Skip to main content

sslTrus CaaS Configuration for Alibaba Cloud SLB

Prerequisites

Before starting the configuration, please ensure you have completed the following preparations:

  1. Purchase the sslTrus CaaS service: Complete the purchase of the CaaS subscription first. For detailed purchase instructions, please refer to sslTrus CaaS Purchase Guide.
  2. Apply for an SSL certificate: Ensure the certificate has been successfully requested and issued. For detailed application process, please refer to sslTrus CaaS Certificate Request.

Configure the installation point — certificate update (Alibaba Cloud SLB)

Configure the Alibaba Cloud SLB management interface

Prerequisites

Prepare the AK/SK of the Alibaba Cloud account for SLB management in advance.

  1. Go to the control backend > Asset Management > Vendor Management, select Alibaba Cloud, and click Manage.

Vendor Management

  1. Click Add Account.

Add Account

  1. Enter the account name and the AK/SK of the Alibaba Cloud SLB management account, then click Save.

Enter AK/SK

Permission description

The AK/SK for Alibaba Cloud SLB requires the following permissions to be enabled:

  • DescribeLoadBalancerHTTPSListenerAttribute
  • DescribeServerCertificates
  • DescribeDomainExtensions
  • UploadServerCertificate
  • SetLoadBalancerHTTPSListenerAttribute
  • SetDomainExtensionAttribute
  • DescribeLoadBalancerListeners
  • DescribeLoadBalancerAttribute
  1. Go to Asset Management and click Add Asset.

Add Asset

  1. Enter the asset name, select Alibaba Cloud SLB as the product, select the account you just created, enter the access account (vendor account), region ID and instance ID (obtained from Alibaba Cloud), then click OK to save.

Asset Configuration

Configure CaaS

  1. Go to the console > sslTrus CaaS Service, select the corresponding service and click Details to enter the CaaS management backend.

CaaS List

  1. Switch to the installation point tab, click Add Installation Node, enter the installation point name, select Alibaba Cloud SLB as the service type, select the asset created in the previous step as the asset name, select the corresponding listener port, then click OK to save.

Install Node

  1. After configuration is complete, you can manage the node. Click Scan Now to start monitoring the node.

Scan Now

  1. After a new certificate is issued, click Push Certificate. The system will push the new certificate to Alibaba Cloud SLB, and you can see in the backend monitoring that the certificate is updated to the latest version.

Push Certificate