Purchase and allocate compliance certificate quota
After purchasing a Compliance CA, you must purchase a compliance certificate quota to issue server or client certificates. This topic describes how to purchase and allocate a compliance certificate quota.
Prerequisites
You have purchased and enabled a Compliance CA. For more information, see Purchase and enable a Compliance CA.
Purchase a compliance certificate quota
Log in to the Certificate Management Service console.
In the navigation pane on the left, choose . On the Private Certificate Management page, select the region where the PCA service is located.
On the Compliant CA tab, find the target root CA and click Purchase Certificate in the Actions column.
In the Purchase Certificate panel, specify whether to purchase a USB key, enter the number of certificates to purchase, and then click Purchased to complete the payment.
USB Key Included: If you select this option, you pay for USB keys. By default, one USB key is provided for each certificate. After you purchase the USB keys, you must contact technical support through the one-to-one expert service to arrange for shipping.
NoteA USB key is a hardware device with a USB interface that stores your requested certificate and private key for identity authentication and data signing. When you apply for a compliance certificate, you can select a USB key as the key container. For more information, see Apply for a compliance certificate.
USB Key Excluded: If you select this option, no USB keys are included.
ImportantFor a single root CA, if the cumulative number of certificates you purchase exceeds a specific threshold, Certificate Management Service waives the fees for the excess certificates. To learn about the specific threshold, contact our product and technical experts. For more information, see one-to-one expert service.
Allocate a compliance certificate quota
Allocate a root CA's certificate quota to an enabled subordinate CA so it can issue server or client certificates.
Log in to the Certificate Management Service console.
In the navigation pane on the left, choose . On the Private Certificate Management page, select the region where the PCA service is located.
On the Compliant CA tab, find the target root CA and click Assign Certificate in the Remaining Certificates column.
In the Assign Certificate panel, select a subordinate CA, enter the number of certificates to allocate to the CA, and then click OK.
The Remaining certificates value indicates the subordinate CA's current certificate quota.
Next steps
After allocating the compliance certificate quota to a subordinate CA, you can apply for client certificates. For more information, see Apply for a compliance certificate.