Configuring Alibaba Cloud ESA for sslTrus CaaS
Prerequisites
Before starting the configuration, make sure you have completed the following preparations:
- Purchase the sslTrus CaaS service: Complete the purchase of your CaaS subscription first. For detailed purchase instructions, refer to sslTrus CaaS Purchase Guide.
- Apply for an SSL certificate: Make sure you have successfully applied for and had the certificate issued. For the detailed application process, refer to sslTrus CaaS Certificate Request.
Configure the installation point — certificate update (Alibaba Cloud ESA)
Configure the Alibaba Cloud ESA management interface
Prerequisites
Prepare the AK/SK for the Alibaba Cloud account that manages ESA in advance.
- Go to the Control Panel → Asset Management → Vendor Management, select Alibaba Cloud, and click Manage.

- Click Add Account.

- Enter the account name and the AK/SK of the Alibaba Cloud ESA management account, then click Save.

Permission description
The AK/SK for Alibaba Cloud ESA must be granted the following permissions:
- ListCertificatesByRecord
- SetCertificate
- ListCertificates
- DeleteCertificate
- ListRecords
- Go to Asset Management and click Add Asset.

- Enter the asset name, select Alibaba Cloud ESA as the product, select the account you just created for the access account, enter the region ID and site ID (obtained from Alibaba Cloud), then click OK to save.

Configure CaaS
- Go to Console → sslTrus CaaS Service, select the corresponding service and click Details to enter the CaaS management panel.

- Switch to the Installation Point tab, click Add Installation Node, enter the installation point name, select Alibaba Cloud ESA as the service type, select the asset created in the previous step as the asset name, enter the domain name in the Full DNS Record field, then click OK to save.

- After configuration is complete, you can manage the node. Click Scan Now to start monitoring the node.

- After a new certificate is issued, click Push Certificate, and the system will push the new certificate to Alibaba Cloud ESA. You can see in the backend monitoring that the certificate is updated to the latest version.
