Skip to main content

Configuring Alibaba Cloud ESA for sslTrus CaaS

Prerequisites

Before starting the configuration, make sure you have completed the following preparations:

  1. Purchase the sslTrus CaaS service: Complete the purchase of your CaaS subscription first. For detailed purchase instructions, refer to sslTrus CaaS Purchase Guide.
  2. Apply for an SSL certificate: Make sure you have successfully applied for and had the certificate issued. For the detailed application process, refer to sslTrus CaaS Certificate Request.

Configure the installation point — certificate update (Alibaba Cloud ESA)

Configure the Alibaba Cloud ESA management interface

Prerequisites

Prepare the AK/SK for the Alibaba Cloud account that manages ESA in advance.

  1. Go to the Control Panel → Asset Management → Vendor Management, select Alibaba Cloud, and click Manage.

Vendor Management

  1. Click Add Account.

Add Account

  1. Enter the account name and the AK/SK of the Alibaba Cloud ESA management account, then click Save.

Enter AK/SK

Permission description

The AK/SK for Alibaba Cloud ESA must be granted the following permissions:

  • ListCertificatesByRecord
  • SetCertificate
  • ListCertificates
  • DeleteCertificate
  • ListRecords
  1. Go to Asset Management and click Add Asset.

Add Asset

  1. Enter the asset name, select Alibaba Cloud ESA as the product, select the account you just created for the access account, enter the region ID and site ID (obtained from Alibaba Cloud), then click OK to save.

Asset Configuration

Configure CaaS

  1. Go to Console → sslTrus CaaS Service, select the corresponding service and click Details to enter the CaaS management panel.

CaaS List

  1. Switch to the Installation Point tab, click Add Installation Node, enter the installation point name, select Alibaba Cloud ESA as the service type, select the asset created in the previous step as the asset name, enter the domain name in the Full DNS Record field, then click OK to save.

Install Node

  1. After configuration is complete, you can manage the node. Click Scan Now to start monitoring the node.

Scan Now

  1. After a new certificate is issued, click Push Certificate, and the system will push the new certificate to Alibaba Cloud ESA. You can see in the backend monitoring that the certificate is updated to the latest version.

Push Certificate