Claude Cursor GitHub Copilot Skill

alibaba-certificate-manager-issuer-review

Review Alibaba Cloud SSL Certificate Service — DV/OV/EV certificate lifecycle, auto-renewal configuration, certificate deployment to SLB/ALB/CDN/OSS, domain validation status, CAA record compliance, and expiry monitoring.

LLM Mart · 0 points · 0 views 0 listing impressions 0 install-command copies
Virus-scanned Reviewed automatically before listing.

Full trust report

Download vincentchuwaichow-vanguard-frontier-agentic-skills_alibaba_alibaba-certificate-manager-issuer-review-febe32a.zip · 4 KB
Part of vincentchuwaichow/vanguard-frontier-agentic — 293 skills

Install

skills CLI npx skills add https://github.com/VincentChuWaiChow/vanguard-frontier-agentic/tree/master/skills/alibaba/alibaba-certificate-manager-issuer-review
Claude Code claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install vincentchuwaichow-vanguard-frontier-agentic@llmmart
Git git clone https://github.com/VincentChuWaiChow/vanguard-frontier-agentic.git

The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole vincentchuwaichow/vanguard-frontier-agentic collection as a plugin from our marketplace. Git is the plain clone.

Skill manifest

Alibaba Cloud Certificate Manager Issuer Review

Purpose

Act as the Alibaba Cloud certificate lifecycle reviewer who audits SSL certificate inventory, validates auto-renewal configuration, verifies deployment binding to SLB/ALB/CDN/OSS resources, confirms CAA record compliance, and ensures expiry monitoring is in place before production incidents occur.

When to use

Use this skill for:

  • reviewing SSL Certificate Service inventory for expiry timeline and type coverage
  • auditing auto-renewal configuration and DNS validation record status
  • verifying certificate deployment to ALB HTTPS listeners, CLB listeners, CDN domains, and OSS buckets
  • assessing CAA DNS record compliance for the CA issuing the certificates
  • confirming CloudMonitor expiry alerts are configured for all production certificates
  • advising on DV vs OV vs EV selection for compliance requirements
  • reviewing private key management posture (platform-generated vs. CSR-uploaded)
  • enforcing TLS 1.2+ via ALB/SLB security policy for PCI-DSS and MLPS 2.0

Lean operating rules

  • Prefer sanitized Alibaba Cloud Console evidence or aliyun CLI output for live state grounding. If live tooling is unavailable, say so and fall back to official Alibaba Cloud documentation.
  • Separate confirmed facts from inference. Label each finding explicitly.
  • A certificate with auto-renewal enabled but an incorrect DNS validation record will silently fail renewal and expire — always verify the DNS validation record is resolvable.
  • Never ask for private key material, CSR contents containing real domain data, or payment credentials.
  • Certificates bound to one resource are not automatically applied to others — deployment must be explicit per resource per certificate.

Key certificate management guidance

  • DV vs OV vs EV: DV (Domain Validated) proves domain control only; OV (Organization Validated) includes organization identity; EV (Extended Validation) provides highest trust indicator with legal entity validation — PCI-DSS typically requires OV or EV for cardholder data environments.
  • Auto-renewal: Alibaba Cloud SSL Certificate Service supports auto-renewal for supported DV certificates — the DNS CNAME validation record must be present and resolvable for auto-renewal to succeed; verify with a DNS lookup, not just console status.
  • Certificate deployment: renewing a certificate in SSL Certificate Service does not automatically update it on SLB listeners, ALB listeners, CDN domains, or OSS buckets — each resource binding must be updated explicitly or via automation.
  • CAA records: Certification Authority Authorization DNS records restrict which CAs can issue for a domain — Alibaba Cloud SSL Certificate Service uses DigiCert or GlobalSign depending on the product SKU; CAA records must allow the correct CA.
  • CloudMonitor expiry alerts: configure CloudMonitor certificate expiry monitoring with at least 30-day advance notice — 7-day notice is too short for OV/EV certificates that require manual renewal steps.
  • TLS version enforcement: ALB and CLB HTTPS listeners support configurable security policies — enforce TLS 1.2+ by selecting the appropriate security policy; TLS 1.0 and 1.1 are non-compliant with PCI-DSS and MLPS 2.0 Level 3.

References

Load these only when needed:

  • Workflow and output contract — use when executing the full certificate review or formatting the final assessment output.
  • Official sources — use when grounding Alibaba Cloud certificate service behavior or product feature claims.

Response minimum

Return, at minimum:

  • the certificate inventory with expiry timeline,
  • certificate type and validation level assessment against compliance requirements,
  • auto-renewal configuration and DNS validation record status,
  • deployment coverage for all bound resources,
  • CAA record compliance verdict,
  • expiry monitoring and alert configuration status,
  • certificate hygiene recommendations.
Files (vanguard-frontier-agentic)
  • references
    • official-sources.md 1.3 KB
      # Official sources
      
      Use this reference only when you need source grounding for Alibaba Cloud SSL Certificate Service behavior or the detailed source list.
      
      ## Alibaba Cloud documentation
      
      Use these as starting points, not as proof of the user's live Alibaba Cloud state:
      - https://www.alibabacloud.com/help/en/ssl-certificate/latest/what-is-ssl-certificates-service
      - https://www.alibabacloud.com/help/en/ssl-certificate/latest/certificate-types
      - https://www.alibabacloud.com/help/en/ssl-certificate/latest/automatic-renewal
      - https://www.alibabacloud.com/help/en/slb/application-load-balancer/user-guide/create-an-https-listener
      - https://www.alibabacloud.com/help/en/cdn/user-guide/configure-an-ssl-certificate
      - https://www.alibabacloud.com/help/en/cloud-monitor/latest/overview
      
      ## Grounding rule
      
      Official documentation explains Alibaba Cloud SSL Certificate Service behavior and feature availability. It does not prove the user's current certificate status, DNS validation record presence, deployment binding state, or CloudMonitor alert configuration. Prefer live Alibaba Cloud console evidence or sanitized user-provided evidence for current-state claims. Certificate auto-renewal status in the console reflects the configuration setting, not proof that the DNS validation record is currently resolvable — verify separately.
      
    • workflow-and-output.md 3.2 KB
      # Workflow and output contract
      
      Use this reference only when performing a full certificate lifecycle review or expiry risk assessment.
      
      ## Review domains
      
      Check these areas before giving a recommendation:
      
      - Certificate inventory: all certificates, their domains, types (DV/OV/EV), expiry dates, and issuer CA
      - Certificate type compliance: DV sufficient vs OV/EV required for the compliance framework in scope
      - Auto-renewal: enabled status, DNS validation record present and resolvable
      - Deployment bindings: SLB listeners, ALB HTTPS listeners, CDN domains, OSS buckets — all updated after last renewal?
      - CAA records: DNS CAA record allows the CA issuing the certificate (DigiCert or GlobalSign)
      - CloudMonitor alerts: expiry alert configured with at least 30-day advance notice
      - TLS policy: TLS 1.2+ enforced via ALB/SLB security policy
      - Private key posture: platform-generated (stored by Alibaba) vs. CSR-uploaded (customer-controlled)
      
      ## Safe workflow
      
      1. **Frame the certificate scope**
         - Certificate domains (sanitized — no real domains required if not available):
         - Certificate types in use (DV/OV/EV):
         - Compliance requirements (PCI-DSS / MLPS 2.0 / none):
         - Resources bound to certificates (SLB/ALB/CDN/OSS):
      2. **Collect evidence**
         - Prefer live console screenshots or aliyun CLI output.
         - Otherwise inspect DNS records, sanitized user evidence, or official Alibaba Cloud docs.
         - Label each finding as `live evidence`, `repo evidence`, `user-provided evidence`, `documentation-based`, or `inference`.
      3. **Stress-test the configuration**
         - Is auto-renewal enabled AND is the DNS CNAME validation record resolvable? (both must be true)
         - Has the certificate been redeployed to all bound resources after the last renewal?
         - Is the CAA record correct for the issuing CA?
         - Is CloudMonitor configured with 30+ day advance expiry alerts?
         - Is TLS 1.0/1.1 blocked via security policy?
      4. **Recommend the smallest safe next step**
         - Prioritize by risk: certificates expiring within 30 days > missing deployment binding > DNS validation record failure > no CloudMonitor alerts > TLS downgrade.
      
      ## Output contract
      
      Return this structure:
      ```markdown
      # Alibaba Cloud Certificate Review: <scope>
      ## Executive summary
      - Certificate posture verdict:
      - Evidence level:
      - Critical findings:
      ## Certificate inventory
      | Domain (sanitized) | Type | Issuer CA | Expiry date | Days remaining |
      |---|---|---|---|---|
      ## Certificate type and compliance assessment
      - Compliance requirement:
      - DV sufficient: yes/no
      - OV/EV required: yes/no
      - Current type coverage: adequate/gap
      ## Auto-renewal and DNS validation
      | Certificate | Auto-renewal | DNS validation record | Resolvable | Risk |
      |---|---|---|---|---|
      ## Deployment coverage
      | Certificate | SLB | ALB | CDN | OSS | Last redeployed |
      |---|---|---|---|---|---|
      ## CAA record compliance
      - CAA record present:
      - CA allowed:
      - Gap:
      ## Expiry monitoring
      - CloudMonitor alert configured:
      - Alert lead time:
      - Notification channels:
      ## TLS version posture
      - TLS 1.2+ enforced:
      - Security policy applied:
      ## Certificate hygiene recommendations
      1. <recommendation> — priority: <critical/high/medium>, effort: <low/medium/high>
      ## Open questions
      1. <question> — owner: <owner>, impact: <impact if unresolved>
      ```
      
  • metadata.json 1.3 KB
    {
      "id": "alibaba-certificate-manager-issuer-review",
      "name": "Alibaba Cloud Certificate Manager Issuer Review",
      "type": "skill",
      "provider": "alibaba",
      "harnesses": [
        "codex",
        "claude-code",
        "cursor",
        "gemini",
        "kiro",
        "other"
      ],
      "summary": "Review Alibaba Cloud SSL Certificate Service — DV/OV/EV certificate lifecycle, auto-renewal configuration, certificate deployment to SLB/ALB/CDN/OSS, domain validation status, CAA record compliance, and expiry monitoring.",
      "source_type": "original",
      "official_docs": [
        "https://www.alibabacloud.com/help/en/ssl-certificate/latest/what-is-ssl-certificates-service",
        "https://www.alibabacloud.com/help/en/slb/application-load-balancer/user-guide/create-an-https-listener",
        "https://www.alibabacloud.com/help/en/cdn/user-guide/configure-an-ssl-certificate"
      ],
      "security_notes": "Alibaba Cloud certificate private keys generated on the platform are stored in Alibaba's systems — for maximum security, use CSR-based upload with your own private key generated locally. SLB/ALB HTTPS listeners using TLS 1.0 or 1.1 are non-compliant with PCI-DSS and MLPS 2.0 — enforce TLS 1.2+ via security policy configuration.",
      "last_verified": "2026-05-09",
      "path": "skills/alibaba/alibaba-certificate-manager-issuer-review",
      "author": "github: VincentChuWaiChow",
      "version": "0.1.0"
    }
    
  • SKILL.md 4.4 KB
    ---
    name: alibaba-certificate-manager-issuer-review
    description: Review Alibaba Cloud SSL Certificate Service — DV/OV/EV certificate lifecycle, auto-renewal configuration, certificate deployment to SLB/ALB/CDN/OSS, domain validation status, CAA record compliance, and expiry monitoring.
    allowed-tools: Read Grep Glob
    metadata:
      author: "github: VincentChuWaiChow"
      version: "0.1.0"
      updated: "2026-05-09"
      category: security
    ---
    
    # Alibaba Cloud Certificate Manager Issuer Review
    
    ## Purpose
    
    Act as the Alibaba Cloud certificate lifecycle reviewer who audits SSL certificate inventory, validates auto-renewal configuration, verifies deployment binding to SLB/ALB/CDN/OSS resources, confirms CAA record compliance, and ensures expiry monitoring is in place before production incidents occur.
    
    ## When to use
    
    Use this skill for:
    
    - reviewing SSL Certificate Service inventory for expiry timeline and type coverage
    - auditing auto-renewal configuration and DNS validation record status
    - verifying certificate deployment to ALB HTTPS listeners, CLB listeners, CDN domains, and OSS buckets
    - assessing CAA DNS record compliance for the CA issuing the certificates
    - confirming CloudMonitor expiry alerts are configured for all production certificates
    - advising on DV vs OV vs EV selection for compliance requirements
    - reviewing private key management posture (platform-generated vs. CSR-uploaded)
    - enforcing TLS 1.2+ via ALB/SLB security policy for PCI-DSS and MLPS 2.0
    
    ## Lean operating rules
    
    - Prefer sanitized Alibaba Cloud Console evidence or aliyun CLI output for live state grounding. If live tooling is unavailable, say so and fall back to official Alibaba Cloud documentation.
    - Separate confirmed facts from inference. Label each finding explicitly.
    - A certificate with auto-renewal enabled but an incorrect DNS validation record will silently fail renewal and expire — always verify the DNS validation record is resolvable.
    - Never ask for private key material, CSR contents containing real domain data, or payment credentials.
    - Certificates bound to one resource are not automatically applied to others — deployment must be explicit per resource per certificate.
    
    ## Key certificate management guidance
    
    - **DV vs OV vs EV**: DV (Domain Validated) proves domain control only; OV (Organization Validated) includes organization identity; EV (Extended Validation) provides highest trust indicator with legal entity validation — PCI-DSS typically requires OV or EV for cardholder data environments.
    - **Auto-renewal**: Alibaba Cloud SSL Certificate Service supports auto-renewal for supported DV certificates — the DNS CNAME validation record must be present and resolvable for auto-renewal to succeed; verify with a DNS lookup, not just console status.
    - **Certificate deployment**: renewing a certificate in SSL Certificate Service does not automatically update it on SLB listeners, ALB listeners, CDN domains, or OSS buckets — each resource binding must be updated explicitly or via automation.
    - **CAA records**: Certification Authority Authorization DNS records restrict which CAs can issue for a domain — Alibaba Cloud SSL Certificate Service uses DigiCert or GlobalSign depending on the product SKU; CAA records must allow the correct CA.
    - **CloudMonitor expiry alerts**: configure CloudMonitor certificate expiry monitoring with at least 30-day advance notice — 7-day notice is too short for OV/EV certificates that require manual renewal steps.
    - **TLS version enforcement**: ALB and CLB HTTPS listeners support configurable security policies — enforce TLS 1.2+ by selecting the appropriate security policy; TLS 1.0 and 1.1 are non-compliant with PCI-DSS and MLPS 2.0 Level 3.
    
    ## References
    
    Load these only when needed:
    
    - [Workflow and output contract](references/workflow-and-output.md) — use when executing the full certificate review or formatting the final assessment output.
    - [Official sources](references/official-sources.md) — use when grounding Alibaba Cloud certificate service behavior or product feature claims.
    
    ## Response minimum
    
    Return, at minimum:
    
    - the certificate inventory with expiry timeline,
    - certificate type and validation level assessment against compliance requirements,
    - auto-renewal configuration and DNS validation record status,
    - deployment coverage for all bound resources,
    - CAA record compliance verdict,
    - expiry monitoring and alert configuration status,
    - certificate hygiene recommendations.
    

Comments (0)

Sign in to join the conversation.

No comments yet.

Reviews (0)

No reviews yet.

Related