sslTrus CaaS Configuration for Alibaba Cloud SLB
Prerequisites
Before starting the configuration, please ensure you have completed the following preparations:
- Purchase the sslTrus CaaS service: Complete the purchase of the CaaS subscription first. For detailed purchase instructions, please refer to sslTrus CaaS Purchase Guide.
- Apply for an SSL certificate: Ensure the certificate has been successfully requested and issued. For detailed application process, please refer to sslTrus CaaS Certificate Request.
Configure the installation point — certificate update (Alibaba Cloud SLB)
Configure the Alibaba Cloud SLB management interface
Prerequisites
Prepare the AK/SK of the Alibaba Cloud account for SLB management in advance.
- Go to the control backend > Asset Management > Vendor Management, select Alibaba Cloud, and click Manage.

- Click Add Account.

- Enter the account name and the AK/SK of the Alibaba Cloud SLB management account, then click Save.

Permission description
The AK/SK for Alibaba Cloud SLB requires the following permissions to be enabled:
- DescribeLoadBalancerHTTPSListenerAttribute
- DescribeServerCertificates
- DescribeDomainExtensions
- UploadServerCertificate
- SetLoadBalancerHTTPSListenerAttribute
- SetDomainExtensionAttribute
- DescribeLoadBalancerListeners
- DescribeLoadBalancerAttribute
- Go to Asset Management and click Add Asset.

- Enter the asset name, select Alibaba Cloud SLB as the product, select the account you just created, enter the access account (vendor account), region ID and instance ID (obtained from Alibaba Cloud), then click OK to save.

Configure CaaS
- Go to the console > sslTrus CaaS Service, select the corresponding service and click Details to enter the CaaS management backend.

- Switch to the installation point tab, click Add Installation Node, enter the installation point name, select Alibaba Cloud SLB as the service type, select the asset created in the previous step as the asset name, select the corresponding listener port, then click OK to save.

- After configuration is complete, you can manage the node. Click Scan Now to start monitoring the node.

- After a new certificate is issued, click Push Certificate. The system will push the new certificate to Alibaba Cloud SLB, and you can see in the backend monitoring that the certificate is updated to the latest version.
