Certificate Management Service is an Alibaba Cloud platform for issuing and managing digital certificates. It provides full lifecycle management for SSL certificates, private certificates, HTTPS acceleration gateways, and certificate application repositories.
Scenarios
Scenario 1: Public HTTPS encryption
Internet-facing services require HTTPS for secure access. Certificate Management Service provides two solutions:
-
SSL certificate: Deploy certificates directly to existing infrastructure such as web servers, SLB, or CDN. Best for scenarios requiring specific certificate brands, types, or configurations.
-
HTTPS Acceleration Gateway: Enable HTTPS for a domain with one click—no need to manage certificate application, renewal, or deployment. Also provides website acceleration.
SSL certificate
After you purchase an SSL certificate, submit a certificate application. Certificate Management Service forwards the application to the CA. After the CA issues the certificate, deploy it to a web server, CDN, or other cloud products.
HTTPS Acceleration Gateway
After you purchase an HTTPS Acceleration Gateway, configure your origin server and point your domain to the gateway-assigned address to enable HTTPS automatically. The gateway integrates CDN caching and edge distribution to improve performance.
Scenario 2: Internal enterprise HTTPS encryption
For internal services such as OA, ERP, DevOps platforms, code repositories, and IoT devices, public certificates can be costly and restrictive due to fixed validity periods and domain validation requirements. The Private Certificate Authority (PCA) service lets you create a private root CA to issue and manage internal certificates. You can customize validity, batch-issue certificates, and instantly revoke abnormal ones—building a unified internal trust system at lower cost.
Private certificates are trusted only within your enterprise. Public browsers do not trust them. You must install the root certificate or client certificate on your internal enterprise devices.
Benefits
-
Authoritative brands: Trusted certificates from well-known domestic and international CAs, available in multiple brands and types.
-
Convenient management: Unified full-lifecycle management with centralized control over certificates on-premises and in the cloud.
-
Efficient deployment: Tightly integrated with Alibaba Cloud products for one-click certificate deployment.
-
Comprehensive services: Covers certificate management, HTTPS Acceleration Gateway, certificate application repository, and certificate hosting.
-
Open and flexible: Rich API operations for batch and automated certificate management.
Core concepts
-
Digital Certificate
A credential issued by a trusted CA containing a public key and entity information. Used to establish secure communication and verify identity. Valid only within its specified validity period.
-
Certificate Authority (CA)
A globally trusted third-party organization that verifies applicant identity and issues digital certificates. The trust anchor of a public key infrastructure.
-
SSL certificate and HTTPS
An SSL certificate enables HTTPS encrypted transmission. After deployment, communication between the browser and server is encrypted, preventing eavesdropping and tampering.
-
Private certificate
Issued by an enterprise-created private CA for encrypted communication between internal systems, such as internal applications and IoT devices.
Features
SSL certificates
The service provides full lifecycle management for certificates, which covers selection, purchase, creation, application, deployment, renewal, and revocation.
PCA certificates
Build a private certificate management platform through a visual interface. Self-service issuance and management of internal certificates with identity authentication and data encryption for internal network security.
HTTPS Acceleration Gateway
An integrated HTTPS solution combining certificate hosting and access acceleration. Simple configuration enables HTTPS and acceleration for domain names. Automatic certificate renewal reduces O&M costs.
Certificate application repository
Centralized management of certificates from Alibaba Cloud and third-party platforms. API operations support signing, signature verification, and encryption/decryption for sensitive data such as electronic contracts and invoices.
Domain name monitoring service
Periodically monitors HTTPS status of public websites, checking SSL configuration and certificate expiration. Displays results, recommendations, and reports in the console to enable proactive certificate O&M and prevent outages from expired certificates.
Certificate message notifications
Supports custom message notifications for domain monitoring exceptions, API exceptions, and certificate lifecycle events. Notification methods include email, DingTalk, internal messages, and phone calls.
Certificate tools
Free tools to view CSR information and certificate details, check SSL status, and convert certificate formats. This provides professional technical support for certificate application, configuration, and deployment.
Billing
Certificate Management Service charges for the following items: SSL certificates, PCA certificates, HTTPS Acceleration Gateway, and public domain name monitoring. For more information about billing, see Billing Overview of SSL Certificates, PCA certificate billing, HTTPS acceleration gateway billing, and Domain name monitoring billing.
Getting started
SSL certificate
-
Learn about the service: To understand the concepts and processes related to SSL certificates, see Core concepts, What is an SSL certificate?, SSL certificate workflow.
-
Purchase a certificate: Select the certificate specifications that meet your business requirements by referring to the SSL certificate selection. Then, Purchase a commercial certificate.
-
Apply for issuance: Create an SSL certificate and then Submit a CA application. Work with the CA to complete Domain ownership verification and wait for the certificate to be issued.
-
Deploy and use: After the certificate is issued, determine a deployment plan by referring to Select a certificate deployment method. Then, deploy the certificate to your server or cloud products.
-
Manage the certificate: SSL certificate renewal and expiration before it expires to prevent business interruptions. Revoke and delete SSL certificates when it is no longer needed.
HTTPS Acceleration Gateway
-
Learn about the service: To understand the benefits and scenarios of HTTPS Acceleration Gateway, see What is HTTPS acceleration gateway?.
-
Purchase the service: Purchase an HTTPS Acceleration Gateway instance and gateway resource units based on your domain name type. For more information, see Purchase an HTTPS acceleration gateway.
-
Configure the domain name: Configure the accelerated domain name and set a CNAME record for forwarding in DNS. For more information, see Configure an HTTPS acceleration gateway.
-
Manage the certificate: No manual certificate application needed. After configuration takes effect, monitor access status to prevent interruptions from overdue payments.
PCA certificate
-
Learn about the service: For information about common scenarios and how to use the service, see What is Private Certificate Authority (PCA)?. To apply for a free trial, see Free trial for PCA.
-
Purchase a certificate: Purchase and enable a private CA, and then Purchase and assign a quota on private certificates.
-
Apply for issuance: Complete private certificate issuance. For more information, see Issue a private certificate.
-
Deploy and use: Download a private certificate, and then deploy the certificates to servers and clients.
-
Manage the certificate: For more information, see Revoke a private certificate, and Reset a private CA.
FAQ
After I purchase an HTTPS Acceleration Gateway, do I still need to purchase a certificate for my domain name?
No. After you purchase an HTTPS Acceleration Gateway, a certificate is automatically attached to your domain name.
What if I do not understand the basic concepts of SSL certificates?
If you are new to SSL certificates, read the following documents:
-
What is an SSL certificate?: Covers encryption principles, workflow, and brands of SSL certificates.
-
SSL certificate workflow: Covers the SSL certificate process: purchase, application, validation, issuance, deployment, and management.
How do I select the right certificate for my business?
If you are not sure which type of certificate is suitable for your business scenario, see SSL certificate selection.
How can non-technical users get technical support?
You can visit the product details page to request an assessment from our technical experts.