Skip to main content

SSL order or renewal fails: State or Province value is invalid for the Country

Symptoms

When placing or renewing an SSL certificate order, the order fails at the validation stage with the following error:

[province: Invalid value] - State or Province value is invalid for the Country

image.png

Cause

Sectigo now strictly enforces ISO 3166-2 compliance for the State/Province field. The stateOrProvinceName value in your CSR must match the official ISO 3166-2 subdivision name for the selected country exactly, including diacritical marks and special characters. Any other spelling is rejected.

Entered value ISO 3166-2 value
Attica Attikí

This applies to all new certificate orders and to renewals. If an order fails at the organization validation step, the State/Province value in the CSR is the most likely cause.

Solution

An order that has already failed cannot be corrected. Cancel the certificate and place a new order with the State/Province in the correct ISO 3166-2 format. The cancelled certificate is credited back to your Openprovider account balance.

To find the correct value:

1. Open the ISO Online Browsing Platform

Go to https://www.iso.org/obp/ui/#home

image.png

2. Search for the country

Enter the country name in the search bar (for example, Greece) and select the matching result.

image.png

3. Find the subdivision

Scroll down to the subdivision table and locate your State/Province. For Greece, the correct entry is Attikí, not Attica.

4. Copy the value exactly

Copy and paste the subdivision name directly from the ISO website. Retyping it risks losing diacritics or special characters, which causes the same error again.

5. Generate a new CSR

Create a new CSR using that exact value in the State/Province field, then place the order.

image.png

Good to know

We are adding validation in the SSL panel so that the State/Province value is checked before the order is submitted. Until this is live, please follow the steps above.