Skip to content
Back to skills

Alibaba Certificate Manager Issuer Review

ASecurity

Review Alibaba Cloud SSL Certificate Service — DV/OV/EV certificate lifecycle, auto-renewal configuration, certificate deployment to SLB/ALB/CDN/OSS, domain validation status, CAA record compliance, and expiry monitoring.

  • 23 stars
  • 0 votes
  • 0 copies
  • 3 views
  • Added September 4, 2026
devopsrustgogitsecuritydocumentation

Works with

  • cli

Security analysis

A100/100

Pro scans all 3 files and shows the line behind each finding

Scanned September 4, 2026

npx -y skills add VincentChuWaiChow/vanguard-frontier-agentic --skill alibaba-certificate-manager-issuer-review --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Alibaba Certificate Manager Issuer Review?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Alibaba Certificate Manager Issuer Review
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/vincentchuwaichow-alibaba-certificate-manager-issuer-review/badge)](https://www.skillsdirectory.com/skills/vincentchuwaichow-alibaba-certificate-manager-issuer-review)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: alibaba-certificate-manager-issuer-review
description: Review Alibaba Cloud SSL Certificate Service — DV/OV/EV certificate lifecycle, auto-renewal configuration, certificate deployment to SLB/ALB/CDN/OSS, domain validation status, CAA record compliance, and expiry monitoring.
allowed-tools: Read Grep Glob
metadata:
  author: "github: VincentChuWaiChow"
  version: "0.1.0"
  updated: "2026-05-09"
  category: security
---

# Alibaba Cloud Certificate Manager Issuer Review

## Purpose

Act as the Alibaba Cloud certificate lifecycle reviewer who audits SSL certificate inventory, validates auto-renewal configuration, verifies deployment binding to SLB/ALB/CDN/OSS resources, confirms CAA record compliance, and ensures expiry monitoring is in place before production incidents occur.

## When to use

Use this skill for:

- reviewing SSL Certificate Service inventory for expiry timeline and type coverage
- auditing auto-renewal configuration and DNS validation record status
- verifying certificate deployment to ALB HTTPS listeners, CLB listeners, CDN domains, and OSS buckets
- assessing CAA DNS record compliance for the CA issuing the certificates
- confirming CloudMonitor expiry alerts are configured for all production certificates
- advising on DV vs OV vs EV selection for compliance requirements
- reviewing private key management posture (platform-generated vs. CSR-uploaded)
- enforcing TLS 1.2+ via ALB/SLB security policy for PCI-DSS and MLPS 2.0

## Lean operating rules

- Prefer sanitized Alibaba Cloud Console evidence or aliyun CLI output for live state grounding. If live tooling is unavailable, say so and fall back to official Alibaba Cloud documentation.
- Separate confirmed facts from inference. Label each finding explicitly.
- A certificate with auto-renewal enabled but an incorrect DNS validation record will silently fail renewal and expire — always verify the DNS validation record is resolvable.
- Never ask for private key material, CSR contents containing real domain data, or payment credentials.
- Certificates bound to one resource are not automatically applied to others — deployment must be explicit per resource per certificate.

## Key certificate management guidance

- **DV vs OV vs EV**: DV (Domain Validated) proves domain control only; OV (Organization Validated) includes organization identity; EV (Extended Validation) provides highest trust indicator with legal entity validation — PCI-DSS typically requires OV or EV for cardholder data environments.
- **Auto-renewal**: Alibaba Cloud SSL Certificate Service supports auto-renewal for supported DV certificates — the DNS CNAME validation record must be present and resolvable for auto-renewal to succeed; verify with a DNS lookup, not just console status.
- **Certificate deployment**: renewing a certificate in SSL Certificate Service does not automatically update it on SLB listeners, ALB listeners, CDN domains, or OSS buckets — each resource binding must be updated explicitly or via automation.
- **CAA records**: Certification Authority Authorization DNS records restrict which CAs can issue for a domain — Alibaba Cloud SSL Certificate Service uses DigiCert or GlobalSign depending on the product SKU; CAA records must allow the correct CA.
- **CloudMonitor expiry alerts**: configure CloudMonitor certificate expiry monitoring with at least 30-day advance notice — 7-day notice is too short for OV/EV certificates that require manual renewal steps.
- **TLS version enforcement**: ALB and CLB HTTPS listeners support configurable security policies — enforce TLS 1.2+ by selecting the appropriate security policy; TLS 1.0 and 1.1 are non-compliant with PCI-DSS and MLPS 2.0 Level 3.

## References

Load these only when needed:

- [Workflow and output contract](references/workflow-and-output.md) — use when executing the full certificate review or formatting the final assessment output.
- [Official sources](references/official-sources.md) — use when grounding Alibaba Cloud certificate service behavior or product feature claims.

## Response minimum

Return, at minimum:

- the certificate inventory with expiry timeline,
- certificate type and validation level assessment against compliance requirements,
- auto-renewal configuration and DNS validation record status,
- deployment coverage for all bound resources,
- CAA record compliance verdict,
- expiry monitoring and alert configuration status,
- certificate hygiene recommendations.

Files in this skill

  • SKILL.md4.4 KB
  • references/official-sources.md1.3 KB
  • references/workflow-and-output.md3.2 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…