All Products
Search
Document Center

Certificate Management Service:Guide to SSL certificate selection

Last Updated:Jul 29, 2025

Certificate Management Service provides various types and brands of wildcard, multi-domain, and hybrid certificates for different types and scales of websites. This topic describes how to select a certificate that best suits your requirements.

Quick selection

Many factors affect SSL certificate selection, such as your budget, domain name type and quantity, security level, encryption algorithm, and compatibility.

Selection example for individual users

If you have a personal website or blog that is used to display content and does not involve data transmission, you can refer to the table below to select a suitable SSL certificate.

Factor

Business characteristic

Recommended certificate

Domain name type and quantity

The certificate needs to be bound to only one domain name (you have only one website and one single domain name).

Select a single-domain certificate, which can protect only one domain name.

Authentication strength and security level

The verification process of the certificate is simple and fast, and the security level is moderate.

Select a DV certificate. The certificate can be issued in a minimum of 10 minutes because the related certificate authority (CA) verifies only the authenticity of the domain name.

Encryption algorithm

The certificate is compatible with mainstream browsers without special encryption requirements.

Select the RSA algorithm, which is compatible with most browsers.

Certificate brand and budget

The certificate is reliable and cost-effective.

Select an Alibaba Cloud Certificate, which is the most cost-effective.

Selection example for enterprise users

If you are an enterprise user, visit the Certificate Management Service product page to obtain technical support.

Select certificates by scenario

Certificate price

The price of an SSL certificate varies based on factors such as the certificate type and brand.

Select an SSL certificate by

Price overview

The following table describes the prices of single-domain, wildcard domain, and multi-domain certificates. You can select a certificate as needed and budget.

Important

The certificate retail prices are for reference only. The actual prices on the Certificate Service buy page shall prevail.

Price comparison of certificate brands

Certificate brand

Certificate type

Domain name type

Price (USD per certificate-year)

Description

Alibaba Cloud

DV

Single domain name

99

N/A

Wildcard domain name

199

/

DigiCert

DV

Single domain name

149

N/A

Wildcard domain name

629

/

OV

Single domain name

  • OV SSL: 484

  • OV_PRO SSL: 1,325

/

Wildcard domain name

  • OV SSL: 2,309

  • OV_PRO SSL: 4,717

/

EV

Single domain name

  • EV SSL: 1,118

  • EV_PRO SSL: 1,837

/

GlobalSign

DV

Single domain name

249

N/A

Wildcard domain name

849

N/A

OV

Single domain name

349

/

Wildcard domain name

949

/

Multiple domain names

749

By default, includes 5 single domain names.

Domain name type and quantity

You can use a certificate by binding domain names or IP addresses to it. You must determine the type and number of certificates that you want to apply for based on the type and number of domain names pointing to your website.

Select a certificate based on the domain name type and quantity

Alibaba Cloud supports Single-domain, Multi-domain, Wildcard, and Hybrid certificates. The following table describes the differences among different types of domain names and provides certificate-related information.

Domain name type

Description

Precaution

Single domain name

You can bind only one domain name to a single-domain certificate.

Supports DV, OV, and EV certificates.

IP

You can bind only one IP address to an IP certificate.

Only GlobalSign brand OV single-domain certificates support binding to an IP address.

Multiple domain names

You can bind multiple primary domain names, subdomains, or public IPv4 addresses to a multi-domain certificate. If your website has multiple primary domain names or subdomains, we recommend that you select a multi-domain certificate.

Note

When you apply for a multi-domain certificate from Alibaba Cloud, a certificate can include a maximum of 5 single domain names.

If a multi-domain certificate includes public IPv4 addresses, the certificate must be an OV certificate from GlobalSign.

Wildcard domain name

A wildcard domain name can match its primary domain name and all first-level subdomains of the primary domain name. If your website has multiple subdomains at the same level, we recommend that you select a wildcard certificate.

Rules for matching the subdomains of a wildcard domain name:

  • Only subdomains at the same level can be matched. Subdomains at different levels cannot be matched.

    Note

    If you apply for a wildcard certificate for *.aliyundoc.com, the certificate can match second-level subdomains, such as www.aliyundoc.com and example.aliyundoc.com, but cannot match third-level subdomains such as www.demo.aliyundoc.com and developer.demo.aliyundoc.com.

  • When you purchase and apply for a wildcard certificate, you can bind only one domain name to the certificate.

    Note

    You can combine multiple wildcard certificates into one certificate. For more information, see Combine certificates.

You can apply only for DV and OV certificates.

Hybrid domain name

You can bind different types of domain names to a hybrid certificate. For example, you can bind *.aliyundoc.com and demo.example.com to a hybrid certificate.

Note

Alibaba Cloud lets you combine multiple certificates of the same brand and type into a hybrid certificate. You can combine certificates when you purchase or apply for certificates. For more information, see Purchase an official certificate and Combine certificates.

  • OV and EV certificates: You can combine all brands of OV and EV certificates.

  • DV certificates: You can combine DV certificates only from the GlobalSign brands. For GlobalSign DV certificates, they must share the same primary domain name. For example, a certificate for example.com can be combined with certificates for a.example.com and a.b.example.com, but not with certificates for example.cn or example01.com.

Note

After you successfully purchase a certificate, if it meets the default rules for domain name assignment, Alibaba Cloud will automatically assign the corresponding domain name.

Authentication strength and security level

SSL certificates are classified into three types based on their security level, encryption level, and verification method: Domain Validated (DV), Organization Validated (OV), and Extended Validation (EV). These certificate types differ significantly in terms of security, supported brands, and applicable website types.

Select a certificate based on the authentication strength and security level

Alibaba Cloud supports DV, OV, and EV SSL certificates.

Certificate type

Applicable website

Credibility level

Authentication strength

Security level

Verification method and required material

Time required for certificate issuance

DV (Domain Validated)

Personal websites, app services, and enterprise testing.

Note

If you have a personal website but do not have an enterprise business license, you can apply only for DV certificates.

Moderate

Moderate. CAs verify only the authenticity of the website.

Moderate

DNS verification.

1 to 15 minutes

OV (Organization Validated)

Government organizations, small and medium-sized enterprises, or educational institutions.

Note

We recommend that you purchase OV or higher-level digital certificates.

High

High. CAs verify the authenticity of organizations and enterprises.

High

Email or phone call. You must submit the information for domain name ownership verification, a company profile, and a business license.

5 calendar days

EV (Extended Validation)

High-privacy websites that involve transactions, payments, and privacy data, including websites of large-sized enterprises and websites in industries such as finance and e-commerce.

Note

We recommend that you purchase EV certificates.

Highest

Highest, with strict authentication.

Highest

Email or phone call. You must submit the information for domain name ownership verification, a company profile, and a business license.

5 calendar days

Encryption algorithm

SSL certificates use common encryption algorithms such as RSA, ECC. These encryption algorithms differ in security level, performance efficiency, compatibility, and application scenarios.

Select a certificate based on the encryption algorithm

Alibaba Cloud SSL certificates support the RSA, ECC, encryption algorithms. If your business has specific requirements for algorithm type and performance, you can refer to the following information to select a certificate.

  • International standard algorithms:

    • RSA: A widely used asymmetric encryption algorithm that provides the best compatibility and universal applicability.

    • ECC (Elliptic Curve Cryptography): Appeared later than RSA, and compared to RSA, it is more advanced and secure, with faster encryption speed, higher efficiency, and lower resource consumption. It has been promoted in mainstream browsers.

    Note

    Certificates using RSA and ECC algorithms can be used in websites, mini programs, apps, and other application scenarios. However, when ensuring performance, compatibility, and meeting specific compliance requirements, evaluation and planning are necessary.

    Comparison item

    RSA algorithm

    ECC algorithm

    Security and key length

    The algorithm requires a longer key length. Supported key lengths are 2,048 and 4,096 bits.

    The algorithm supports a shorter key length to provide the same level of security as other algorithms.

    • 256-bit: An ECC 256-bit key can provide the same security as an RSA 2,048-bit key.

    • 384-bit: An ECC 384-bit key can provide the same security as an RSA 3,072-bit key.

    Performance efficiency/encryption-decryption speed

    Slow.

    Fast, especially in environments with limited resources, such as mobile and IoT devices.

    Memory and CPU usage

    High.

    Low.

    Compatibility

    Good.

    Good, slightly lower than RSA.

Algorithm support for various brands and types of SSL certificates:

Certificate brand

Certificate type

RSA

ECC

Signature algorithm

Key length

Signature algorithm

Key length

SHA256withECDSA

SHA384withECDSA

2048

4096

prime256v1

secp384r1

SHA256withRSA

SHA384withRSA

DigiCert

DV

绿色对

绿色对

绿色对

绿色对

红色错

红色错

红色错

红色错

OV

绿色对

绿色对

绿色对

绿色对

绿色对

绿色对

绿色对

绿色对

EV

绿色对

绿色对

绿色对

绿色对

红色错

红色错

红色错

红色错

GlobalSign

DV

绿色对

绿色对

绿色对

绿色对

红色错

红色错

红色错

红色错

OV

绿色对

绿色对

绿色对

绿色对

绿色对

绿色对

绿色对

绿色对

Alibaba Cloud

DV

绿色对

绿色对

绿色对

绿色对

红色错

红色错

红色错

红色错

Note

SSL certificate signature algorithms by default use SHA256withRSA or SHA256withECDSA. The Certificate Management Service console does not currently support selecting signature algorithms with the SHA384 hash function. To use such signature algorithms to issue certificates, you need to create a CSR file locally and upload it to the console. For more information, see How do I create a CSR file? and Upload CSR.

Certificate brand

In most cases, the certificate brand is not a primary factor that you need to consider when you select a certificate for the first time. However, when you renew an existing certificate or want to use a certificate of the same brand in new workloads, ensuring certificate brand consistency can streamline decision-making.

Select a certificate based on the certificate brand

Well-known international certificate brands include DigiCert and GlobalSign. When selecting a certificate brand, you must consider the certificate type, signature algorithm type, key length, domain name type, price, your business requirements, and budget.

Note

If you are still unable to determine the certificate brand, you can visit the product page to consult a technical expert for an evaluation.

Certificate brand

CA

Description

DigiCert

DigiCert, Inc.

DigiCert (formerly Symantec) is a well-known and trusted SSL certificate brand in the industry. All DigiCert certificates use prominent encryption technologies to provide enhanced security solutions for different websites and servers.

GlobalSign and Alibaba Cloud

GMO GlobalSign Pte Ltd.

GlobalSign is an early CA in the industry. GlobalSign has been committed to network security authentication and digital certificate services. GlobalSign is a trusted CA and SSL certificate provider. Compared with other certificate brands, Alibaba Cloud certificates are more cost-effective.

References