Ordering & Validation
- Adding a wildcard into a multidomain SSL order
- Changes in Domain Control Validation Procedure
- How to order a SSL Certificate
- How to validate a SSL order
- Making changes after the SSL has been issued (reissue)
- Making changes during the validation process
- Transitioning SSL Validation from WHOIS to DNS
Adding a wildcard into a multidomain SSL order
Question
How to add wildcard into a multidomain product?
Answer
It is possible to add a wildcard domain in an SSL order.
This is only possible for DV + OV SSL certificates.
Products for Comodo / Sectigo: PositiveSSL MDC and UCC.
A wildcard (*.domainname.com) can only be added as SAN domain.
Impossible to add a wildcard domain (*.domain.com) as the common name in the request.
An order can look like:
- Common name: www.domain.com
- Extra domains (SAN) : *.domain.com
Reissue with adding new wildcards can only be requested using Reseller Control Panel.
Move to SSL Panel, open order then click "Reissue".
You will be redirected to Reseller Control Panel to SSL Orders overview from where you can request reissue.
If you would like to have a sub-subdomain wildcard certificate then this is possible with a Unified Communications Certificate (UCC) certificate.
For example: *.sub.example.com
Note!
Single domain certificates secure both www and non www version of the domain. But the multidomain certificate is NOT automatically valid for both. So both versions (www and non www version of the domain) needs to be added separately to the certificate.
In case you add a wildcard (*.domain.com) in the multidomain order, the www. is considered a subdomain so this is covered by the wildcard domain and does not need to be added as extra SAN in the order. The base domain however does need to be added as separate SAN.
Changes in Domain Control Validation Procedure
On the 15th of November 2021, the DCV (Domain Control Validation) procedure will be adjusted to meet new requirements from CA.
What is Domain Control Validation?
Domain Control Validation (DCV) is the process by which a CA gains evidence that a particular domain is managed by the applicant for a certificate.
One of these options is file-based validation (also called; HTTP/HTTPS, file authentication), which requires the domain owner to upload to the domain a file containing a unique identifier given to the certificate applicant by the Certificate Authority (CA).
The CA can then locate and interrogate this file as proof that the requestor has control of this domain.
What will change exactly?
The new policy will be implemented on the 15th of November and will affect SSLs and orders in the following ways:
1. It will be no longer possible to validate Wildcard certificates using file-based validation (all types of Wildcards are affected)
2. When using file validation for multi-domain certificates, domain validation will be required for every FQDN/SAN (domain) individually.
Example:
Prior to the 15th of November - if you ordered a certificate for:
openprovider.nl
www.openprovider.nl
test.openprovider.nl
You would only need to place a file on openprovider.nl/some-folder
After the 15th of November - if you order a certificate for the above domains you will need to place the file on:
www.openprovider.nl/some-folder
test.openprovider.nl/.well-known/some-folder
openprovider.nl/.well-known/some-folder
3. When using file validation for single domain certificates, domain validation will be required for every FQDN/SAN (domain) individually.
Example:
Prior to the 15th of November - if you ordered a certificate for test.openprovider.nl, file could be placed either on test.openprovider.nl or openprovider.nl
After 15th of November - if you want to protect test.openprovider.nl, the file must be placed for test.openprovider.nl
4. For DV certificates (single domain) you can also receive the "www" as an additional name for free,
e.g. If you order a certificate for openprovider.nl you can receive www.openprovider.nl for free, and vice-versa
If you order for test.openprovider.nl you can receive www.test.openprovider.nl for free and vice-versa.
That also means files must be placed for both domains: with and without www.
Important: For Openprovider API users:
When requesting a certificate using our API, if you wish to request a certificate for a domain with WWW and without WWW, you have to specify host names and domain validation methods for both variants.
Certificate renewal: When processing a renewal request, we will first check which variants where initially issued for the particular domain; with WWW and without WWW variant or with just one. If you received first certificate with both, then the renewed certificate will include WWW and non-WWW domain.
If you received the certificate with just one variant but need both, you can always reissue it in SSL Panel with the above checkbox selected.
What is the impact?
- The change will not affect certificate issues prior to the 15th of November.
- It will affect all new orders, renewals, and reissues after November 15, when using file validation as a DCV method.
- Other domain control validation methods are not impacted by this change, so this change does not apply to Email- and DNS-based validation, which still are available for wildcard certificates.
- If you now use file validation for wildcard certificates, you will have to switch to email validation or CNAME validation.
- Wildcard certificates which were previously issued with file validation can not be directly renewed via the ssl panel (using the previous details). Please start a new order and select one of the supported validation methods.
- If you use file validation for single and multi-domain certificates and want to continue using it, you will need to prepare a separate file for each subdomain (SAN), or switch to another DCV method.
Openprovider strongly suggests choosing other methods of domain validation than HTTP / HTTPS validation:-
- E-mail validation
- DNS / CNAME validation
Both will make validation process quicker to complete.
How to order a SSL Certificate
This section will describe how to order a SSL Certificate in the SSL Panel.
In case you are interested to learn how to do this via API, please click here
Step 1
The most important step when requesting a SSL Certificate is to make sure all details you use in the request are up to date. Especially with OV and EV orderes, we advise to first double check the handles you are about to use, or create a new handle with the latest information. Make sure the handle has a valid firstname / lastname of a contactperson who would be available for a verification-call. (required for OV and EV certificates)
This can not be changed once the order is submitted.
Step 2
Go to the SSL Panel and select the SSL Certificate you wish to request.
Not sure which type you need to order? You can find an explanation of all types here.
Step 3
On the following page, you can toggle the auto renew feature on or off and select for how many years you want to order the SSL Certificate. In case you select a 2+ years certificate, an Subscription SSL will be created. Click on "Order" to proceed with the request.
Step 4
Fill in all the required data for your order.
Contact data
Important! The handle which you select as "Organisation (requestor)", will be used for the SSL certificate. The data from this handle will be used for the SSL owner and for the SSL validation. If any data is invalid or outdated, please go back to the customer management and update the handle before requesting the SSL.
We advise to leave the "Technical contact" assigned to Openprovider (selected by default) for managing purposes.
Technical data
It is highly recommended that you generate the CSR for your certificate in our control panel (exception: IIS certificate), even if you earlier generated it elsewhere. This will guarantee that your CSR is in proper format, which is a must, to generate the certificate successfully.
Important!
You will need this CSR and Private key during installation of the SSL on your server. Make sure to store the private key locally as this will will not be stored by us.
Lost the private key? Click here
Step 5
At the bottom of the page, there are some additional options:
You can enable DNS automation, very useful when the DNS zone is managed in Openprovider and you wish to validate the certificate via DNS validation.
Add the www/non-www domain to your order (additional information here).
Once everything is filled in, you can select the validation option.
By default this is set to Http(s) but via the dropdown you can select all available options; http(s), DNS or e-mail. More details about the validation methods can be found in the How to validate a SSL order article.
To submit the request, just click on "Request".
How to validate a SSL order
Question
How to validate a SSL order once the request has been made?
Answer
In order for Sectigo to issue the SSL Certificate, one or multiple validation steps have to be taken to ensure that the company who requested the SSL, is also actually the owner. Which steps have to be taken all depends on the "Type of certificate" you have selected.
DV Certificates
OV Certificates
EV Certificates
DCV validation (Domain Control Validation)
This is a check to confirm that you have ownership over the domain for which you are requesting the SSL Certificate.
This can be done by 1 of 3 options; via email confirmation, via a record in the DNS or file a file on the server.
1. Email validation
2. DNS validation
3. File validation
Email validation
Confirming an email that is linked to the domain name is one of the options to proof that you own the domain. Therefore is not not possible to sent this email to any random email address, but it has to be connected to the domain.
The following so-called "approver email addresses" are provided as options:
- admin@..., followed by the (sub) domain of the certificate ;
- administrator@..., followed by the (sub) domain of the certificate ;
- postmaster@..., followed by the (sub) domain of the certificate ;
- hostmaster@..., followed by the (sub) domain of the certificate ;
- webmaster@..., followed by the (sub) domain of the certificate ;
- WHOIS-visible email [Deprecated - public Certificate Authorities will no longer allow WHOIS-based email addresses for domain validation. You can read more information about this here]
Via the SSL panel, you can review all available options and make changes if required.
The email itself will be sent from noreply_support@trust-provider.com, with the subject Comodo Domain Validation for [domainname] (reference #number)
Please follow steps as described in the email to validate the request.
DNS validation
Another option to proof that you have control over the DNS, is by adding a record in the DNS zone of the domain. This option is especially interesting for resellers who control the DNS zone of the domain and prefer not to ask the registrant to go look for an email from Sectigo.
In case you select the DNS validation, you will need to add a CNAME in the zone of the domain. Please make sure to check where the zone is managed. If you manage the zone via Openprovider, you can add the record directly in the zone (or use the automated option during the SSL request) and in case you use a third party nameserver, you will need to add the record in the zone there.
The value which needs to be added will be unique and can be found in the SSL panel (or requested via API) via the button "Follow the instructions".
A pop-up will appear where you can find the details:
File validation (HTTP(s)
File validation (also referred to as HTTPs) validation works a bit similar.
Hash values are provided to you to create a simple plain-text file and place this in a specific host directory on the server. Sectigo will check the location and when the file is visible, the validation is approved.
Please note: this method can not be used for validating certificates with Wildcard names. When using file validation for multi-domain certificates, domain validation will be required for every FQDN/SAN (domain) individually.
Note that validation will fail if redirection is in place.
The "hash: (the plain text value) which needs to be uploaded can be found in the ssl panel (Button "Follow the instructions" once the order is submitted or can be retrieved via API.
Please put the same file for a domain with www or without www in a respective folders, eg. www.exampledomain.com/.well-known/pki-validation/ and exampledomain.com/.well-known/pki-validation/
Company validation
Sectigo will verify that your organization is legally registered on the address that you have entered in the handle which you used to submit the request. This will typically be verify through a government database or online directories, like Dun & Bradstreet (https://www.dnb.com/), the Chamber of Commerce (for example; kvk.nl), etc.
Therefore it is very important that the information in the online directory is matching the information in the handle!
Phone Validation
In order to receive an OV and EV certificate, you must have a registered active telephone listing that is verifiable by an online telephone directory. It is important that your listing matches the exact business name and physical address that have been provided and verified.
In most cases the phone number is found in the company registration database when the company validation step is preformed.
During this call, Sectigo will ask to speak to the contact person which is mentioned in the handle
Note: It is not possible to ask Sectigo to call an unlisted phone number. It will only be possible to use phone numbers which are listed in a public directory. Your own website is not a public source, so phone numbers from your own website can not be used.
Signed Documents
In order to validate an EV certificate, a "subscriber agreement" document must be signed. This document will be sent to the email address mentioned in the handle.
Making changes after the SSL has been issued (reissue)
Question:
The SSL has been issued, but I want to make changes. Is that possible?
Answer:
There can situations when you realize after the SSL has been issued (delivered), that a mistake was made. In some cases, you will have the option to make changes via a reissue.
Examples of those scenarios are:
- I forgot to add the WWW domain in the order.
- I forgot to store the Private key during the order process.
- I want to add or remove SAN domain(s) in my multidomain SSL. Please note that adding extra domains will be charged during the reissue request, removing domains will not result in a refund.
In some scenarios, a reissue can not resolve the problem. The only option is to cancel the SSL (See SSL refund policy) and start the order again.
Examples of those scenarios are:
- I ordered the SSL for the wrong domain.
- I used the wrong handle for the validation.
- I ordered the wrong type of SSL (DV instead of OV for example).
- I used the wrong CSR in my order.
It can happen that a certain handle / contact person is attached to your SSL orders, which can not validate the order anymore (for example - this person has left the company).
Unfortunately, this can not be updated in existing issued SSL Certificates.
The only option to update a handle or contact person for SSL Certificates, is waiting until the order reaches it final expiration date, disable the auto renewal and start a new request with the new details.
Making changes during the validation process
Question
My order is stuck due to invalid or outdated details. Can I make changes?
Answer
In case your order is stuck due to invalid details during the pre-validation phase (Status is "Open", the order has not been send to Sectigo yet), we would recommend to cancel the order (do not proceed via the force request button) , make the required changes in the handle or in the business registration database and start the order again.
In case the order is being reviewed by Sectigo (Status is "Requested") and they inform you via the chat* that information is invalid (for example, the address in the handle is not matching with the business registration database), Sectigo can ask you in the chat if they may update the order for you.
You have the option to reply via your ssl panel chat* window directly towards the Sectigo validation team.
Important!
In case you allow Sectigo to change the details in the order to match the company registration database, this will be only applied to the current SSL request.
The SSL will be issued with different details as mentioned in your SSL panel. This means that every reissue and renewal will face the same issue, as the reissue / renewal will be initiated with the old details.
In those cases, we advise to check the deadline of the order.
In case the order is not urgent - we advise to reject the manual change via the Sectigo validation team, cancel the order and start it again with the correct details.
In case the order is urgent - we advise to accept the manual change via the Sectigo validation team, disable the auto renewal of the SSL and once the SSL is within 30 days of the final expiration date, start a new request manually with the correct details. Note that the remaining period of the ssl will be lost, as the details of the order are not a 100% match anymore.
Please note that it is also not possible to change the SSL details via a reissue.
*Keep in mind, this is not a realtime chat. Replies from the Sectigo validation team generally take 24 / 48 hours during business days.
This CHAT is only operational from the moment the SSL request is "Requested" and will be closed once the SSL is issued. When the SSL has the status "open" the CHAT can not be used yet.
Transitioning SSL Validation from WHOIS to DNS
Recent vulnerabilities in the domain name WHOIS system have highlighted the WHOIS-based domain-validation method as a weakness in the process of validating publicly-trusted digital certificates. As a result, Sectigo and all other public Certificate Authorities have announced that WHOIS-listed email addresses are no longer acceptable for domain validation, nor can historic domain validations based on WHOIS email addresses be reused. You can read more information about this change here.
Renewal or Re-issue of SSL orders that currently use WHOIS email address will fail with error "CA request failed" due to this. To ensure continued successful validation and issuance of your SSL certificates, at Openprovider we will be proactively switching the validation method from WHOIS to DNS validation for affected orders. This change will apply automatically before the next renewal or issuance. After the certificate is issued, you will still have the option to change the validation method (e.g., to email or HTTP) if preferred. You ca find available validation methods here.