All Products
Search
Document Center

Anti-DDoS:DescribeCerts

Last Updated:Nov 25, 2025

Queries all certificates that are available for a domain name. This operation does not query the certificate that is currently in use.

Operation description

You can call this operation to query all certificates that are available for a domain name protected by an Anti-DDoS instance. A domain name can be associated with multiple certificates. For example, a query for a specific domain name can return both a certificate for that specific domain name and a wildcard certificate.

Note

To query the certificate that is currently used by a domain name, call the DescribeWebRules operation to obtain the CertName and CertRegion values. Then, call the ListUserCertificateOrder operation of Certificate Management Service. Use the returned CertName value to query the corresponding certificate ID and other details.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

yundun-ddoscoo:DescribeCerts

get

*All Resource

*

None None

Request parameters

Parameter

Type

Required

Description

Example

ResourceGroupId

string

No

The ID of the resource group to which the Anti-DDoS instance belongs in Resource Management. If you leave this parameter empty, the instance belongs to the default resource group.

default

Domain

string

No

The domain name of your website.

Note

A website forwarding rule must be configured for the domain name. You can call the DescribeDomains operation to query all domain names.

www.aliyun.com

Response elements

Element

Type

Description

Example

object

RequestId

string

The ID of the request.

0bcf28g5-d57c-11e7-9bs0-d89d6717dxbc

Certs

array<object>

The certificate information.

object

EndDate

string

The expiration date of the certificate. The value is a string.

2021-09-12

DomainRelated

boolean

Indicates whether the certificate is associated with the domain name. Valid values:

  • true: The certificate is associated with the domain name.

  • false: The certificate is not associated with the domain name.

true

StartDate

string

The issuance date of the certificate. The value is a string.

2019-09-12

Issuer

string

The certification authority (CA) that issued the certificate.

Symantec

Name

string

The name of the certificate.

testcert

Common

string

The domain name that is associated with the certificate.

www.aliyun.com

Id

integer

The ID of the certificate.

81

CertIdentifier

string

The global certificate ID. The value is a string that consists of the certificate ID and the region ID, separated by a hyphen (-). For example, if the certificate ID is `123` and the region is `cn-hangzhou`, the value of `CertIdentifier` is `123-cn-hangzhou`.

126345-ap-southeast-1

Examples

Success response

JSON format

{
  "RequestId": "0bcf28g5-d57c-11e7-9bs0-d89d6717dxbc",
  "Certs": [
    {
      "EndDate": "2021-09-12",
      "DomainRelated": true,
      "StartDate": "2019-09-12",
      "Issuer": "Symantec",
      "Name": "testcert",
      "Common": "www.aliyun.com",
      "Id": 81,
      "CertIdentifier": "126345-ap-southeast-1"
    }
  ]
}

Error codes

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.