This topic describes the complete process for selecting and purchasing SSL certificates in Alibaba Cloud Certificate Management Service, including quick selection recommendations based on website type, number of domains, and brand, the purchase procedure, complimentary domain rules, and FAQ.
Quick selection
Your answers to the following questions directly correspond to the configuration options when you Purchase a certificate.
Question 1: How many domains do you need to protect?
A single domain (such as
aliyun.comorlogin.aliyun.com): Select a Single Domain certificate.All subdomains under one primary domain name (such as
*.aliyun.com): Select a Wildcard Domain certificate.Multiple domains (such as
aliyun.com,taobao.com, and*.aliyun.com): Select a Multiple Domains certificate.
When you purchase certain certificates, the system automatically includes a complimentary associated domain. For details, see Complimentary domain rules.
Question 2: What type of website do you have?
Personal websites or development/test environments: Select a DV (Domain Validated) certificate. Only domain ownership is verified. Certificates are automatically issued within an average of 1 to 15 minutes at a lower cost.
Enterprise websites or internal information systems: Select an OV (Organization Validated) certificate. Organizational identity verification is required, providing higher security. The organization name is displayed in the certificate details. The average issuance time is 5 calendar days.
Financial, e-commerce, or government websites with high security requirements: Select an EV (Extended Validation) certificate. The most rigorous identity verification standards are applied. This is the highest trust-level certificate. The full organization name is displayed in the certificate details, maximizing user trust. The average issuance time is 5 calendar days.
Question 3: How do you choose a certificate brand?
Global recognition: DigiCert has extensive global market recognition.
Service stability: GeoTrust and GlobalSign are established international certificate service providers.
Cost-sensitive applications: RapidSSL and WoSign provide basic certificate services.
Government and financial applications: CFCA has relevant industry certifications.
SM algorithm (Chinese national cryptography) applications: CFCA, WoSign, vTrus, and Shanghai CA all support SM (Chinese national cryptography) standards.
For more comprehensive selection guidance, see SSL certificate selection guide.
Purchase a certificate
Go to the SSL Certificate Management V2.0 page, click Commercial Certificates > Purchase Certificate, and select one of the following methods to purchase a certificate:
Purchase by Domain Name (Domain Name): This option is for when you have already determined the domain name.
Purchase by Quantity (Certificate Instance Purchase): This method is suitable if you need to purchase certificates in bulk, pre-purchase certificate resources, or have not yet determined the domain names. Because you do not need to provide a domain name during the purchase, you must manually associate a domain name with each certificate and submit an application after the purchase is complete.
Purchase by domain name
Purchase process
Step 1: Purchase options
On the purchase page, configure the certificate by using the following information.
Purchase Method
Select Domain Name.
Domain Name
Enter the domain name for the certificate. The system automatically suggests supported certificate types and brands. To enter multiple domains, type each one and press Enter. A domain name can be up to 253 characters long, and each label cannot exceed 63 characters. You can add up to 250 domain names. The following domain types are supported:
Single Domain: An SSL certificate is attached to a primary domain name, a subdomain, or a public IP address (IPv4). Examples:
aliyun.com,abc.example.com, and1.1.X.X.Wildcard Domain: A wildcard certificate is used to protect a primary domain name and all its first-level subdomains.
Matching rules: Matches only subdomains at the same level. It cannot match subdomains across multiple levels. For example, a certificate for
*.aliyun.comcan matchdemo.aliyun.com, but cannot matchguide.demo.aliyun.com.Limits: By default, a certificate supports only one wildcard domain name. To include multiple wildcard domain names in a single certificate, see Merge certificate requests.
Multiple Domains: A single certificate is issued to protect multiple domains, which can be a combination of Single Domain and Wildcard Domain. We recommend that the number of domains does not exceed 200.
Certificate Type
The available certificate types vary depending on the domain type. For more information, see SSL certificate selection guide.
DV Certificate
Use cases: Personal websites and enterprise test environments.
Average issuance time: 1 to 15 minutes.
Supported domain types: Wildcard Domain, Single Domain, and Multiple Domains.
OV Certificate
Use cases: Government organizations, small and medium-sized enterprises, and educational institutions.
Average issuance time: 5 calendar days.
Supported domain types: Wildcard Domain, Single Domain, and Multiple Domains.
EV Certificate
Use cases: Large enterprises, financial institutions, and e-commerce sites that handle transactions and sensitive data.
Average issuance time: 5 calendar days.
Supported domain types: Single Domain, Multiple Domains.
Certificate Brand
International brands: DigiCert, GeoTrust, GlobalSign, and Rapid. These support international standards (RSA/ECC).
Chinese domestic brands: vTrus, CFCA, and WoSign. These support international standards (RSA) and Chinese domestic standards (SM2).
For more information, see SSL certificate selection guide.
NoteOnly certificates from the GlobalSign brand support binding to domains with the
.rusuffix.Expert Services
Not Required: Do not purchase any technical support services.
Assistance Application: Provides assistance to expedite the issuance of SSL certificates during service hours (9:00–16:00) on business days.
Deployment: Helps you deploy RSA or ECC algorithm certificates during service hours (9:00 to 18:00) on business days.
Assistance Application + Deployment: Provides end-to-end assistance to help you quickly complete the certificate application, issuance, and deployment process. Support is available on non-working days from 9:00 to 20:00.
Deployment (SM Certificate): This service helps you deploy Shang Mi (SM2) algorithm certificates during business hours (9:00–18:00 on workdays) to resolve complex deployment and configuration issues. This option is available only when the certificate type is a Chinese brand certificate, such as CFCA, vTrus, or Wosign.
Automated Management
When you enable this service, the system automatically renews your certificate before it expires. It will consume a credit from your existing hosting plan if one is available; otherwise, a new credit will be automatically purchased. This service automates new certificate applications, DNS record additions, and certificate updates on your cloud products.
Resource Group and Tag Key
Associate an Alibaba Cloud Resource Group and a Tag Key with the certificate for easier future management and search.
Step 2: Select Duration
On the right side of the purchase page, confirm the order information and select the Duration.
A Duration may include multiple certificates with different validity periods. For more information, see Description of validity period changes.
Step 3: Payment
Read and agree to the Certificate Management Service Terms of Service and the Technical Support Agreement for Certificate Management Service, click Buy Now, and complete the payment. After the purchase is complete, you can view the purchased SSL certificate orders on the Order and Refund Management page.
Step 4: View certificate
After the purchase is complete, the certificate is displayed in SSL Certificate Management V2.0 with a status of Pending Application.
Next steps
Submit a certificate request:
If a certificate has the Pending Application status, you must submit a request to a certification authority (CA). A certificate is issued after the CA approves the request.
Complete domain ownership validation:
For certificates in the Validating Application status, you must complete domain ownership validation based on the certificate type.
Modify certificate application information:
If you need to modify the certificate information after purchase, you can perform the Cancel Application operation, and then make the modifications.
Purchase by quantity
Purchase process
Step 1: Purchase options
On the purchase page, configure the certificate by using the following information.
Purchase Method:
Select Certificate Instance Purchase.
Certificate Quantity:
The maximum number of certificates you can purchase at one time is 100.
Domain Type:
Single Domain: An SSL certificate is attached to a primary domain name, a subdomain, or a public IP address (IPv4). Examples:
aliyun.com,abc.example.com, and1.1.X.X.Wildcard Domain: A wildcard certificate is used to protect a primary domain name and all its first-level subdomains.
Matching rules: Matches only subdomains at the same level. It cannot match subdomains across multiple levels. For example, a certificate for
*.aliyun.comcan matchdemo.aliyun.com, but cannot matchguide.demo.aliyun.com.Limits: By default, a certificate supports only one wildcard domain name. To include multiple wildcard domain names in a single certificate, see Merge certificate requests.
Multiple Domains: Used to attach multiple single domain names at the same time. You can attach up to five single domain names. Only single domain names are supported. Wildcard domain names are not supported.
When Domain Type is set to Multiple Domains, you must enter Single Domains and Wildcard Domains.
ImportantIf you purchase multiple certificates, each certificate will support the number of domains that you enter in this field. The SSL Certificate Management V2.0 version currently does not support adding more domains to a certificate. Please confirm the number of domains when you make the purchase.
Certificate Type:
The available certificate types vary depending on the domain type. For more information, see SSL certificate selection guide.
DV Certificate
Use cases: Personal websites and enterprise test environments.
Average issuance time: 1 to 15 minutes.
Supported domain types: Wildcard Domain, Single Domain.
OV Certificate
Use cases: Government organizations, small and medium-sized enterprises, and educational institutions.
Average issuance time: 5 calendar days.
Supported domain types: Wildcard Domain, Single Domain, and Multiple Domains.
EV Certificate
Use cases: Large enterprises, financial institutions, and e-commerce sites that handle transactions and sensitive data.
Average issuance time: 5 calendar days.
Supported domain types: Single Domain, Multiple Domains.
Certificate Brand:
International brands: DigiCert, GeoTrust, GlobalSign, and Rapid. These support international standards (RSA/ECC).
Chinese domestic brands: vTrus, CFCA, and WoSign. These support international standards (RSA) and Chinese domestic standards (SM2).
For more information, see SSL certificate selection guide.
Automated Management:
When you enable this service, the system automatically renews your certificate before it expires. It will consume a credit from your existing hosting plan if one is available; otherwise, a new credit will be automatically purchased. This service automates new certificate applications, DNS record additions, and certificate updates on your cloud products.
Expert Services
Not Required: Do not purchase any technical support services.
Assistance Application: Provides assistance to expedite the issuance of SSL certificates during service hours (9:00–16:00) on business days.
Deployment: Helps you deploy RSA or ECC algorithm certificates during service hours (9:00 to 18:00) on business days.
Assistance Application + Deployment: Provides end-to-end assistance to help you quickly complete the certificate application, issuance, and deployment process. Support is available on non-working days from 9:00 to 20:00.
Deployment (SM Certificate): This service helps you deploy Shang Mi (SM2) algorithm certificates during business hours (9:00–18:00 on workdays) to resolve complex deployment and configuration issues. This option is available only when the certificate type is a Chinese brand certificate, such as CFCA, vTrus, or Wosign.
Resource Group and Tag Key:
Associate a certificate with an Alibaba Cloud Resource Group and a Tag Key for easier management and searching.
Step 2: Select Duration
On the right side of the purchase page, confirm the order information and select the Duration.
A Duration may include multiple certificates with different validity periods. For more information, see Description of validity period changes.
Step 3: Payment
Read and agree to the Certificate Management Service Terms of Service and the Technical Support Agreement for Certificate Management Service, click Buy Now, and complete the payment. After the purchase is complete, you can view the purchased SSL certificate orders on the Order and Refund Management page.
Step 4: View certificate
On the SSL Certificate Management V2.0 page, you can view your purchased certificates.
Next steps
Submit a certificate request:
If a certificate has the Pending Application status, you must submit a request to a certification authority (CA). A certificate is issued after the CA approves the request.
Complete domain ownership validation:
For certificates in the Validating Application status, you must complete domain ownership validation based on the certificate type.
Modify certificate application information:
If you need to modify the certificate information after purchase, you can perform the Cancel Application operation and then make the changes.
Complimentary domain rules
When you purchase a certificate, the system automatically includes a complimentary associated domain if the conditions are met.
Conditions
GlobalSign
DV: The domain validation method must be DNS validation.
OV: No special restrictions.
EV: The domain must be a primary domain name (apex domain).
DigiCert, GeoTrust, RapidSSL, CFCA, vTrus, WoSign, and Shanghai CA
DV: The domain validation method must be DNS validation.
OV, EV: The domain must be a primary domain name (apex domain).
Complimentary domain rules
Single-domain certificate:
Binding a primary domain name automatically includes the
wwwsubdomain. For example, bindingaliyun.comincludeswww.aliyun.com.Binding a
wwwsubdomain automatically includes the primary domain name. For example, bindingwww.aliyun.comincludesaliyun.com.
Wildcard certificate:
Binding a wildcard domain automatically includes the corresponding primary domain name. For example, binding
*.aliyun.comincludesaliyun.com.
Multi-domain certificate:
Only when the first domain meets the complimentary conditions, the system automatically includes a domain associated with the first domain. For example, if the certificate binds
a.aliyun.comandb.aliyun.com, onlywww.a.aliyun.comis included.
FAQ
What should I do if I purchased the wrong certificate specification?
If the certificate specification (such as domain type, brand, or number of domains) is incorrect, take the following action based on the certificate status and purchase time:
Within 7 days of purchase and the certificate has not been issued: Go to the Refund Management page to request a refund, and then purchase the correct certificate.
More than 7 days after purchase or the certificate has been issued: A refund is not available. For security reasons, you can revoke the issued certificate.
What should I do if I purchased the wrong domain orthe domain was entered incorrectly when submitting the certificate application?
If you purchased the wrong domain or the domain was entered incorrectly when submitting the certificate application but the certificate specification is correct, you can perform the Cancel Application operation. After the application is canceled, re-enter the certificate information.