Configure Alibaba Cloud MSE for sslTrus CaaS
Prerequisites
Before starting configuration, make sure you have completed the following preparations:
- Purchase sslTrus CaaS service: Complete the CaaS subscription purchase first. For detailed purchase instructions, refer to sslTrus CaaS Purchase Guide.
- Apply for SSL certificate: Ensure that the certificate has been successfully requested and issued. For detailed application process, refer to sslTrus CaaS Certificate Request.
Configure installation point — certificate update (Alibaba Cloud MSE)
Configure Alibaba Cloud MSE management interface
Prerequisites
Prepare the AK/SK of the Alibaba Cloud account used to manage MSE in advance.
- Go to the Control Console → Asset Management → Vendor Management, select Alibaba Cloud, and click Manage.

- Click Add Account.

- Enter the account name and the AK/SK of the Alibaba Cloud MSE management account, then click Save.

Permission description
The AK/SK for Alibaba Cloud MSE must be granted the following permissions:
- ListGatewayDomain
- UpdateSSLCert
- ListGateway
- Go to Asset Management and click Add Asset.

- Enter the asset name, select Alibaba Cloud MSE, select the account you just created, enter the region ID (obtained from Alibaba Cloud), and click Confirm to save.

Configure CaaS
- Go to Console → sslTrus CaaS Service, select the corresponding service and click Details to enter the CaaS management backend.

- Switch to the Installation Points tab, click Add Installation Node, enter the installation point name, select Alibaba Cloud MSE for Service Type, select the asset created in the previous step for Asset Name, enter the unique gateway ID (obtained from Alibaba Cloud), enter the domain name in the Domain Name field, and click Confirm to save.

- After the configuration is completed, you can manage the node. Click Scan Now to start monitoring the node.

- After a new certificate is issued, click Push Certificate, and the system will push the new certificate to Alibaba Cloud MSE. You can see the certificate is updated to the latest version in the backend monitoring.
