This topic describes the complete process for selecting and purchasing SSL certificates in Alibaba Cloud Certificate Management Service, including quick selection recommendations based on website type, number of domains, and brand, the purchase procedure, complimentary domain rules, and FAQ.
Quick selection
Your answers to the following questions directly correspond to the configuration options when you Purchase a certificate.
Question 1: How many domains do you need to protect?
A single domain (such as
aliyun.comorlogin.aliyun.com): Select a Single Domain certificate.All subdomains under one primary domain name (such as
*.aliyun.com): Select a Wildcard Domain certificate.Multiple domains (such as
aliyun.com,taobao.com, and*.aliyun.com): Select a Multiple Domains certificate.
When you purchase certain certificates, the system automatically includes a complimentary associated domain. For details, see Complimentary domain rules.
Question 2: What type of website do you have?
Personal websites or development/test environments: Select a DV (Domain Validated) certificate. Only domain ownership is verified. Certificates are automatically issued within an average of 1 to 15 minutes at a lower cost.
Enterprise websites or internal information systems: Select an OV (Organization Validated) certificate. Organizational identity verification is required, providing higher security. The organization name is displayed in the certificate details. The average issuance time is 5 calendar days.
Financial, e-commerce, or government websites with high security requirements: Select an EV (Extended Validation) certificate. The most rigorous identity verification standards are applied. This is the highest trust-level certificate. The full organization name is displayed in the certificate details, maximizing user trust. The average issuance time is 5 calendar days.
Question 3: How do you choose a certificate brand?
Global recognition: DigiCert is recommended.
Service stability: GlobalSign is recommended.
Cost-sensitive applications: Alibaba Cloud is recommended.
For more comprehensive selection guidance, see SSL certificate selection guide.
Purchase a certificate
To acquire a certificate, you must first place a purchase order and then apply to a certificate authority (CA) for issuance.
Step 1: Purchase options
Go to the SSL Certificate Management V2.0 page, click Commercial Certificates > Purchase Certificate, and fill in the required information as described below.
Domain Type:
Single Domain: An SSL certificate is attached to a primary domain name, a subdomain, or a public IP address (IPv4). Examples:
aliyun.com,abc.example.com, and1.1.X.X.Wildcard Domain: A wildcard certificate is used to protect a primary domain name and all its first-level subdomains.
Matching rules: Matches only subdomains at the same level. It cannot match subdomains across multiple levels. For example, a certificate for
*.aliyun.comcan matchdemo.aliyun.com, but cannot matchguide.demo.aliyun.com.Limits: By default, a certificate supports only one wildcard domain name. To include multiple wildcard domain names in a single certificate, see Merge certificate requests.
Multiple Domains: Used to attach multiple single domain names at the same time. You can attach up to five single domain names. Only single domain names are supported. Wildcard domain names are not supported.
Certificate Type:
The available certificate types vary depending on the domain type.
DV: A domain-validated certificate that requires only domain control validation. It is suitable for personal websites, informational sites, or test environments. This is the fastest and most affordable option.
OV: An organization-validated certificate that verifies both the domain and the organization's identity. It is suitable for government organizations, small to medium-sized enterprises, or educational institutions.
OV_PRO: Offers a higher level of encryption and security than a standard OV certificate.
EV: An extended validation certificate that involves the most rigorous corporate verification. It is suitable for large enterprises, financial institutions, and e-commerce sites that handle transactions and sensitive data.
EV_PRO: Offers a higher level of encryption and security than a standard EV certificate.
Brand:
Supports DigiCert, GlobalSign, and Alibaba Cloud. For more information, see SSL certificate selection guide.
ImportantDigiCert does not issue certificates for domains with special suffixes such as
.edu,.gov,.org,.jp,.pay,.bank,.live,.nuclear, or.ru.Domains: You can set this parameter only if you select the Multiple Domains type.
Certificate Instance Quantity: This value is fixed at 1 and cannot be changed.
Service Duration: The duration of the subscription or purchase.
ImportantA subscription period may include multiple certificates with different validity periods. For more information, see Changes to certificate validity periods.
Step 2: Payment
Click Buy Now, read and agree to the Terms of Service, and then click Buy Now to complete the payment. After the purchase is complete, you can view your SSL certificate order on the Order and Refund Management page.
Step 3: View certificate
After you complete the purchase, the certificate appears in the Certificates with a status of Pending Application.
Next steps
If a certificate has the Pending Application status, you must submit a request to a certification authority (CA). A certificate is issued after the CA approves the request.
Complimentary domain rules
When you purchase a certificate, the system automatically includes a complimentary associated domain if the conditions are met.
Conditions
GlobalSign
DV: The domain validation method must be DNS validation.
OV: No special restrictions.
EV: The domain must be a primary domain name (apex domain).
DigiCert
DV: The domain validation method must be DNS validation.
OV, EV: The domain must be a primary domain name (apex domain).
Alibaba Cloud: The bound domain must be the www subdomain corresponding to a primary domain name.
A complimentary primary domain name is provided only when you bind a
wwwsubdomain. For example, bindingwww.aliyun.comincludes the complimentary domainaliyun.com.Binding a domain such as
aliyun.comor*.aliyun.comdoes not include the correspondingwwwsubdomain.
Complimentary domain rules
Single-domain certificate:
Binding a primary domain name automatically includes the
wwwsubdomain. For example, bindingaliyun.comincludeswww.aliyun.com.Binding a
wwwsubdomain automatically includes the primary domain name. For example, bindingwww.aliyun.comincludesaliyun.com.
Wildcard certificate:
Binding a wildcard domain automatically includes the corresponding primary domain name. For example, binding
*.aliyun.comincludesaliyun.com.
Multi-domain certificate:
Only when the first domain meets the complimentary conditions, the system automatically includes a domain associated with the first domain. For example, if the certificate binds
a.aliyun.comandb.aliyun.com, onlywww.a.aliyun.comis included.
FAQ
What should I do if I purchased the wrong certificate specification?
If the certificate specification (such as domain type, brand, or number of domains) is incorrect, take the following action based on the certificate status and purchase time:
Within 7 days of purchase and the certificate has not been issued: Go to the Refund Management page to request a refund, and then purchase the correct certificate.
More than 7 days after purchase or the certificate has been issued: A refund is not available. For security reasons, you can revoke the issued certificate.
What should I do if the domain was entered incorrectly when submitting the certificate application?
If the domain was entered incorrectly when submitting the certificate application but the certificate specification is correct, you can perform the Cancel Application operation. After the application is canceled, re-enter the certificate information.