Deploy SSL certificates to cloud services

Updated at:

This topic describes how to create a deployment task to deploy SSL certificates to Alibaba Cloud services individually or in bulk at a scheduled time.

Before you begin

  • This topic does not cover Elastic Compute Service (ECS) or Simple Application Server. To deploy a certificate to an ECS instance or a Simple Application Server instance, see Update an existing certificate on an Alibaba Cloud ECS instance or a Simple Application Server instance.

  • You have purchased and applied for a certificate by using the SSL Certificates Service, and its Status is Issued. To purchase and apply for a certificate, see Purchase a paid certificate and Apply for a certificate.

  • The SSL certificate alias must not contain Chinese characters. The following figure shows an example.

  • The domain name has completed MIIT ICP filing (for services deployed in the Chinese mainland only).

    How to check DNS records and ICP filing information

    Open the Network Probe Tool, select Network Diagnostic Analysis, enter your domain name, and confirm the following information:

    • DNS Provider Resolution Result:

      • If the DNS record is an A record, it must point to the public IP address of the target server where you want to deploy the certificate.

      • If the DNS record is a CNAME record, it must point to the CNAME provided by the traffic entry point, such as WAF, CDN, or ALB.

    • The ICP Filing Check status is ICP Filed. If the status is "The website is not ICP filed. Please contact the website server provider.", you must complete the ICP filing before you install the certificate.

  • Verify the certificate status and confirm that the certificate matches the target domain names.

    Check certificate status and domain match

    On the SSL Certificate Management V2.0 page, find the target certificate and verify the following information:

    1. Certificate Status: Make sure the status is Issued. If the status is About to Expire or Expired, you must renew the SSL certificate.

    2. Bound Domains: Make sure the certificate covers all domain names you want to protect. If a domain name is not covered, users will see a security warning when they access that domain over HTTPS. To add or change domain names, see Add and replace domain names.

      Domain name matching rules

      The Bound Domains of a certificate can include multiple exact and wildcard domain names. The matching rules are as follows:

      • Exact domain name: Covers only the specified domain name.

        • example.com covers only example.com.

        • www.example.com covers only www.example.com.

      • Wildcard domain name: Covers only first-level subdomains.

        • *.example.com covers first-level subdomains such as www.example.com and a.example.com.

        • *.example.com does not cover the root domain example.com or multi-level subdomains such as a.b.example.com.

      Note

      To cover a multi-level subdomain, the Bound Domains field must include that specific domain name (for example, a.b.example.com) or a matching wildcard domain name (for example, *.b.example.com).

  • To create a deployment task, a RAM user must be granted the AliyunYundunCertFullAccess system policy or a custom policy that includes the yundun-cert:CreateDeploymentJob permission.

  • To obtain cloud service resource IDs by calling API operations, the RAM user must also be granted the yundun-cert:ListWorkerResource permission to call the ListCloudResources operation.

Limitations

Note
  • If your product is not supported by the "cloud product deployment" feature, refer to the product's documentation for deployment instructions. Products that support one-click push are listed in the table below.

  • "Update existing certificate" in the table below refers to the scenario where a certificate is already deployed on a cloud product and you need to replace it.

Cloud product

Deployment task scenario

Certificate configuration scenario

Cloud Web Hosting

Initial deployment, Update existing certificate

Enable HTTPS access for websites

Container Registry (ACR)

Update existing certificate

Access a Container Registry Enterprise Edition instance over HTTPS with a custom domain name

Container Service for Kubernetes (ACK)

Update existing certificate

Update AlbConfig certificates and Secret certificates in ACK managed and dedicated clusters

Important

Do not manually modify a Secret in ACK. The system creates a new Secret automatically.

Serverless App Engine - gateway routing

Update existing certificate

Configure HTTPS as the forwarding protocol for gateway routing (ALB and CLB)

Function Compute (FC)

Update existing certificate

HTTP function scenario

Microservices Engine - cloud-native gateway

Update existing certificate

Cloud-native gateway routing scenario

API Gateway

Update existing certificate

Access an API over HTTPS with a domain name

Global Accelerator (GA)

Update existing certificate

Accelerate HTTPS domain name access securely

  • Application Load Balancer (ALB)

  • Network Load Balancer (NLB)

  • Classic Load Balancer (CLB)

Update existing certificate

Forward requests over HTTPS using an HTTPS listener (server certificate)

Note

To deploy a client certificate, see End-to-end HTTPS encryption.

Content Delivery Network (CDN)

Initial deployment, Update existing certificate

HTTPS secure acceleration

Dynamic Route for CDN (DCDN)

Initial deployment, Update existing certificate

HTTPS secure acceleration

Edge Security Acceleration (ESA)

Update existing certificate

HTTPS secure acceleration

Object Storage Service (OSS)

Update existing certificate

Access OSS over HTTPS

Note

If your domain name uses CDN acceleration, replace the certificate in the CDN console.

Web Application Firewall (WAF)

Update existing certificate

CNAME access scenario

Anti-DDoS Pro and Anti-DDoS Premium

Update existing certificate

Domain name access for Anti-DDoS Pro and Anti-DDoS Premium

ApsaraVideo for Live

Initial deployment, Update existing certificate

HTTPS secure acceleration for stream ingest and playback

ApsaraVideo for VOD

Initial deployment, Update existing certificate

Content distribution and acceleration

Platform for AI (PAI)

Update existing certificate

Elastic Algorithm Service (EAS) model serving: use a custom domain name for a dedicated gateway

  • Deploy a China Cryptography Standard SSL certificate (SM2, supported only by CDN, DCDN, and Anti-DDoS Pro and Anti-DDoS Premium)

  • Procedure

    Step 1: Purchase deployment quota

    Note

    Deployment quota is consumed only when you deploy certificates of the Uploaded type. If your certificate is not of the Uploaded type, skip to Step 2: Check authorizations.

    • If you do not have enough deployment quota, purchase deployment quotas. Each deployment costs CNY 30 and is valid for one year.

    • Deployment quota is not consumed for certificates other than the Uploaded type, or for certificates shared between Alibaba Cloud accounts that belong to the same verified individual or enterprise. If a deployment fails, the consumed quota is refunded.

    Step 2: Check authorizations

    Note

    If your deployment task does not involve ACK, skip to Step 3: Deploy the certificate to cloud service resources.

    Before deploying a certificate to Container Service for Kubernetes (ACK), log on to the ACK console with your Alibaba Cloud account and grant the AliyunCASDefaultRole RAM role the permissions to manage the destination cluster. Otherwise, the Certificate Management Service console cannot discover the cluster namespace.

    1. Go to the Authorization Management page in the ACK console. On the RAM Roles tab, enter AliyunCASDefaultRole and click Modify Permissions.

    2. On the Permission Management tab, grant the O&M Engineer permission for the destination cluster.

      image

    Step 3: Deploy the certificate

    Single deployment

    1. If this is your first time using the deployment service, follow the on-screen prompts to grant the required permissions before you can create deployment tasks. For more information, see Grant permissions to access cloud resources.

    2. Log in to the Certificate Management Service console.

    3. In the navigation pane on the left, choose Certificate Management > SSL Certificate Management V2.0.

    4. On the SSL Certificate Management page, click the appropriate certificate tab. In the certificate list, find the certificate you want to deploy and click Deploy in the Actions column.

      Certificates issued by Private CA are listed on the Uploaded Certificates tab, where you can manage them.

    5. On the Create Task page, in the Select Resource step, select or adjust the cloud services and resources, and then click Preview and Submit.

      • The system automatically matches cloud service resources that already have an SSL certificate configured. In the automatic matching dialog box, click OK. The matched resources are added to the Selected Resources area. You can then adjust the selection as needed.

        image

      • The system automatically discovers and retrieves all resources from your cloud services. If you cannot find a target resource, check the following:

        • In the Total Resources section, check whether resource synchronization is complete. If resources are still being synchronized (shown in a grayed-out state), wait for synchronization to finish. The time required depends on the number of resources in your cloud services.

          image

        • If you still cannot find the resource after synchronization is complete, verify that you meet the deployment prerequisites.

    6. In the Task Preview panel, review the certificate and resource details. If everything looks correct, click Submit.

      The preview page shows the number of matched certificates for each cloud service and the deployment quota to be consumed. A match count of 0 means the certificate does not match the resource, and the deployment will fail. Review your selection carefully.

    Bulk deployment

    1. If this is your first time using the deployment service, follow the on-screen prompts to grant the required permissions before you can create deployment tasks. For more information, see Grant permissions to access cloud resources.

    2. Log in to the Certificate Management Service console.

    3. In the navigation pane on the left, choose Deployment Management > Deployment to Cloud Services.

    4. On the Deployment to Cloud Services page, click Create Task and deploy the SSL certificates.

      1. In the Configure Basic Information step, configure the task name, contact, and deployment time. Then, click Next.

        Parameter

        Description

        Task Name

        Enter a custom name for the deployment task.

        Contact

        Select contacts to receive deployment task notifications. You can add up to 10 contacts.

        Deployment Time

        • Deploy Now: Deploys the certificates to cloud services immediately.

        • Custom Time: Schedules the deployment task to run at a specific time.

      2. In the Select Certificate step, select the SSL certificates that correspond to the cloud resources. Then, click Next.

        • Certificates issued by Private CA are listed on the The ID of the certificate in Alibaba Cloud. You must upload a certificate first. tab, where you can select them.

        • Each deployment task can include only certificates of a single type.

      3. In the Select Resource step, select or adjust the cloud services and resources, and then click Preview and Submit.

        Note

        Bulk deployment is not supported for Server Load Balancer (SLB) listeners that are bound to multiple server certificates.

        • The system automatically matches cloud service resources that already have an SSL certificate configured. In the automatic matching dialog box, click OK. The matched resources are added to the Selected Resources area. You can then adjust the selection as needed.

          image

        • The system automatically discovers and retrieves all resources from your cloud services. If you cannot find a target resource, check the following:

          • In the The total resource requests for all replicated pods exceed the recommended resource requests (4 vCores and 8 GB of memory). This may lead to quick consumption of resource plans. section, check whether resource synchronization is complete. If resources are still being synchronized (shown in a grayed-out state), wait for synchronization to finish. The time required depends on the number of resources.

            image

          • If you still cannot find the resource after synchronization is complete, verify that your scenario supports initial certificate deployment. For more information, see Before you begin.

      4. In the Task Preview panel, review the certificate and resource details. If everything looks correct, click Submit.

        The preview page shows the number of matched certificates for each cloud service and the deployment quota to be consumed. A match count of 0 means the certificates do not match the resources, and the deployment will fail. Review your selections carefully.

    Related operations

    View deployment task details

    1. On the Deployment to Cloud Services page, find the target deployment task and click Details in the Actions column.

    2. On the task details page, you can view the deployment status of each instance resource. If a resource deployment fails, check the Actions column for the failure reason and take the appropriate action.

      If you cannot determine the specific failure reason, contact a product technical expert for assistance. For more information, see One-on-one expert service.

    Roll back a deployment task

    Important

    Deployment quota is not refunded after a successful rollback.

    After a certificate is deployed successfully, if you find that the wrong certificate was deployed or you need to undo the deployment for another reason, you can roll back to the pre-deployment state:

    1. On the Deployment to Cloud Services page, find the target deployment task and click Details in the Actions column.

    2. On the task details page, click the cloud service, find the target instance resource, and then click Roll Back in the Actions column.

      After a successful rollback, the task status changes to Rolled Back.

    Delete a deployment task

    Important

    Deleted tasks cannot be recovered. Proceed with caution.

    On the Deployment to Cloud Services page, find the target deployment task and click Delete in the Actions column. You can also select multiple deployment tasks and click Delete at the bottom of the list.

    FAQ

    Cross-account certificate deployment

    You cannot directly deploy Alibaba Cloud SSL certificates across different accounts.

    • If multiple accounts belong to the same verified identity, you can use the certificate sharing feature to deploy certificates across accounts at no charge. For more information, see Upload, synchronize, and share SSL certificates.

    • If the accounts belong to different verified identities, you must download the certificate from the source account and then manually upload and deploy it to the destination account.

    Does deployment enable HTTPS automatically?

    Deploying a certificate from the SSL Certificates Service console only pushes it to the target cloud service. You must still verify the deployment in that service's management console.

    Cloud service resources shown as 0

    When you create a deployment task, the system automatically identifies and retrieves all resources from your cloud services. If you cannot find the target resource, check the following items:

    • In the Total Resources section, check whether resource synchronization is complete. If resources are being synchronized (the status is gray, as shown in the following figure), wait for the synchronization to complete. The synchronization duration depends on the number of resources in the cloud service.

      image

    • If the resource is not found after synchronization is complete, check whether the initial configuration requirements for certificate deployment are met. If not, you must deploy the certificate in the management console of the cloud service.

    After an SSL certificate is issued, do I only need to configure an A record pointing to a public IP address to enable HTTPS?

    No. Configuring an A record only resolves the domain name to an IP address; it does not enable HTTPS encryption. After an SSL certificate is issued, you must also complete the following steps to access your site over HTTPS:

    • Deploy the certificate: Install the SSL certificate on your web server (such as Nginx or Apache) or on Alibaba Cloud services, and ensure that the certificate file and private key are correctly configured.

    • ICP filing: The domain name can be accessed only after the ICP filing is completed.

    How do I deploy an issued SSL certificate to API Gateway and verify that HTTPS is working?

    Deployment steps:

    1. Log on to the API Gateway console and bind the issued SSL certificate to the corresponding HTTPS service or group.

    2. Wait for the configuration to take effect (this typically takes a few minutes).

    Verification:

    Use the curl command to verify that HTTPS is working:

    curl -v https://<domain-name>

    Check the following in the response:

    • The message SSL certificate verify ok appears, indicating that the certificate has been verified.

    • Certificate details (such as subject and expire date) are displayed — confirm that the certificate matches your expectations.

    • The HTTP status code is normal (such as 200 or the expected business status code), indicating that the service is accessible.

    If all of the above conditions are met, the SSL certificate has been successfully deployed to API Gateway and HTTPS is working correctly.