Certificate Management Service provides various types and brands of wildcard, multi-domain, and hybrid certificates for different types and scales of websites. This topic describes how to select a certificate that best suits your requirements.
Quick selection
Many factors affect SSL certificate selection, such as your budget, domain name type and quantity, security level, encryption algorithm, and compatibility.
Selection example for individual users
If you have a personal website or blog that is used to display content and does not involve data transmission, you can refer to the table below to select a suitable SSL certificate.
Factor | Business characteristic | Recommended certificate |
Domain name type and quantity | The certificate needs to be bound to only one domain name (you have only one website and one single domain name). | Select a single-domain certificate, which can protect only one domain name. |
Authentication strength and security level | The verification process of the certificate is simple and fast, and the security level is moderate. | Select a DV certificate. The certificate can be issued in a minimum of 10 minutes because the related certificate authority (CA) verifies only the authenticity of the domain name. |
Encryption algorithm | The certificate is compatible with mainstream browsers without special encryption requirements. | Select the RSA algorithm, which is compatible with most browsers. |
Certificate brand and budget | The certificate is reliable and cost-effective. | Select an Alibaba Cloud Certificate, which is the most cost-effective. |
Select certificates by scenario
Certificate price
The price of an SSL certificate varies based on factors such as the certificate type and brand.
Select an SSL certificate by
Price overview
The following table describes the prices of single-domain, wildcard domain, and multi-domain certificates. You can select a certificate as needed and budget.
Price comparison of certificate brands
Certificate brand | Certificate type | Domain name type | Price (USD per certificate-year) | Description |
|
Alibaba Cloud | DV | Single domain name | 99 | N/A |
Wildcard domain name | 199 | / |
DigiCert | DV | Single domain name | 149 | N/A |
Wildcard domain name | 629 | / |
OV | Single domain name | OV SSL: 484 OV_PRO SSL: 1,325
| / |
Wildcard domain name | OV SSL: 2,309 OV_PRO SSL: 4,717
| / |
EV | Single domain name | EV SSL: 1,118 EV_PRO SSL: 1,837
| / |
GlobalSign | DV | Single domain name | 249 | N/A |
Wildcard domain name | 849 | N/A |
OV | Single domain name | 349 | / |
Wildcard domain name | 949 | / |
Multiple domain names | 749 | By default, includes 5 single domain names. |
Domain name type and quantity
You can use a certificate by binding domain names or IP addresses to it. You must determine the type and number of certificates that you want to apply for based on the type and number of domain names pointing to your website.
Select a certificate based on the domain name type and quantity
Alibaba Cloud supports Single-domain, Multi-domain, Wildcard, and Hybrid certificates. The following table describes the differences among different types of domain names and provides certificate-related information.
Domain name type | Description | Precaution |
Single domain name | You can bind only one domain name to a single-domain certificate. | Supports DV, OV, and EV certificates. |
IP | You can bind only one IP address to an IP certificate. | Only GlobalSign brand OV single-domain certificates support binding to an IP address. |
Multiple domain names | You can bind multiple primary domain names, subdomains, or public IPv4 addresses to a multi-domain certificate. If your website has multiple primary domain names or subdomains, we recommend that you select a multi-domain certificate.
Note When you apply for a multi-domain certificate from Alibaba Cloud, a certificate can include a maximum of 5 single domain names. | If a multi-domain certificate includes public IPv4 addresses, the certificate must be an OV certificate from GlobalSign. |
Wildcard domain name | A wildcard domain name can match its primary domain name and all first-level subdomains of the primary domain name. If your website has multiple subdomains at the same level, we recommend that you select a wildcard certificate. Rules for matching the subdomains of a wildcard domain name: Only subdomains at the same level can be matched. Subdomains at different levels cannot be matched.
Note If you apply for a wildcard certificate for *.aliyundoc.com, the certificate can match second-level subdomains, such as www.aliyundoc.com and example.aliyundoc.com, but cannot match third-level subdomains such as www.demo.aliyundoc.com and developer.demo.aliyundoc.com. When you purchase and apply for a wildcard certificate, you can bind only one domain name to the certificate.
Note You can combine multiple wildcard certificates into one certificate. For more information, see Combine certificates.
| You can apply only for DV and OV certificates. |
Hybrid domain name | You can bind different types of domain names to a hybrid certificate. For example, you can bind *.aliyundoc.com and demo.example.com to a hybrid certificate.
Note Alibaba Cloud lets you combine multiple certificates of the same brand and type into a hybrid certificate. You can combine certificates when you purchase or apply for certificates. For more information, see Purchase an official certificate and Combine certificates. | OV and EV certificates: You can combine all brands of OV and EV certificates. DV certificates: You can combine DV certificates only from the GlobalSign brands. For GlobalSign DV certificates, they must share the same primary domain name. For example, a certificate for example.com can be combined with certificates for a.example.com and a.b.example.com, but not with certificates for example.cn or example01.com.
|
Authentication strength and security level
SSL certificates are classified into three types based on their security level, encryption level, and verification method: Domain Validated (DV), Organization Validated (OV), and Extended Validation (EV). These certificate types differ significantly in terms of security, supported brands, and applicable website types.
Select a certificate based on the authentication strength and security level
Alibaba Cloud supports DV, OV, and EV SSL certificates.
Certificate type | Applicable website | Credibility level | Authentication strength | Security level | Verification method and required material | Time required for certificate issuance |
DV (Domain Validated) | Personal websites, app services, and enterprise testing.
Note If you have a personal website but do not have an enterprise business license, you can apply only for DV certificates. | Moderate | Moderate. CAs verify only the authenticity of the website. | Moderate | DNS verification. | 1 to 15 minutes |
OV (Organization Validated) | Government organizations, small and medium-sized enterprises, or educational institutions.
Note We recommend that you purchase OV or higher-level digital certificates. | High | High. CAs verify the authenticity of organizations and enterprises. | High | Email or phone call. You must submit the information for domain name ownership verification, a company profile, and a business license. | 5 calendar days |
EV (Extended Validation) | High-privacy websites that involve transactions, payments, and privacy data, including websites of large-sized enterprises and websites in industries such as finance and e-commerce.
Note We recommend that you purchase EV certificates. | Highest | Highest, with strict authentication. | Highest | Email or phone call. You must submit the information for domain name ownership verification, a company profile, and a business license. | 5 calendar days |
Encryption algorithm
SSL certificates use common encryption algorithms such as RSA, ECC. These encryption algorithms differ in security level, performance efficiency, compatibility, and application scenarios.
Select a certificate based on the encryption algorithm
Alibaba Cloud SSL certificates support the RSA, ECC, encryption algorithms. If your business has specific requirements for algorithm type and performance, you can refer to the following information to select a certificate.
Algorithm support for various brands and types of SSL certificates:
Certificate brand | Certificate type | RSA | ECC |
Signature algorithm | Key length | Signature algorithm | Key length |
SHA256withECDSA | SHA384withECDSA | 2048 | 4096 | prime256v1 | secp384r1 | SHA256withRSA | SHA384withRSA |
DigiCert | DV | 
| 
| 
| 
| 
| 
| 
| 
|
OV | 
| 
| 
| 
| 
| 
| 
| 
|
EV | 
| 
| 
| 
| 
| 
| 
| 
|
GlobalSign | DV | 
| 
| 
| 
| 
| 
| 
| 
|
OV | 
| 
| 
| 
| 
| 
| 
| 
|
Alibaba Cloud | DV | 
| 
| 
| 
| 
| 
| 
| 
|
Note SSL certificate signature algorithms by default use SHA256withRSA or SHA256withECDSA. The Certificate Management Service console does not currently support selecting signature algorithms with the SHA384 hash function. To use such signature algorithms to issue certificates, you need to create a CSR file locally and upload it to the console. For more information, see How do I create a CSR file? and Upload CSR.
Certificate brand
In most cases, the certificate brand is not a primary factor that you need to consider when you select a certificate for the first time. However, when you renew an existing certificate or want to use a certificate of the same brand in new workloads, ensuring certificate brand consistency can streamline decision-making.
Select a certificate based on the certificate brand
Well-known international certificate brands include DigiCert and GlobalSign. When selecting a certificate brand, you must consider the certificate type, signature algorithm type, key length, domain name type, price, your business requirements, and budget.
Note If you are still unable to determine the certificate brand, you can visit the product page to consult a technical expert for an evaluation.
Certificate brand | CA | Description |
DigiCert | DigiCert, Inc. | DigiCert (formerly Symantec) is a well-known and trusted SSL certificate brand in the industry. All DigiCert certificates use prominent encryption technologies to provide enhanced security solutions for different websites and servers. |
GlobalSign and Alibaba Cloud | GMO GlobalSign Pte Ltd. | GlobalSign is an early CA in the industry. GlobalSign has been committed to network security authentication and digital certificate services. GlobalSign is a trusted CA and SSL certificate provider. Compared with other certificate brands, Alibaba Cloud certificates are more cost-effective. |
References