Revoke an SSL certificate to invalidate it with the CA, or delete expired and revoked certificates to keep your inventory clean.
-
Certificates purchased in SSL Certificate Management V2.0 must be revoked and deleted on the SSL Certificate Management V2.0 page.
-
Legacy certificates purchased before the release of SSL Certificate Management V2.0 must be revoked and deleted on the SSL Certificate Management (V1.0 - New Purchases Discontinued) page.
Revoke SSL certificate
When to revoke
-
Revoke an issued SSL certificate when you need to modify application information, change the bound domain name, or change the encryption algorithm.
ImportantDigiCert DV, Rapid DV, and personal test certificates (Free Edition) do not support domain name changes through revocation and reapplication. You must purchase a new certificate for a different domain.
-
The certificate was issued less than 28 calendar days ago and its domain name has not been changed:
After successful revocation, Alibaba Cloud returns the SSL certificate quota. You can use the returned quota to apply for a new certificate.
NoteThe 28-calendar-day period starts from the issuance time. For example, if a certificate is issued at 12:00:00 on May 1, 2025, the quota is returned only if revocation completes before 12:00:00 on May 29, 2025 and no domain name changes were made.
-
The certificate was issued more than 28 calendar days ago, or its domain name has been changed:
After revocation, Alibaba Cloud does not return the used SSL certificate quota. You must purchase a new certificate.
-
If you cancel your initial certificate application or revoke the certificate and then reapply:
You cannot change the domain name when you reapply. Use the same domain name as in the initial application.
-
-
If an issued SSL certificate is no longer needed, you can revoke it directly.
Revocation rules
-
Each SSL certificate purchase of a specific specification (same brand and type) from Certificate Management Service grants one revocation opportunity for that specification.
-
If a refund was processed for an order of a specific specification, that order does not grant revocation opportunities.
For example, if you purchase five DigiCert OV certificates, you get five revocation opportunities for that specification. After all five are used, no additional revocations can be requested.
-
If a certificate is revoked within 28 calendar days of issuance and its domain name has not been changed, Alibaba Cloud will return the SSL certificate quota.
-
If a certificate is revoked more than 28 calendar days after issuance or after its domain name has been changed, the SSL certificate quota is not returned.
Revocation review period
The CA can take up to 5 business days to process a revocation request. To qualify for a refund, submit the revocation request within 7 calendar days of placing the order. After approval, revocation takes effect within 48 hours.
If you do not allow sufficient time for processing, the revocation may complete after the refund period expires, making you ineligible for a refund.
Procedure
Before you revoke an SSL certificate, ensure that:
-
The certificate was purchased through Alibaba Cloud Certificate Management Service and has been issued.
NoteYou cannot revoke a third-party certificate uploaded to Certificate Management Service. Revoke it from the original provider.
-
The certificate has not expired.
-
The SSL certificate is in the Not hosted state.
Certificate hosting automatically renews the certificate before expiration. If the certificate is revoked, auto-renewal fails. To revoke a hosted certificate, first Cancel Certificate Hosting.
To revoke an SSL certificate:
A revoked certificate cannot be restored. To avoid service disruption, proceed with caution.
Log in to the Certificate Management Service console.
In the navigation pane on the left, choose .
-
On the Commercial Certificates tab, locate the certificate that you want to revoke, and in the Actions column, click More.
-
On the Revoke tab, confirm the revocation information, and then click Confirm Revoke.
-
In the Note dialog box, carefully read the message, and then click OK.
If you are revoking an Extended Validation (EV) certificate, the CA sends a revocation confirmation email. Respond promptly to avoid delays.
After you submit the request, on the Commercial Certificates tab, select Validating Revocation from the status drop-down list to view revocation progress. After approval, revocation takes effect within 48 hours.
If you select Automatic Refund when you submit a certificate revocation request, Alibaba Cloud will automatically initiate the refund process after the certificate revocation is complete.
Delete SSL certificate
-
Deleting a certificate deployed on a cloud service may cause business disruptions.
-
A deleted certificate cannot be recovered. Proceed with caution.
Before you delete a certificate:
-
For a certificate purchased through Certificate Management Service: expired certificates can be deleted directly; unexpired certificates must be revoked first. Revoke an SSL certificate.
-
You can directly delete a third-party certificate uploaded to Certificate Management Service.
-
Check the certificate's deployment status. If deployed on Alibaba Cloud services, assess business risks before deleting.
To delete an SSL certificate:
Log in to the Certificate Management Service console.
In the navigation pane on the left, choose .
-
On the Commercial Certificates tab, locate the certificate that you want to delete, and in the Actions column, click Delete.
-
In the Tip dialog box, click Confirm and Delete.
The certificate is permanently removed from the certificate list.
To batch-delete multiple expired or revoked certificates, filter by Expired or Revoked status, then select and delete them.