This topic describes the workflow for using an SSL certificate, from purchase and request to validation, issuance, deployment, and management.
Workflow overview
Workflow description
Purchase a certificate
Select a certificate type as needed. For more information, see SSL certificate selection guide.
Provide your purchase information. For details, see Purchase an official certificate .
Create a certificate
After you purchase a certificate, you must create an SSL certificate to associate your purchased quota with a domain name. During the creation process, the system provides a Quick Issue option:
Select Quick Issue: You are required to fill in the application information. After the certificate is created, the system will automatically submit the certificate application to the CA. Subsequently, you only need to complete domain ownership validation.
Do not select Quick Issue: After the certificate is created, you must log on to the Certificate Management Service console to manually fill in and submit the application. For details, see Submit a request to a CA.
The certificate list shows only certificates that are attached to domain names. Unattached certificates appear after you complete the Create Certificate operation.
Request a certificate
Submit a request to a CA
You must enter information based on the certificate type, such as the associated domain name or IP address, contact, company, and business license information. Then, submit the CSR to the CA. For more information, see Request a certificate.
Domain ownership validation
When you submit a request to the CA, you must validate the ownership of your domain name. For more information, see Domain ownership validation.
Domain Validated (DV) certificates support three authentication methods: Automatic DNS Verification, Manual DNS Verification, and File Verification.
For Extended Validation (EV) or Organization Validated (OV) certificates, you must complete the validation based on the instructions in the domain validation email sent by the CA.
CA review
After you submit the request and complete domain ownership validation, the CA reviews your request. To view the review progress and result, see Handle CA review results. DV certificates are typically issued within 1 to 15 minutes. OV and EV certificates are typically issued within 5 calendar days.
Deploy the certificate
After the CA approves your request and the certificate status changes to "Issued", you can deploy the certificate file to your web server, such as Nginx, Apache, or IIS, or to a cloud product. This enables HTTPS for your site. For more information, see Deploy an SSL certificate.
If your server is in the Chinese mainland, you must apply for an ICP filing. Otherwise, your website will be inaccessible.
If you use an Alibaba Cloud server, go to the Alibaba Cloud ICP Filing system to complete the ICP filing for your website. For more information, see ICP filing process.
If you do not use an Alibaba Cloud server, go to your server provider's ICP filing system or the MIIT ICP Filing website to complete the filing.
Next steps
Renew the certificate
When an SSL certificate expires, you must promptly renew it or request a new one. You must also install the new SSL certificate to maintain the encrypted connection and security of your website. For more information, see SSL certificate renewal and expiration handling.
Revoke the certificate
If you no longer use a certificate, you can revoke it. For more information, see Revoke and delete an SSL certificate.
The revocation operation is irreversible. After a certificate is revoked, it is removed from the CA's trusted list. Browsers and clients will identify it as an invalid certificate during validation and display a security warning to visitors.
FAQ
What do I do if I cannot find the certificate after purchase?
If you did not enter domain name information during purchase, a certificate creation quota is added to your account instead of a ready-to-use certificate. The certificate is not displayed in the certificate list until you create an SSL certificate and associate it with a domain name.
Do SSL certificates support Chinese domain names?
Yes, they do. If you want to associate a Chinese domain name, you must convert it to Punycode as prompted in the console before you request the certificate. You can also use a transcoding tool to perform the conversion. For more information, see Convert a Chinese domain name.
Can I apply for an Alibaba Cloud SSL Certificate if my DNS provider is not Alibaba Cloud?
Yes, you can. You only need to complete the domain ownership validation. This is independent of your DNS provider.
Solution | Method | Advantage |
Configure the record at your current provider. | Log on to your current domain name platform and add the SSL certificate validation record (TXT) from Alibaba Cloud. Note Contact your provider's support if you need assistance. | Fast and direct. No domain name transfer is required. |
Transfer your domain to Alibaba Cloud. | Follow the steps to transfer a domain name to Alibaba Cloud. Once complete, you can manage all DNS records in the Alibaba Cloud DNS console. Important Transferring a domain requires paying a one-year renewal fee. | Convenient for future certificate renewals and unified domain name management. |