All Products
Search
Document Center

Certificate Management Service:SSL certificate selection guide

Last Updated:Nov 10, 2025

Certificate Service offers wildcard, multi-domain, and hybrid domain certificates from various brands and in different types. These certificates are suitable for websites of different domain types and sizes. This topic helps you select the most suitable SSL certificate.

Quick selection

Many factors affect SSL certificate selection, such as your budget, domain type and number, security level, encryption algorithm, and compatibility.

Example for personal users

If you have built a personal website or blog that only displays content and does not require data transmission, you can refer to the following table to select a suitable SSL certificate.

Factor

Business feature

Recommended selection

Domain type and quantity

Binds to only one domain name (you have one website and one single domain name).

Select a single-domain certificate. One SSL certificate protects one domain name.

Validation strength and security level

The certificate issuance and validation process is simple and fast, but the security level is standard.

Select a DV certificate. The CA validates only the authenticity of the domain name. The certificate can be issued in as little as 10 minutes.

Certificate encryption algorithm

No special encryption requirements. The certificate only needs to be compatible with mainstream browsers.

Select the RSA algorithm. It is compatible with almost all browsers.

Certificate brand and budget

Guaranteed and low-priced

Select the Alibaba Cloud Brand for a lower price.

Example for enterprise users

If you are an enterprise user, visit the product page to consult with a technical expert.

Selection by scenario

Certificate price

The price of an SSL certificate depends on factors such as the certificate type and brand.

Select an SSL certificate based on the price

Price overview

The following table lists the prices of single-domain, wildcard domain, and multi-domain SSL certificates for each brand. Select a certificate based on your requirements and budget.

Important

The retail prices of certificates are for reference only. For actual prices, see the Certificate Service purchase page.

Price comparison of certificate brands

Certificate brand

Certificate type

Domain type

Price (USD/certificate/year)

Remarks

Alibaba Cloud

DV

Single domain name

99

/

Wildcard domain name

199

/

DigiCert

DV

Single domain name

149

/

Wildcard domain name

629

/

OV

Single domain name

  • OV SSL: 484

  • OV_PRO SSL: 1,325

/

Wildcard domain name

  • OV SSL: 2,309

  • OV_PRO SSL: 4,717

/

EV

Single domain name

  • EV SSL: 1,118

  • EV_PRO SSL: 1,837

/

GlobalSign

DV

Single domain name

249

/

Wildcard domain name

849

/

OV

Single domain name

349

/

Wildcard domain name

949

/

Multi-domain

749

Includes five single-domain names by default.

Website domain type and quantity

An SSL certificate is effective only after it is associated with a domain name or IP address. The type and number of domain names associated with your website determine the type and number of SSL certificates that you need.

Select an SSL certificate based on the website domain type and quantity

You can apply for Single-domain, Multi-domain, Wildcard Domain, and Hybrid Domain certificates in Alibaba Cloud. The following table describes the differences between these certificate types.

Domain type

Selection guide

Notes

Single domain name

One certificate can be associated with only one domain name.

You can apply for DV, OV, and EV certificates.

IP

One certificate can be associated with only one IP address.

Only OV single-domain certificates of the GlobalSign, DigiCert brands can be associated with IP addresses.

Multi-domain

One certificate can be associated with multiple single domain names (primary domain names, subdomains, or public IPv4 addresses). If your website has multiple primary domain names or subdomains, you can select a multi-domain certificate.

Note

When you apply for a multi-domain certificate through Alibaba Cloud, the certificate can include up to five single-domain names.

If a multi-domain certificate includes a public IPv4 address, the SSL certificate must be an OV single-domain certificate of the GlobalSign, DigiCert brand.

Wildcard domain name

A wildcard domain name includes a primary domain name and all its subdomains at the next level. If your website has multiple subdomains under a primary domain name, you need to purchase only one wildcard certificate.

The matching rules for wildcard domain names are as follows:

  • A wildcard certificate can match only subdomains at the same level. It cannot match subdomains across levels.

    Note

    A first-level wildcard certificate for *.aliyundoc.com can match second-level subdomains such as www.aliyundoc.com and example.aliyundoc.com, but cannot match third-level subdomains such as www.demo.aliyundoc.com and developer.demo.aliyundoc.com.

  • During the purchase and application phase, one certificate can include only one wildcard domain name.

    Note

    For more information about how to merge multiple wildcard domain certificates into a single certificate, see Merged certificate application.

You can apply for only DV and OV certificates.

Hybrid domain name

A hybrid domain certificate is a single certificate that includes multiple types of domain names. For example, a certificate that is associated with both *.aliyundoc.com and demo.example.com is a hybrid domain certificate.

Note

Alibaba Cloud lets you generate a hybrid domain certificate by merging multiple certificates of the same brand and type. You can choose to merge and issue the certificates directly during the purchase phase or during the subsequent certificate application. For more information, see Purchase a commercial certificate or Merged certificate application.

  • OV and EV certificates: All brands are supported.

  • DV certificates: Only the GlobalSign brands support merged applications for DV certificates. For DV certificates of the GlobalSign brand, the primary domain names must be the same. For example, you can merge certificates for a.example.com and a.b.example.com with a certificate for example.com, but you cannot merge certificates for example.cn or example01.com.

Note

After you purchase a certificate, Alibaba Cloud provides a corresponding domain name free of charge if the purchase meets the conditions. For more information, see Purchase a commercial certificate.

Validation strength and security

SSL certificates are classified into three types based on security, encryption level, and verification method: DV (Domain Validated), OV (Organization Validated), and EV (Extended Validation). These certificate types differ significantly in security, supported brands, and the types of websites for which they are suitable.

Select an SSL certificate based on the security and validation strength

Alibaba Cloud offers DV, OV, and EV SSL certificates.

Certificate type

Applicable website type

Trust level

Authentication strength

Security

Verification method and documents

Average issuance time

DV (Domain Validated)

Personal websites, app services, and enterprise testing.

Note

For a personal website without a business license, you can apply only for a DV certificate.

Standard

Standard. The CA verifies only the authenticity of the personal website.

Standard

DNS verification.

1 to 15 minutes

OV (Organization Validated)

Government organizations, small and medium-sized enterprises (SMEs), and educational institutions.

Note

We recommend that you purchase an OV or EV certificate.

High

High. The CA verifies the authenticity of the organization or enterprise.

High

Email or phone. You must submit the domain name for verification, company information, and business license.

5 calendar days

Extended Validation (EV)

Large enterprises, financial institutions, and e-commerce websites that involve transaction payments and private data.

Note

We recommend that you purchase an EV certificate.

Highest

Highest. Strict authentication is required.

Highest

Email or phone. You must submit the domain name for verification, company information, and business license.

5 calendar days

Certificate encryption algorithm

Common encryption algorithms for SSL certificates include RSA, ECC. These encryption algorithms differ in security level, performance, efficiency, compatibility, and application scenarios.

Select an SSL certificate based on the encryption algorithm

Alibaba Cloud SSL certificates support the RSA, ECC encryption algorithms. If your business has requirements for the algorithm type and performance, you can refer to the following information to select a certificate.

  • International standard algorithms:

    • RSA: A widely used asymmetric key encryption algorithm that provides the best compatibility and general applicability.

    • ECC (Elliptic Curve Cryptography): ECC was developed after RSA. Compared with RSA, ECC is more advanced and secure. It also provides faster encryption, higher efficiency, and lower resource consumption. ECC has been widely adopted by mainstream browsers.

    Note

    SSL certificates that use the RSA or ECC algorithm can be used in application scenarios such as websites, miniapps, and apps. However, you must perform an evaluation and plan accordingly to ensure performance and compatibility and meet specific compliance requirements.

    Comparison

    RSA algorithm

    ECC algorithm

    Security and key length

    Requires a long key. Supported key lengths are 2,048 bits and 4,096 bits.

    Achieves the same security level with a relatively short key.

    • 256 bits: provides the same level of security as a 2,048-bit RSA key.

    • 384 bits: provides the same level of security as a 3,072-bit RSA key.

    Performance/Encryption and decryption speed

    Slow.

    Fast. Performs better in resource-constrained environments, such as on mobile devices and Internet of Things (IoT) devices.

    Memory and CPU usage

    High.

    Low.

    Compatibility

    Good.

    Good, but slightly less compatible than RSA.

Algorithm support for SSL certificates of different brands and types:

Certificate brand

Certificate type

RSA

ECC

Signature algorithm

Key length

Signature algorithm

Key length

SHA256withECDSA

SHA384withECDSA

2048

4096

prime256v1

secp384r1

SHA256withRSA

SHA384withRSA

DigiCert

DV

绿色对

绿色对

绿色对

绿色对

红色错

红色错

红色错

红色错

OV

绿色对

绿色对

绿色对

绿色对

绿色对

绿色对

绿色对

绿色对

EV

绿色对

绿色对

绿色对

绿色对

红色错

红色错

红色错

红色错

GlobalSign

DV

绿色对

绿色对

绿色对

绿色对

红色错

红色错

红色错

红色错

OV

绿色对

绿色对

绿色对

绿色对

绿色对

绿色对

绿色对

绿色对

Alibaba Cloud

DV

绿色对

绿色对

绿色对

绿色对

红色错

红色错

红色错

红色错

Note

The default signature algorithm for SSL certificates is SHA256withRSA or SHA256withECDSA. You cannot select a signature algorithm with a SHA384 hash function in the Certificate Service console. To use this signature algorithm to issue a certificate, you must create a CSR file on your computer and upload the CSR file to the console. For more information, see How do I create a CSR file? and Upload a CSR file.

Certificate brand

The certificate brand is generally not the primary factor to consider when you select a certificate for the first time. However, if you want to renew a certificate or continue to use the same brand for new services, you can prioritize the certificate brand to narrow down your options and purchase a certificate of the same brand and specifications.

Select an SSL certificate based on the certificate brand

Well-known international brands include DigiCert and GlobalSign. When you select a certificate brand, consider factors such as the supported certificate types, signature algorithm types, key lengths, domain types, and prices. Make a comprehensive decision based on your needs and budget.

Note

If you are still unsure about which certificate brand to choose, you can visit the product page.

Certificate brand

Certification authority (CA)

Description

DigiCert

DigiCert, Inc.

DigiCert (formerly Symantec) is a well-known CA and a trusted SSL certificate brand. All its certificates use industry-leading encryption technologies to provide security solutions for different websites and servers.

GlobalSign, Alibaba Cloud

GMO GlobalSign Pte Ltd.

GlobalSign is one of the earliest CAs. It has been dedicated to network security authentication and digital certificate services and is a trusted CA and SSL digital certificate provider. Compared with other brands, Alibaba Cloud certificates are more affordable.

References