A certificate application repository classifies and manages certificates from different sources (issued by Alibaba Cloud or uploaded locally). You can use certificates in a repository for contract signing or data encryption. This topic describes how to create and manage a certificate application repository.
Create a certificate application repository
Log in to the Certificate Management Service console.
In the navigation pane on the left, choose .
On the Certificate Application Repository page, click Create Repository.
In the Create Repository panel, configure the parameters as described in the following table, and then click OK.
Parameter
Description
Repository Name
Custom repository name. No specific naming rules.
Data Source
Upload Certificates
Applicable scenarios:
Manage certificates that you upload, including self-signed certificates, certificates issued by third parties, or certificates issued by Alibaba Cloud.
Use uploaded certificates for signing or data encryption and decryption.
Uploaded CA Certificates
Applicable scenarios:
Manage CA certificates uploaded from your local environment (must include a complete certificate chain).
Used for HTTPS mutual authentication of Alibaba Cloud services, such as HTTPS mutual authentication for load balancing and Anti-DDoS Pro and Anti-DDoS Premium.
NoteFor information about configuring HTTPS listeners for load balancing, see Add an HTTPS listener (ALB), Add a TCPSSL listener (NLB), or Add an HTTPS listener (CLB).
For information about deploying HTTPS mutual authentication with Anti-DDoS Pro and Anti-DDoS Premium, see Add a domain to Anti-DDoS Pro and enable mutual authentication.
Alibaba Cloud Private CA
Applicable scenarios:
Manage Alibaba Cloud private CA certificates across all regions under the current account.
Used for HTTPS mutual authentication of Alibaba Cloud services, such as HTTPS mutual authentication for load balancing and Anti-DDoS Pro and Anti-DDoS Premium.
NoteFor information about configuring HTTPS listeners for load balancing, see Add an HTTPS listener (ALB), Add a TCPSSL listener (NLB), or Add an HTTPS listener (CLB).
For information about deploying HTTPS mutual authentication with Anti-DDoS Pro and Anti-DDoS Premium, see Add a domain to Anti-DDoS Pro and enable mutual authentication.
Alibaba Cloud Private Certificates (not yet supported on the international site)
Applicable scenarios:
Manage Alibaba Cloud private certificates under the current account.
Use private certificates to encrypt OA approval workflows or other data. After the repository is created, call the certificate application repository API to perform encryption operations.
NoteAn intermediate CA that is already associated with another certificate repository cannot be associated again.
Alibaba Cloud Compliant Certificates (not yet supported on the international site)
Applicable scenarios:
Manage Alibaba Cloud compliance certificates under the current account.
Use compliance certificates for electronic signatures or contract signing. Select Scenario to Sign Contract. The contract signing scenario allows you to create a compliance CA and apply for compliance certificates for free.
After obtaining a compliance certificate, you can call the certificate application repository API for contract signing.
NoteAn intermediate CA that is already associated with another certificate repository cannot be associated again.
Manage a certificate application repository
Log in to the Certificate Management Service console.
In the navigation pane on the left, choose .
On the Certificate Application Repository page, find the target certificate application repository, and perform the management operations as described in the following table.
Feature
Scenario
Procedure
Reset a certificate application repository
Applicable to the following scenarios:
You selected the wrong repository type when creating or enabling the certificate application repository, and need to change it.
You no longer use the repository and need to reset it before deletion.
ImportantResetting a repository clears all data in it, and the data cannot be recovered. Proceed with caution.
Click Reset.
In the Tip dialog box, select I understand the risks of the reset operation and confirm the operation., and then click Reset.
Enable a certificate application repository
After resetting a certificate application repository, you need to re-enable it.
Click Enabled.
In the Enabled panel, select the corresponding Data Source, and then click Enabled.
Delete a certificate application repository
You no longer use a certificate application repository and want to delete it.
ImportantOnly certificate application repositories that have been reset can be deleted.
Click Delete.
In the OK dialog box, click Delete.
Rename a certificate application repository
The name was not specified or was incorrect when the repository was created, and needs to be changed.
Hover over the repository name, and click Modify.
Enter a new repository name, and click Save.