate type is Individual Test Certificate (Pro), you must configure the validity period. Due to ongoing reductions in certificate validity periods, multiple certificates may be issued during the service period. For more information, see Changes in certificate validity periods.
Quick Issue
If you select Quick Issue, you must provide application details. After the certificate is created, the system automatically submits the certificate application to the CA. You must then complete domain name ownership verification.
Step 2 (Optional): Provide application details (Quick Issue workflow)
If you select Quick Issue, provide the details required for review by the CA. After you provide the required information and click Submit for Review, the certificate status changes to Validating Application. You must then complete domain name ownership verification. The parameters are described as follows:
Domain Verification Method
Select a verification method based on your account status:
NoteCertificate purchase account: The Alibaba Cloud account used to purchase the target SSL certificate in the Certificate Management Service console.
DNS resolution account: The Alibaba Cloud account used to configure DNS resolution for the target domain name in Alibaba Cloud DNS.
The purchase and DNS accounts are different
Manual DNS Verification (recommended): Log on to your DNS service platform and add a CNAME or TXT DNS record.
File Verification: Log on to your web server, and create and upload the required validation file to the specified directory.
ImportantWildcard domain names do not support file validation.
The purchase and DNS account are the same
The system uses the Automatic DNS Verification method. Alibaba Cloud automatically adds a DNS record for the domain name in Alibaba Cloud DNS to verify domain ownership. No manual operation is required.
Contact
Select a contact for this certificate application. The contact information includes an email address and a mobile number. To create or modify a contact, click Create Contact or Edit, or go to Contact Management.
Location
Select the city or region where the applicant is located.
Encryption Algorithm
Option
Security
Compatibility
Performance
Recommendation
RSA_2048
Medium
Widest
Middle
Recommended for general use and suitable for most web applications.
RSA_3072
High
Good
Lower
Suitable for scenarios with high security requirements, such as finance and payments.
RSA_4096
Very High
Fair
Low
Recommended only for top-secret or extremely high-security scenarios.
ECC_256
High
Good
Very High
Suitable for mobile applications, high-concurrency systems, and IoT devices.
SM2
High
Specific
High
Applicable only to scenarios that require compliance with Chinese cryptographic standards, such as government, state-owned enterprises, and finance.
RSA: An asymmetric key encryption algorithm based on the difficulty of factoring large integers. It is the most widely used and has excellent compatibility. Longer keys provide higher security but increase performance overhead.
ECC: An asymmetric key encryption algorithm based on the difficulty of the elliptic curve discrete logarithm problem. It achieves the same level of security as RSA with shorter keys, offers higher computational efficiency, and is suitable for resource-constrained environments such as mobile devices and IoT.
SM2: A Chinese domestic elliptic curve algorithm released by the State Cryptography Administration of China. It is part of the Chinese national cryptographic standard. Its security is comparable to ECC and is suitable for government, finance, and other scenarios with domestic compliance requirements.
NoteCurrently, only some brands and types of certificates support the ECC and SM2 algorithms. For more information, see SSL certificate selection.
CSR Generation
A Certificate Signing Request (CSR) is an application file submitted to a CA when you apply for an SSL certificate. It contains your domain name, organization information, and public key. You must securely store the corresponding private key.
Automatic (recommended)
Alibaba Cloud automatically creates a CSR and a private key for you. After the certificate is issued, you can directly download the complete file that contains the private key.
Manual Entry
You can use tools such as OpenSSL or Keytool to manually generate a CSR and a private key file, which you must store securely. Then, copy the CSR content into the CSR File configuration item. For more information about how to create a CSR and a private key file, see How to create a CSR file.
ImportantSecurely store your private key. If you lose the private key, the certificate becomes unusable because the key is unrecoverable. You would need to generate a new key pair and request a certificate reissuance.
If you apply for a Chinese cryptographic algorithm certificate and select Manual Entry for the CSR, the private key is not stored in Alibaba Cloud. The private key is required to decrypt the obtained certificate. You must contact the party that generated the private key to assist with decryption. This does not apply to Wosign-branded certificates.
The encryption algorithm of the CSR must match the Key Algorithm selected above. If you are unsure of the encryption algorithm used by your CSR, you can use the View CSR tool to check it. For more information, see View CSR Details.
Certificates issued using this method do not support one-click deployment to other Alibaba Cloud products.
Select an Existing CSR
From the CSRs created or uploaded in the Certificate Management Service console, select the CSR that matches the Domains to Bind. For more information about how to create and upload a CSR, see Create a CSR.
CSR File
This parameter is required only when CSR Generation is set to Manual or Select Existing CSR. Enter the content of your CSR file.
Create a commercial certificate
Log on to the Certificate Management Service console. In the left-side navigation pane, choose . On the Commercial Certificates tab, click Create Certificate.
Step 1: Configure basic information
Follow the instructions to configure the basic parameters. If you do not select Quick Issue, the certificate enters the Pending Application state after you provide the required information and click OK. You will need to submit an application to the Certificate Authority (CA) later.
Certificate Type
The system displays the types of certificates that you have purchased and can create. This can include single domain, multi-domain, and wildcard types. You can select a type only if you have purchased the corresponding certificate resources.
Certificate Specifications
Displays the certificate specifications you have purchased and their available quantities. If the required specification is not available, first purchase a commercial certificate.
Domain Name
Domain name requirements
Type matching: The domain type that you enter (single, multi-domain, or wildcard) must match your purchased certificate.
Length limits: The total length must not exceed 253 characters. Each label (a segment separated by the
.character) must not exceed 63 characters.
Special format requirements
Wildcard: Must start with
*, such as*.example.com.Chinese domain name: If you use a Chinese domain name, you must convert it to Punycode as prompted in the console. You can also use a conversion tool. For more information, see Chinese Domain Name Conversion.
NotevTrus-branded certificates do not support Chinese domain names.
IP addresses: Supported only by some OV single-domain certificates (Brands: GlobalSign and GeoTrust, vTrus, and CFCA).
Suffix restrictions: Only GlobalSign-branded certificates support attaching to domain names with the
.rusuffix.Complimentary domain name: If your domain name is eligible, Alibaba Cloud provides a complimentary domain name.
Validity Period (Years)
Select the service duration for your certificate. Because certificate validity periods are decreasing, multiple certificates may be issued during the service period. For more information, see Changes in certificate validity periods.
Quick Issue
If you select Quick Issue, you must provide application details. After the certificate is created, the system automatically submits the certificate application to the CA. You must then complete domain name ownership verification. You do not need to submit the application again.
Step 2 (Optional): Provide application details (Quick Issue workflow)
If you select Quick Issue, provide the details that the CA requires for review. The required information varies by certificate type (DV, OV, or EV). After you provide this information and click Submit for Review, the certificate status changes to Validating Application, and you must then complete domain name ownership verification.
Certificate application information
DV certificates
Domain Verification Method
NoteCertificate purchase account: The Alibaba Cloud account used to purchase the target SSL certificate in the Certificate Management Service console.
DNS resolution account: The Alibaba Cloud account used to configure DNS resolution for the target domain name in Alibaba Cloud DNS.
The purchase and DNS accounts are different
Manual DNS Verification (recommended): Log on to your DNS service platform and add a CNAME or TXT DNS record.
File Verification: Log on to your web server, and create and upload the required validation file to the specified directory.
ImportantWildcard domain names do not support file validation.
The purchase and DNS account are the same
The system uses the Automatic DNS Verification method. Alibaba Cloud automatically adds a DNS record for the domain name in Alibaba Cloud DNS to verify domain ownership. No manual operation is required.
Contact
Select a contact for this certificate application. The contact information includes an email address and a mobile number. To create or modify a contact, click Create Contact or Edit, or go to Contact Management.
Location
Select the city or region where the applicant is located.
Encryption Algorithm
Option
Security
Compatibility
Performance
Recommendation
RSA_2048
Medium
Widest
Middle
Recommended for general use and suitable for most web applications.
RSA_3072
High
Good
Lower
Suitable for scenarios with high security requirements, such as finance and payments.
RSA_4096
Very High
Fair
Low
Recommended only for top-secret or extremely high-security scenarios.
ECC_256
High
Good
Very High
Suitable for mobile applications, high-concurrency systems, and IoT devices.
SM2
High
Specific
High
Applicable only to scenarios that require compliance with Chinese cryptographic standards, such as government, state-owned enterprises, and finance.
RSA: An asymmetric key encryption algorithm based on the difficulty of factoring large integers. It is the most widely used and has excellent compatibility. Longer keys provide higher security but increase performance overhead.
ECC: An asymmetric key encryption algorithm based on the difficulty of the elliptic curve discrete logarithm problem. It achieves the same level of security as RSA with shorter keys, offers higher computational efficiency, and is suitable for resource-constrained environments such as mobile devices and IoT.
SM2: A Chinese domestic elliptic curve algorithm released by the State Cryptography Administration of China. It is part of the Chinese national cryptographic standard. Its security is comparable to ECC and is suitable for government, finance, and other scenarios with domestic compliance requirements.
NoteCurrently, only some brands and types of certificates support the ECC and SM2 algorithms. For more information, see SSL certificate selection.
CSR Generation
A Certificate Signing Request (CSR) is an application file submitted to a CA when you apply for an SSL certificate. It contains your domain name, organization information, and public key. You must securely store the corresponding private key.
Automatic (recommended)
Alibaba Cloud automatically creates a CSR and a private key for you. After the certificate is issued, you can directly download the complete file that contains the private key.
Manual Entry
You can use tools such as OpenSSL or Keytool to manually generate a CSR and a private key file, which you must store securely. Then, copy the CSR content into the CSR File configuration item. For more information about how to create a CSR and a private key file, see How to create a CSR file.
ImportantSecurely store your private key. If you lose the private key, the certificate becomes unusable because the key is unrecoverable. You would need to generate a new key pair and request a certificate reissuance.
If you apply for a Chinese cryptographic algorithm certificate and select Manual Entry for the CSR, the private key is not stored in Alibaba Cloud. The private key is required to decrypt the obtained certificate. You must contact the party that generated the private key to assist with decryption. This does not apply to Wosign-branded certificates.
The encryption algorithm of the CSR must match the Key Algorithm selected above. If you are unsure of the encryption algorithm used by your CSR, you can use the View CSR tool to check it. For more information, see View CSR Details.
Certificates issued using this method do not support one-click deployment to other Alibaba Cloud products.
Select an Existing CSR
From the CSRs created or uploaded in the Certificate Management Service console, select the CSR that matches the Domains to Bind. For more information about how to create and upload a CSR, see Create a CSR.
CSR File
This parameter is required only when CSR Generation is set to Manual or Select Existing CSR. Enter the content of your CSR file.
OV certificates
Contact
Select the contact for this certificate application. The contact information includes an email address and a mobile phone number. To create or modify a contact, click Create Contact or Edit, or go to Contact Management.
ImportantAfter the CA receives the certificate application, it sends a validation email to the contact's email address or communicates with the contact using their mobile phone number (only in the Chinese mainland) for the review. Make sure that the contact information is accurate and valid.
Company
Select the company information for this certificate application, including the name, phone number, and address. To create or modify company information, click Create Company Profile or Edit, or go to Company Information Management.
ImportantWhen you apply for an OV certificate for a .gov domain name, the organization name in the domain's WHOIS information must exactly match the company name.
Business License
After you select a Company, the system automatically identifies the business license picture uploaded for the company. If you did not upload a business license picture when you created the company, the business license picture is empty. To ensure a quick review by the CA, we recommend that you upload the company's business license picture.
Encryption Algorithm
Option
Security
Compatibility
Performance
Recommendation
RSA_2048
Medium
Widest
Middle
Recommended for general use and suitable for most web applications.
RSA_3072
High
Good
Lower
Suitable for scenarios with high security requirements, such as finance and payments.
RSA_4096
Very High
Fair
Low
Recommended only for top-secret or extremely high-security scenarios.
ECC_256
High
Good
Very High
Suitable for mobile applications, high-concurrency systems, and IoT devices.
SM2
High
Specific
High
Applicable only to scenarios that require compliance with Chinese cryptographic standards, such as government, state-owned enterprises, and finance.
RSA: An asymmetric key encryption algorithm based on the difficulty of factoring large integers. It is the most widely used and has excellent compatibility. Longer keys provide higher security but increase performance overhead.
ECC: An asymmetric key encryption algorithm based on the difficulty of the elliptic curve discrete logarithm problem. It achieves the same level of security as RSA with shorter keys, offers higher computational efficiency, and is suitable for resource-constrained environments such as mobile devices and IoT.
SM2: A Chinese domestic elliptic curve algorithm released by the State Cryptography Administration of China. It is part of the Chinese national cryptographic standard. Its security is comparable to ECC and is suitable for government, finance, and other scenarios with domestic compliance requirements.
NoteCurrently, only some brands and types of certificates support the ECC and SM2 algorithms. For more information, see SSL certificate selection.
CSR Generation
A Certificate Signing Request (CSR) is an application file submitted to a CA when you apply for an SSL certificate. It contains your domain name, organization information, and public key. You must securely store the corresponding private key.
Automatic (recommended)
Alibaba Cloud automatically creates a CSR and a private key for you. After the certificate is issued, you can directly download the complete file that contains the private key.
Manual Entry
You can use tools such as OpenSSL or Keytool to manually generate a CSR and a private key file, which you must store securely. Then, copy the CSR content into the CSR File configuration item. For more information about how to create a CSR and a private key file, see How to create a CSR file.
ImportantSecurely store your private key. If you lose the private key, the certificate becomes unusable because the key is unrecoverable. You would need to generate a new key pair and request a certificate reissuance.
If you apply for a Chinese cryptographic algorithm certificate and select Manual Entry for the CSR, the private key is not stored in Alibaba Cloud. The private key is required to decrypt the obtained certificate. You must contact the party that generated the private key to assist with decryption. This does not apply to Wosign-branded certificates.
The encryption algorithm of the CSR must match the Key Algorithm selected above. If you are unsure of the encryption algorithm used by your CSR, you can use the View CSR tool to check it. For more information, see View CSR Details.
Certificates issued using this method do not support one-click deployment to other Alibaba Cloud products.
Select an Existing CSR
From the CSRs created or uploaded in the Certificate Management Service console, select the CSR that matches the Domains to Bind. For more information about how to create and upload a CSR, see Create a CSR.
CSR File
This parameter is required only when CSR Generation is set to Manual or Select Existing CSR. Enter the content of your CSR file.
EV certificates
Contact
Select the contact for this certificate application. The contact information includes an email address and a mobile phone number. To create or modify a contact, click Create Contact or Edit, or go to Contact Management.
ImportantAfter the CA receives the certificate application, it sends a validation email to the contact's email address or communicates with the contact using their mobile phone number (only in the Chinese mainland) for the review. Make sure that the contact information is accurate and valid.
Company
Select the company information for this certificate application, including the name, phone number, and address. To create or modify company information, click Create Company Profile or Edit, or go to Company Information Management.
ImportantWhen you apply for an OV certificate for a .gov domain name, the organization name in the domain's WHOIS information must exactly match the company name.
Business License
After you select a Company, the system automatically identifies the business license picture uploaded for the company. If you did not upload a business license picture when you created the company, the business license picture is empty. To ensure a quick review by the CA, we recommend that you upload the company's business license picture.
Encryption Algorithm
Option
Security
Compatibility
Performance
Recommendation
RSA_2048
Medium
Widest
Middle
Recommended for general use and suitable for most web applications.
RSA_3072
High
Good
Lower
Suitable for scenarios with high security requirements, such as finance and payments.
RSA_4096
Very High
Fair
Low
Recommended only for top-secret or extremely high-security scenarios.
ECC_256
High
Good
Very High
Suitable for mobile applications, high-concurrency systems, and IoT devices.
SM2
High
Specific
High
Applicable only to scenarios that require compliance with Chinese cryptographic standards, such as government, state-owned enterprises, and finance.
RSA: An asymmetric key encryption algorithm based on the difficulty of factoring large integers. It is the most widely used and has excellent compatibility. Longer keys provide higher security but increase performance overhead.
ECC: An asymmetric key encryption algorithm based on the difficulty of the elliptic curve discrete logarithm problem. It achieves the same level of security as RSA with shorter keys, offers higher computational efficiency, and is suitable for resource-constrained environments such as mobile devices and IoT.
SM2: A Chinese domestic elliptic curve algorithm released by the State Cryptography Administration of China. It is part of the Chinese national cryptographic standard. Its security is comparable to ECC and is suitable for government, finance, and other scenarios with domestic compliance requirements.
NoteCurrently, only some brands and types of certificates support the ECC and SM2 algorithms. For more information, see SSL certificate selection.
CSR Generation
A Certificate Signing Request (CSR) is an application file submitted to a CA when you apply for an SSL certificate. It contains your domain name, organization information, and public key. You must securely store the corresponding private key.
Automatic (recommended)
Alibaba Cloud automatically creates a CSR and a private key for you. After the certificate is issued, you can directly download the complete file that contains the private key.
Manual Entry
You can use tools such as OpenSSL or Keytool to manually generate a CSR and a private key file, which you must store securely. Then, copy the CSR content into the CSR File configuration item. For more information about how to create a CSR and a private key file, see How to create a CSR file.
ImportantSecurely store your private key. If you lose the private key, the certificate becomes unusable because the key is unrecoverable. You would need to generate a new key pair and request a certificate reissuance.
If you apply for a Chinese cryptographic algorithm certificate and select Manual Entry for the CSR, the private key is not stored in Alibaba Cloud. The private key is required to decrypt the obtained certificate. You must contact the party that generated the private key to assist with decryption. This does not apply to Wosign-branded certificates.
The encryption algorithm of the CSR must match the Key Algorithm selected above. If you are unsure of the encryption algorithm used by your CSR, you can use the View CSR tool to check it. For more information, see View CSR Details.
Certificates issued using this method do not support one-click deployment to other Alibaba Cloud products.
Select an Existing CSR
From the CSRs created or uploaded in the Certificate Management Service console, select the CSR that matches the Domains to Bind. For more information about how to create and upload a CSR, see Create a CSR.
CSR File
This parameter is required only when CSR Generation is set to Manual or Select Existing CSR. Enter the content of your CSR file.
Permit for Opening a Bank Account
This information is required only when applying for a GeoTrust or DigiCert-branded certificate. Upload a clear scanned copy of the company's bank account opening permit.
NoteThe scanned copy must be in PNG or JPEG format and its size cannot exceed 500 KB.
Configuration items specific to CFCA brand certificates
NoteThe scans of the application form, lawyer's certificate, lawyer's letter, agent's ID card, and agent's passport must be in PNG or JPEG format. The size of each scanned copy cannot exceed 500 KB.
Advanced settings
Use the Advanced Settings to configure the Notification service for the certificate lifecycle.
Notification Status: Enabled by default.
Notification Method: You can configure Email Address, Text Message, Internal Message, and DingTalk/WeCom/Feishu.
Notification Content: You can configure three types of reminder messages: Business Notification, Alert Notification, and Product Change Notification.
Expiration Notification Frequency: Configure a reminder frequency policy. Options include: Only Once, Every Day, Every 3 Days, Every 5 Days, and Every 7 Days.
Expiration Deadline Notification: Configure how many days in advance to send reminders. Options include: 15 Days Before Expiration, 30 Days Before Expiration, 60 Days Before Expiration, and 90 Days Before Expiration.
The service period for the message reminder feature matches the validity period of the certificate. The service ends automatically when the certificate expires.
Next steps
Scenario 1: You selected Quick Issue.
After the certificate is created, the system automatically submits a certificate application to a CA. To track the application, hover over the
icon in the Status column and click View Progress in the tooltip. The Certificate Progress panel shows the review progress. You must then complete the domain name ownership verification.
Scenario 2: You did not select Quick Issue.
After a certificate is created, it appears in the certificate list with the status Pending Application. You must submit the certificate application to a CA for review. The CA issues the certificate only after your application is approved. For more information, see Submit an Application to a CA.
Complimentary domain rules
When you purchase a certificate, the system includes one complimentary associated domain if the conditions are met.
Conditions for a complimentary domain
In this topic, a second-level domain is a domain such as aliyun.com, in which .com is the top-level domain. www.aliyun.com and demo.aliyun.com are third-level domains. demo.doc.aliyun.com is a fourth-level domain, and so on.
DigiCert, GeoTrust, RapidSSL, CFCA, vTrus, WoSign, and Shanghai CA
-
DV: The domain validation method must be DNS validation.
-
OV and EV: The domain must be a second-level domain.
Complimentary domain rules
-
Single-domain certificate:
-
If you bind a primary domain name, the
wwwsubdomain is included. For example, if you bindaliyun.com,www.aliyun.comis included. -
If you bind a
wwwsubdomain, the primary domain name is included. For example, if you bindwww.aliyun.com,aliyun.comis included.
-
-
Wildcard certificate:
-
If you bind a wildcard domain, the corresponding primary domain name is included. For example, if you bind
*.aliyun.com,aliyun.comis included.
-
-
Multi-domain certificate:
-
A complimentary domain is included only if the first domain meets the conditions. Only the domain associated with the first domain is included. For example, if the certificate binds
a.aliyun.comandb.aliyun.com, onlywww.a.aliyun.comis included.
-
FAQ
Insufficient certificate quota
If you receive a notification that your quota is insufficient when creating a certificate, first check your certificate type. Then, consult the following tables for causes and solutions.
Type 1: Individual Test Certificate (Formerly Free Certificate)
Cause
Solution
First-time use or quota not claimed in the current calendar year
You must manually claim the free quota for each calendar year. Go to the Claim Free Certificate Quota page.
Annual quota is exhausted
Each user who has completed identity verification can claim a maximum of 20 free certificates per calendar year.
ImportantIf the 20-certificate quota is insufficient for your needs, consider purchasing the Individual Test Certificate (Pro).
The quota is not returned if a certificate is revoked or deleted.
Quota is cleared at the start of a new year
Alibaba Cloud clears the unused free quota for all users at the end of each calendar year (December 31). You must reclaim the quota at the start of the new year.
Type 2: Individual Test Certificate (Pro)
Cause
Solution
Quota is occupied by certificates in the "Pending Application" state
Check your certificate list for unneeded certificates in the "Pending Application" state. Click "Cancel Application". The quota is returned immediately after cancellation.
ImportantThe quota is not returned if a certificate is revoked or deleted.
All purchased quota is used or occupied
To purchase additional certificate quota, go to the Purchase a paid certificate page.
Zero available certificates after purchase
If the Create Certificate page shows 0 available certificates even though you have already purchased a certificate or claimed an Individual Test Certificate, this does not mean your quota is missing. SSL Certificate Management V2.0 has switched to a subscription model. After you purchase a certificate, the system automatically creates a certificate instance in the Pending Application state, so you do not need to manually create a certificate. A count of 0 on the Create Certificate page is expected behavior. Please view the purchased certificates on the SSL Certificate Management V2.0 page.
Chinese (IDN) domain names
When you apply for a certificate for a Chinese (IDN) domain name, you must convert it to Punycode. You can follow the prompts in the console or use a conversion tool. For more information, see Chinese Domain Name Conversion.