tencent cloud

Feedback

SSL Certificate Purchase Process

Last updated: 2023-05-19 14:54:43

    We recommend that you take the time to understand the differences between the different certificate types and domain name types so that you can purchase the appropriate certificate for your actual needs. The following details the process of purchasing a certificate.

    Step 1. Go to the SSL certificate purchase page

    1. Log in at the SSL certificate purchase page.

    2. Click Purchase Certificate to view the detailed certificate configuration and pricing information, as shown in the following image:

      Note:

      • If you are not familiar with certificate types and brands, click Quick Configuration to quickly purchase a certificate recommended by the system.
      • Click Advanced Settings and set Project and Tag to better manage existing Tencent Cloud resources by category. For detailed directions on how to add a tag, see Querying Resources by Tag.

    Step 2. Select the certificate type and brand

    1. Select a certificate type that best fits your industry and actual needs. For more information, see Certificate Type Selection Cases.

    2. Select a certificate brand. For more information, please see Certificate Brands.

    Step 3. Select the domain name type and the number of domain names supported

    Domain Type Description Notes
    Single-domain Only one domain can be bound. The domain can be a second-level domain such as `tencent.com` or a third-level domain such as `example.tencent.com`. Binding all subdomains under a second-level domain is not supported.
    Up to 100 levels of domains are supported.
    An SSL certificate bound to the domain `www.tencent.com` (`www` as the subdomain) supports the second-level domain `tencent.com`.
    Multi-domain A certificate can be bound to multiple domains, subject to the maximum number of domains displayed in the console. The prices of SecureSite multi-domain certificates are calculated based on the number of domains.
    For the GeoTrust, TrustAsia, GlobalSign, WoTrus, and DNSPod multi-domain certificates, there are additional charges for the domains that exceed the default maximum number of domains supported.
    Wildcard domain One and only one wildcard domain can be bound, and only one wildcard can be added. For example, `\*.tencent.com` and `\*.example.tencent.com` support up to 100 levels.
    Multi-wildcard domains such as `\*.\*.tencent.com` are not supported.
    An SSL certificate bound to the domain `\*.tencent.com` (which must be a second-level wildcard domain) supports the second-level domain `tencent.com`.
    Multiple wildcard domains Multiple wildcard domains can be bound. For example, `\*.tencent.com`, `\*.ssl.tencent.com`, and `\*.another.com` are counted as a total of three wildcard domains, including all the subdomains at the same level, subject to the maximum number of domains displayed in the console.

    Step 4. Select the certificate validity period

    Due to changes in Apple and Google root store policies, newly issued SSL/TLS certificates with a validity period greater than 13 months (397 days) have been prohibited by policy since September 1, 2020. Therefore, global CAs have ceased issuing such certificates since September 1, 2020.
    Currently, only certain multi-year SSL certificates are available from Tencent Cloud (others available are all SSL certificates with a validity period of 13 months). Within 30 days before expiration of your current multi-year certificate, Tencent Cloud will automatically apply for a new one for you, which will be automatically issued upon CA approval.

    Note:

    • Available multi-year SSL certificate brands and types are as displayed on the purchase page.
    • If the original certificate is installed at the server website, you need to replace it with a newly issued one as instructed in Selecting an Installation Type for an SSL Certificate.

    Step 5. Pay for your order

    After selecting the brand, model, supported domain name, and certificate validity period, you can submit your order and complete the payment process.

    Step 6. Submit an application

    DNSPod (SM2) OV and EV SSL certificates:

    1. After purchasing the certificate, log in to the SSL Certificate Service console and select Pending Submission to enter the management page. Then, submit the information, upload the confirmation letter, and complete the domain ownership verification.

    2. After your application is submitted, it will be reviewed. After the review is successfully completed, the certificate will be issued.

    WoTrus OV and EV SSL certificates

    1. After purchasing the certificate, log in to the SSL Certificate Service console and select Pending Submission to enter the management page. Then, submit the information to pre-apply for the certificate. After your pre-application is approved, the domain ownership needs to be verified.

    2. After your domain is validated, manual approval is needed, upon which the certificate will be issued. For more information, see Information Submission Process for Wotrus OV and EV SSL Certificates.

    Other OV and EV SSL certificates

    1. After purchasing the certificate, log in to the SSL Certificate Service console and select Pending Submission to enter the management page. Then, submit the information and upload the confirmation letter to apply for the certificate.

    2. After your application is submitted, it will be reviewed. After the review is successfully completed, the certificate will be issued. For more information, please see The Process of Submitting Materials for OV/EV SSL Certificates.

      Note:

      • If you use the approved organization and administrator information in My Profile, the confirmation letter is not required.
      • For GlobalSign certificates, the confirmation letter still needs to be uploaded when you submit the information.

    DV SSL certificates

    After purchasing the certificate, log in to the SSL Certificate Service console and select Pending Submission to enter the management page. Then, submit the information and complete the domain ownership verification, after which the CA will issue the certificate.

    Free DV SSL certificates

    After applying for the certificate, complete the domain ownership verification. The CA will then issue the certificate.

    Contact Us

    Contact our sales team or business advisors to help your business.

    Technical Support

    Open a ticket if you're looking for further assistance. Our Ticket is 7x24 avaliable.

    7x24 Phone Support