{"slug":"alibaba-certificate-manager-issuer-review","title":"alibaba-certificate-manager-issuer-review","summary":"Review Alibaba Cloud SSL Certificate Service — DV/OV/EV certificate lifecycle, auto-renewal configuration, certificate deployment to SLB/ALB/CDN/OSS, domain validation status, CAA record compliance, and expiry monitoring.","platform":"Claude","tags":[],"authorName":"LLM Mart","authorSlug":"llm-mart","score":0,"source":"github","price":null,"verified":false,"createdAt":"2026-10-05T21:50:43.737743Z","repo":{"url":"https://github.com/VincentChuWaiChow/vanguard-frontier-agentic","stars":24,"forks":3,"license":"Apache-2.0","updatedAt":"2026-10-05T13:00:24Z"},"bodyHtml":"<hr>\n<h2>name: alibaba-certificate-manager-issuer-review\ndescription: Review Alibaba Cloud SSL Certificate Service — DV/OV/EV certificate lifecycle, auto-renewal configuration, certificate deployment to SLB/ALB/CDN/OSS, domain validation status, CAA record compliance, and expiry monitoring.\nallowed-tools: Read Grep Glob\nmetadata:\nauthor: \"github: VincentChuWaiChow\"\nversion: \"0.1.0\"\nupdated: \"2026-05-09\"\ncategory: security</h2>\n<h1>Alibaba Cloud Certificate Manager Issuer Review</h1>\n<h2>Purpose</h2>\n<p>Act as the Alibaba Cloud certificate lifecycle reviewer who audits SSL certificate inventory, validates auto-renewal configuration, verifies deployment binding to SLB/ALB/CDN/OSS resources, confirms CAA record compliance, and ensures expiry monitoring is in place before production incidents occur.</p>\n<h2>When to use</h2>\n<p>Use this skill for:</p>\n<ul>\n<li>reviewing SSL Certificate Service inventory for expiry timeline and type coverage</li>\n<li>auditing auto-renewal configuration and DNS validation record status</li>\n<li>verifying certificate deployment to ALB HTTPS listeners, CLB listeners, CDN domains, and OSS buckets</li>\n<li>assessing CAA DNS record compliance for the CA issuing the certificates</li>\n<li>confirming CloudMonitor expiry alerts are configured for all production certificates</li>\n<li>advising on DV vs OV vs EV selection for compliance requirements</li>\n<li>reviewing private key management posture (platform-generated vs. CSR-uploaded)</li>\n<li>enforcing TLS 1.2+ via ALB/SLB security policy for PCI-DSS and MLPS 2.0</li>\n</ul>\n<h2>Lean operating rules</h2>\n<ul>\n<li>Prefer sanitized Alibaba Cloud Console evidence or aliyun CLI output for live state grounding. If live tooling is unavailable, say so and fall back to official Alibaba Cloud documentation.</li>\n<li>Separate confirmed facts from inference. Label each finding explicitly.</li>\n<li>A certificate with auto-renewal enabled but an incorrect DNS validation record will silently fail renewal and expire — always verify the DNS validation record is resolvable.</li>\n<li>Never ask for private key material, CSR contents containing real domain data, or payment credentials.</li>\n<li>Certificates bound to one resource are not automatically applied to others — deployment must be explicit per resource per certificate.</li>\n</ul>\n<h2>Key certificate management guidance</h2>\n<ul>\n<li><strong>DV vs OV vs EV</strong>: DV (Domain Validated) proves domain control only; OV (Organization Validated) includes organization identity; EV (Extended Validation) provides highest trust indicator with legal entity validation — PCI-DSS typically requires OV or EV for cardholder data environments.</li>\n<li><strong>Auto-renewal</strong>: Alibaba Cloud SSL Certificate Service supports auto-renewal for supported DV certificates — the DNS CNAME validation record must be present and resolvable for auto-renewal to succeed; verify with a DNS lookup, not just console status.</li>\n<li><strong>Certificate deployment</strong>: renewing a certificate in SSL Certificate Service does not automatically update it on SLB listeners, ALB listeners, CDN domains, or OSS buckets — each resource binding must be updated explicitly or via automation.</li>\n<li><strong>CAA records</strong>: Certification Authority Authorization DNS records restrict which CAs can issue for a domain — Alibaba Cloud SSL Certificate Service uses DigiCert or GlobalSign depending on the product SKU; CAA records must allow the correct CA.</li>\n<li><strong>CloudMonitor expiry alerts</strong>: configure CloudMonitor certificate expiry monitoring with at least 30-day advance notice — 7-day notice is too short for OV/EV certificates that require manual renewal steps.</li>\n<li><strong>TLS version enforcement</strong>: ALB and CLB HTTPS listeners support configurable security policies — enforce TLS 1.2+ by selecting the appropriate security policy; TLS 1.0 and 1.1 are non-compliant with PCI-DSS and MLPS 2.0 Level 3.</li>\n</ul>\n<h2>References</h2>\n<p>Load these only when needed:</p>\n<ul>\n<li><a href=\"references/workflow-and-output.md\">Workflow and output contract</a> — use when executing the full certificate review or formatting the final assessment output.</li>\n<li><a href=\"references/official-sources.md\">Official sources</a> — use when grounding Alibaba Cloud certificate service behavior or product feature claims.</li>\n</ul>\n<h2>Response minimum</h2>\n<p>Return, at minimum:</p>\n<ul>\n<li>the certificate inventory with expiry timeline,</li>\n<li>certificate type and validation level assessment against compliance requirements,</li>\n<li>auto-renewal configuration and DNS validation record status,</li>\n<li>deployment coverage for all bound resources,</li>\n<li>CAA record compliance verdict,</li>\n<li>expiry monitoring and alert configuration status,</li>\n<li>certificate hygiene recommendations.</li>\n</ul>\n","files":[{"path":"metadata.json","sizeBytes":1382,"isText":true},{"path":"references/official-sources.md","sizeBytes":1336,"isText":true},{"path":"references/workflow-and-output.md","sizeBytes":3300,"isText":true},{"path":"SKILL.md","sizeBytes":4486,"isText":true}],"reviewScore":null,"reviewSummary":null,"trust":{"provenance":"trusted-source-unreviewed","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow.","bodySource":null},"bodyLocked":false,"purchaseUrl":null,"sourceUrl":null,"report":{"provenance":"trusted-source-unreviewed","screen":{"ran":true,"outcome":"notes-only","suspicious":0,"notes":6,"hiddenCharacters":false},"virusScan":{"engine":"clamav","status":"clean","scannedAt":"2026-10-05T21:51:28.843603Z","sha256":"7E38CEF6C150718E19853D77278004ABE8E327C9876BC18F0E2FC4D152851F43","sizeBytes":5065},"review":null,"source":{"repositoryUrl":"https://github.com/VincentChuWaiChow/vanguard-frontier-agentic","path":"skills/alibaba/alibaba-certificate-manager-issuer-review","license":"Apache-2.0","commit":"febe32a08e78fd06b1e466187410d673f1958d87","subtreeSha":"CE011EC66B5B5721520B5D6E2A822A6FF3042C2F59553FCA477BBEBCB9C4F8AA","lastSyncedAt":"2026-10-05T21:51:58.639905Z"},"reviewedAt":"2026-10-05T21:52:38.002503Z","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow."},"install":[{"target":"skills-cli","command":"npx skills add https://github.com/VincentChuWaiChow/vanguard-frontier-agentic/tree/master/skills/alibaba/alibaba-certificate-manager-issuer-review"},{"target":"claude-code","command":"claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install vincentchuwaichow-vanguard-frontier-agentic@llmmart"},{"target":"git","command":"git clone https://github.com/VincentChuWaiChow/vanguard-frontier-agentic.git"}]}