All Products
Document Center

Certificate Management Service:Apply for a free trial of PCA

Last Updated:Aug 25, 2023

Private Certificate Authority (PCA) allows you to build a private certificate authority (CA) platform for your enterprise after simple operations. Then, you can issue and use private certificates to authenticate applications and encrypt and decrypt the data of your enterprise. This topic describes how to apply for a free trial of PCA.

Intended users

  • Users who need to build a private CA platform within enterprises for internal use

  • Users whose Alibaba Cloud accounts are not used to purchase a private CA


  • Each Alibaba Cloud account can apply for a free trial of PCA only once. The free trial period is 30 days and starts from the day when the free trial application is approved.

  • After you apply for a free trial of PCA, you can use private CAs instead of compliant CAs. Private CAs are only for internal use, and no regulatory requirements are imposed. Compliant CAs are used to ensure compliance, and regulatory requirements are imposed.


  1. Log on to the Certificate Management Service console.
  2. In the left-side navigation pane, click Private Certificates.
  3. On the Private CAs tab, click Start Free Trial.

  4. In the Free Trial panel, select the encryption algorithm that you want to use and click OK.

    The following encryption algorithms are supported:

    • RSA: The RSA algorithm is an asymmetric algorithm that is widely used in the world and provides high compatibility. This is the default value.
    • ECC: The ECC algorithm is an encryption algorithm based on elliptic curves.

      Compared with the RSA algorithm, the ECC algorithm is more advanced and secure. The ECC algorithm provides faster encryption and higher efficiency at lower server resource consumption. The ECC algorithm is promoted among mainstream browsers.

    • SM2: The SM2 algorithm is developed and approved by the State Cryptography Administration of China based on the ECC algorithm. The SM2 algorithm is used to replace the RSA algorithm in Chinese commercial cryptography systems.
  5. In the Note message, click OK.

    After you apply for a free trial of PCA, Certificate Management Service automatically creates a private root CA and a private intermediate CA. The private root CA provides a quota of 10 private certificates.

    You can use the private root CA and private intermediate CA to build a private CA platform within your enterprise. For more information, see Purchase and enable a private CA.

What do I do after the free trial period ends?

The private root CA and private intermediate CA that are created for the free trial are valid for 30 days. After 30 days, you can no longer use the private root CA or private intermediate CA, and all private certificates that are issued by the private intermediate CA become invalid. If you want to continue using PCA, you must renew the private root CA. For more information, see PCA billing.