Purchase a commercial certificate

Updated at:

This topic describes how to select and purchase an SSL certificate in Alibaba Cloud Certificate Management Service. It covers quick selection tips based on website type, number of domains, and brand. It also describes the steps for the two purchase methods, Purchase by Domain Name and Purchase by Quantity, the complimentary domain rules, and answers to common questions.

Quick selection

Important

Your answers to the following questions map directly to the options that you set when you Purchase a certificate.

Question 1: How many domains do you need to protect?

  • One domain (such as aliyun.com or login.aliyun.com): Select a Single Domain certificate.

  • All subdomains of one primary domain name (such as *.aliyun.com): Select a Wildcard Domain certificate.

  • Multiple domains (such as aliyun.com, taobao.com, and *.aliyun.com): Select a Multiple Domains certificate.

Note

For some certificates, the system includes one complimentary associated domain. For more information, see Complimentary domain rules.

Question 2: What type of website do you have?

  • A personal website or a development or test environment: Select a DV (Domain Validated) certificate. Only domain ownership is verified. The certificate is issued automatically in 1 to 15 minutes on average, and the cost is low.

  • An enterprise website or an internal information system: Select an OV (Organization Validated) certificate. The organization identity is verified, so security is higher. The certificate details show the organization name. The average issuance time is 5 calendar days.

  • A website with high security requirements, such as a financial, e-commerce, or government website: Select an EV (Extended Validation) certificate. EV certificates use the strictest identity verification standards and provide the highest level of trust. The certificate details show the full organization name, which maximizes user trust. The average issuance time is 5 calendar days.

Question 3: How do you select a certificate brand?

  • You need global recognition: DigiCert is widely recognized in the global market.

  • You value service stability: GeoTrust and GlobalSign are established international certificate service providers.

  • You are cost-sensitive: RapidSSL and WoSign provide basic certificate services.

  • You work in the government or financial industry: CFCA holds the required industry qualifications.

  • You need SM (Chinese national cryptographic) algorithms: CFCA, WoSign, vTrus, and Shanghai CA support SM standards.

Note

The preceding items are quick selection tips. For a more complete selection guide, see SSL certificate selection guide.

Purchase a certificate

Go to the SSL Certificate Management V2.0 page. On the Commercial Certificates tab, click Purchase Certificate. Then, select one of the following purchase methods:

  • Purchase by Domain Name (Domain Name): Use this method if you have already determined the domain and need only one certificate.

  • Purchase by Quantity (Certificate Instance Purchase): Use this method if you need to purchase certificates in bulk, reserve certificate resources in advance, or have not determined the domains yet. You do not need to provide a domain during the purchase. After the purchase, you must associate a domain with each certificate and submit a request.

Purchase by domain name

Purchase process

image

Step 1: Select certificate options

In the Certificate Configuration section, select the options for the certificate that you want to purchase. The options are described as follows:

  • Purchase Method

    Select Domain Name.

  • Domain Name

    Enter the domain that you want to bind to the certificate. The system automatically matches the supported certificate types and brands. To enter multiple domains, type each domain and press Enter. A domain can contain up to 253 characters, and each level of the domain can contain up to 63 characters. You can enter up to 250 domains. The following domain types are supported:

    • Single Domain: An SSL certificate is attached to a primary domain name, a subdomain, or a public IP address (IPv4). Examples: aliyun.com, abc.example.com, and 1.1.X.X.

    • Wildcard Domain: A wildcard certificate is used to protect a primary domain name and all its first-level subdomains.

      • Matching rules: Matches only subdomains at the same level. It cannot match subdomains across multiple levels. For example, a certificate for *.aliyun.com can match demo.aliyun.com, but cannot match guide.demo.aliyun.com.

      • Limits: By default, a certificate supports only one wildcard domain name. To include multiple wildcard domain names in a single certificate, see Merge certificate requests.

    • Multiple Domains: Multiple domains, which can be a combination of Single Domain and Wildcard Domain, are merged into one certificate. The certificate then protects all of these domains. We recommend that you bind no more than 200 domains.

  • Certificate Type

    The available certificate types vary based on the domain type. For more information, see SSL certificate selection guide.

    • DV Certificate

      • Use cases: Personal websites and enterprise test environments.

      • Average issuance time: 1 to 15 minutes.

      • Supported domain types: Wildcard Domain, Single Domain, and Multiple Domains.

    • OV Certificate

      • Use cases: Government organizations, small and medium-sized enterprises, and educational institutions.

      • Average issuance time: 5 calendar days.

      • Supported domain types: Wildcard Domain, Single Domain, and Multiple Domains.

    • EV Certificate

      • Use cases: Large enterprises, financial institutions, e-commerce sites, and other websites that handle payment transactions and private data.

      • Average issuance time: 5 calendar days.

      • Supported domain types: Single Domain and Multiple Domains.

  • Certificate Brand

    • International brands: DigiCert, GeoTrust, GlobalSign, and Rapid support international standards (RSA and ECC).

    • Chinese domestic brands: vTrus, CFCA, and WoSign support the international standard (RSA) and the SM standard (SM2). Shanghai CA supports international standards (RSA and ECC) and the SM standard (SM2).

    For more information, see SSL certificate selection guide.

    Note

    Only GlobalSign certificates can be bound to domains that use the .ru suffix.

Step 2: Select value-added services

When you purchase an SSL certificate, you must select the Automation Service Editions and Value-Added Services that you need. The options are described as follows:

  • Automation Service Edition

    Required. The following options are available:

    • Standard Edition: Includes custom notifications, one-click deployment to cloud services (unlimited), and public domain name monitoring (one domain included).

    • Professional Edition (Recommended): Includes custom notifications, one-click deployment to cloud services (unlimited), public domain name monitoring (one domain included), auto-managed certificate, and server deployment (one node included).

    • Ultimate: Includes custom notifications, one-click deployment to cloud services (unlimited), public domain name monitoring (100 domains included), auto-managed certificate, and server deployment (100 nodes included).

  • Add Value-Added Services

    If you need more domain name monitoring or server deployment quotas than the selected Automation Service Edition includes, purchase additional quotas.

  • Expert Services

    Optional. The following options are available:

    • Not Required: Do not purchase any technical support service.

    • Assistance Application: Helps you obtain an SSL certificate quickly during service hours on business days (09:00 to 16:00).

    • Deployment: Helps you deploy an RSA or ECC certificate during service hours on business days (09:00 to 18:00).

    • Assistance Application + Deployment: Provides end-to-end assistance with the certificate request and deployment process. Support is also available outside business days, from 09:00 to 20:00. This service helps you complete certificate issuance and deployment quickly.

    • Deployment (SM Certificate): Helps you deploy an SM (SM2) certificate during service hours on business days (09:00 to 18:00). SM certificates are complex to deploy and configure. This option is available only for Chinese domestic brands, such as CFCA, vTrus, and WoSign.

Step 3: Configure other settings

The following settings are optional and are not billed.

  • Resource Group and Tag Key

    Associate the certificate with an Alibaba Cloud Resource Group and a Tag Key to manage and find the certificate more easily. If you skip these settings, certificate purchase, request, issuance, and deployment are not affected.

Step 4: Select the Duration

On the right side of the purchase page, confirm the order information and select the Duration that you want to purchase.

Important

A Duration can include multiple certificates that have different validity periods. You must request the next certificate only when the current certificate is about to expire. Certificates cannot be issued in advance. For more information about certificate validity periods, see Changes to certificate validity periods.

Step 5: Confirm the order and pay

Read and accept the Certificate Management Service Terms of Service and the Technical Support Agreement for Certificate Management Service. Then, click Buy Now and complete the payment. After the purchase, you can view your SSL certificate orders on the Order and Refund Management page.

Step 6: View the purchased certificate

After the purchase, the certificate appears in the SSL Certificate Management V2.0 list. The certificate status is Pending Application.

Next steps

  • Submit a certificate request:

    If a certificate has the Pending Application status, you must submit a request to a certification authority (CA). A certificate is issued after the CA approves the request.

  • Complete domain ownership validation:

    If a certificate has the Validating Application status, complete domain ownership validation based on the certificate type.

  • Modify the certificate request information:

    To change the certificate information after the purchase, perform the Cancel Application operation, and then make the changes.

Purchase by quantity

Purchase process

image

Step 1: Select certificate options

On the purchase page, configure the certificate based on the following information.

  • Purchase Method:

    Select Certificate Instance Purchase.

  • Certificate Quantity:

    You can purchase up to 100 certificates at a time.

  • Domain Type:

    • Single Domain: An SSL certificate is attached to a primary domain name, a subdomain, or a public IP address (IPv4). Examples: aliyun.com, abc.example.com, and 1.1.X.X.

    • Wildcard Domain: A wildcard certificate is used to protect a primary domain name and all its first-level subdomains.

      • Matching rules: Matches only subdomains at the same level. It cannot match subdomains across multiple levels. For example, a certificate for *.aliyun.com can match demo.aliyun.com, but cannot match guide.demo.aliyun.com.

      • Limits: By default, a certificate supports only one wildcard domain name. To include multiple wildcard domain names in a single certificate, see Merge certificate requests.

    • Multiple Domains: Used to attach multiple single domain names at the same time. You can attach up to five single domain names. Only single domain names are supported. Wildcard domain names are not supported.

  • If you set Domain Type to Multiple Domains, you must specify Single Domains and Wildcard Domains.

    Important

    If you purchase multiple certificates, each certificate supports the number of domains that you specify here. SSL Certificate Management V2.0 certificates do not support adding domains after the purchase. Confirm the number of domains before you pay.

  • Certificate Type

    The available certificate types vary based on the domain type. For more information, see SSL certificate selection guide.

    • DV Certificate

      • Use cases: Personal websites and enterprise test environments.

      • Average issuance time: 1 to 15 minutes.

      • Supported domain types: Wildcard Domain, Single Domain, and Multiple Domains.

    • OV Certificate

      • Use cases: Government organizations, small and medium-sized enterprises, and educational institutions.

      • Average issuance time: 5 calendar days.

      • Supported domain types: Wildcard Domain, Single Domain, and Multiple Domains.

    • EV Certificate

      • Use cases: Large enterprises, financial institutions, e-commerce sites, and other websites that handle payment transactions and private data.

      • Average issuance time: 5 calendar days.

      • Supported domain types: Single Domain and Multiple Domains.

  • Certificate Brand:

    • International brands: DigiCert, GeoTrust, GlobalSign, and Rapid support international standards (RSA and ECC).

    • Chinese domestic brands: vTrus, CFCA, and WoSign support the international standard (RSA) and the SM standard (SM2). Shanghai CA supports international standards (RSA and ECC) and the SM standard (SM2).

    For more information, see SSL certificate selection guide.

Step 2: Select value-added services

When you purchase an SSL certificate, you must select the Automation Service Editions and Value-Added Services that you need. The options are described as follows:

  • Automation Service Edition

    Required. The following options are available:

    • Standard Edition: Includes custom notifications, one-click deployment to cloud services (unlimited), and public domain name monitoring (one domain included).

    • Professional Edition (Recommended): Includes custom notifications, one-click deployment to cloud services (unlimited), public domain name monitoring (one domain included), auto-managed certificate, and server deployment (one node included).

    • Ultimate: Includes custom notifications, one-click deployment to cloud services (unlimited), public domain name monitoring (100 domains included), auto-managed certificate, and server deployment (100 nodes included).

  • Add Value-Added Services

    If you need more domain name monitoring or server deployment quotas than the selected Automation Service Edition includes, purchase additional quotas.

  • Expert Services

    Optional. The following options are available:

    • Not Required: Do not purchase any technical support service.

    • Assistance Application: Helps you obtain an SSL certificate quickly during service hours on business days (09:00 to 16:00).

    • Deployment: Helps you deploy an RSA or ECC certificate during service hours on business days (09:00 to 18:00).

    • Assistance Application + Deployment: Provides end-to-end assistance with the certificate request and deployment process. Support is also available outside business days, from 09:00 to 20:00. This service helps you complete certificate issuance and deployment quickly.

    • Deployment (SM Certificate): Helps you deploy an SM (SM2) certificate during service hours on business days (09:00 to 18:00). SM certificates are complex to deploy and configure. This option is available only for Chinese domestic brands, such as CFCA, vTrus, and WoSign.

Step 3: Configure other settings

The following settings are optional and are not billed.

  • Resource Group and Tag Key

    Associate the certificate with an Alibaba Cloud Resource Group and a Tag Key to manage and find the certificate more easily. If you skip these settings, certificate purchase, request, issuance, and deployment are not affected.

Step 4: Select the Duration

On the right side of the purchase page, confirm the order information and select the Duration that you want to purchase.

Important

A Duration can include multiple certificates that have different validity periods. You must request the next certificate only when the current certificate is about to expire. Certificates cannot be issued in advance. For more information about certificate validity periods, see Changes to certificate validity periods.

Step 5: Confirm the order and pay

Read and accept the Certificate Management Service Terms of Service and the Technical Support Agreement for Certificate Management Service. Then, click Buy Now and complete the payment. After the purchase, you can view your SSL certificate orders on the Order and Refund Management page.

Step 6: View the purchased certificate

View the purchased certificates on the SSL Certificate Management V2.0 page.

Next steps

  • Submit a certificate request:

    If a certificate has the Pending Application status, you must submit a request to a certification authority (CA). A certificate is issued after the CA approves the request.

  • Complete domain ownership validation:

    If a certificate has the Validating Application status, complete domain ownership validation based on the certificate type.

  • Modify the certificate request information:

    To change the certificate information after the purchase, perform the Cancel Application operation, and then make the changes.

Complimentary domain rules

When you purchase a certificate, the system includes one complimentary associated domain if the conditions are met.

Conditions for a complimentary domain

Note

In this topic, a second-level domain is a domain such as aliyun.com, in which .com is the top-level domain. www.aliyun.com and demo.aliyun.com are third-level domains. demo.doc.aliyun.com is a fourth-level domain, and so on.

DigiCert, GeoTrust, RapidSSL, CFCA, vTrus, WoSign, and Shanghai CA

  • DV: The domain validation method must be DNS validation.

  • OV and EV: The domain must be a second-level domain.

Complimentary domain rules

  • Single-domain certificate:

    • If you bind a primary domain name, the www subdomain is included. For example, if you bind aliyun.com, www.aliyun.com is included.

    • If you bind a www subdomain, the primary domain name is included. For example, if you bind www.aliyun.com, aliyun.com is included.

  • Wildcard certificate:

    • If you bind a wildcard domain, the corresponding primary domain name is included. For example, if you bind *.aliyun.com, aliyun.com is included.

  • Multi-domain certificate:

    • A complimentary domain is included only if the first domain meets the conditions. Only the domain associated with the first domain is included. For example, if the certificate binds a.aliyun.com and b.aliyun.com, only www.a.aliyun.com is included.

FAQ

What do I do if I purchased a certificate with the wrong specifications?

If you selected the wrong specifications, such as the domain type, brand, or number of domains, take action based on the certificate status and the purchase time:

  • Within 7 days of the purchase and the certificate is not issued: Go to the Refund Management page to request a refund, and then purchase a new certificate.

  • More than 7 days after the purchase, or the certificate is issued: Refunds are not supported. For security, you can revoke the issued certificate.

What do I do if I entered the wrong domain during the purchase or when I submitted the certificate request?

If the domain is misspelled during the purchase or in the certificate request, but the certificate specifications are correct, perform the Cancel Application operation. After you cancel the request, enter the certificate information again.

Can I use a certificate that I purchased from a different product page?

Yes. All SSL certificates are managed by Certificate Management Service, no matter whether you purchase them from a cloud service page, the Certificate Management Service console, or another Alibaba Cloud product page. The purchase entry point does not affect the certificate. Certificates that have the same specifications, which include the domain type, certificate type, and brand, use the same request, issuance, and deployment methods.

After the purchase, log on to the Certificate Management Service console. In the left-side navigation pane, choose Certificate Management to go to the SSL Certificate Management page. On the Commercial Certificates tab, you can view and manage all purchased certificates.

If you cannot find a purchased certificate in the list, check whether the order is paid. Go to the Order and Refund Management page to view the order status.