After you purchase a private CA, you receive a root CA and an intermediate CA with a default quota of 10 private certificates. If 10 certificates do not meet your requirements, you can purchase additional certificates as needed. This topic describes how to purchase and assign a private certificate quota.
Prerequisites
You have purchased and enabled a private CA. For more information, see Purchase and enable a private CA.
Purchase a private certificate quota
Log in to the Certificate Management Service console.
In the navigation pane on the left, choose Certificate Management > Private Certificate Management. Select the region where the PCA service is located.
On the Private CAs tab, find the target root CA and click Purchase Certificate in the Actions column.
In the Purchase Certificate panel, enter the number of certificates to purchase, click Purchased, and complete the payment.
For a single root CA, if the total number of purchased certificates exceeds a specific threshold, Certificate Management Service waives the fees for certificates beyond that threshold. For the specific threshold, You can contact your account manager for assistance.
Assign a private certificate quota
Assign the root CA certificate quota to an Enabled intermediate CA to issue server certificates or client certificates.
Log in to the Certificate Management Service console.
In the navigation pane on the left, choose Certificate Management > Private Certificate Management. Select the region where the PCA service is located.
On the Private CAs tab, find the target root CA and click Assign Certificate in the Remaining Certificates column.
In the Assign Certificate panel, select the intermediate CA to which you want to assign certificates, enter the remaining certificate quota, and click OK.
Remaining Certificate Quota: is the number of certificates currently assigned to the intermediate CA.
What to do next
After you assign a private certificate quota to an intermediate CA, you can apply for server certificates or client certificates. For more information, see Issue a private certificate.