hero-faq-1

FAQs

Where is the SSL .conf file in Apache?

The conf. file may reside in different locations depending on your OS and configuration. Check the httpd.conf, apahce2.conf or ssl.conf in one of the following directories: etc/httpd/, /etc/apache2/ or /etc/httpd/conf.d/ssl.conf

Copy Link

How do I know if Apache SSL is enabled?

For Debian and Ubuntu distributions, use the following commands

#grep -ir SSLProtocol /etc/apache2/*

/etc/apache2/mods-available/ssl.conf:SSLProtocol +TLSv1.2 +TLSv1.3

Copy Link

What is SSL in Apache?

SSL (Secure Sockets Layer), now TLS (Transport Layer Security), is a cryptographic protocol that encrypts communications between two network endpoints, for instance, a web server such as Apache and users’ browsers.

Copy Link

I cannot choose the domain validation method

When configuring, reissuing, or renewing your SSL Certificate, if you cannot choose the domain validation method, or you encounter an error message, it means there is a CSR error. Here are the most common CSR errors, and the ways to fix them:

  • If you have a Wildcard SSL Certificate (for multiple sub-domains), then the common name in your CSR should start with an asterisk and a dot (*.) as in this example *.website.com. For regular, non-wildcard SSL Certificates, the common name should have one of the following formats: website.com, www.website.com or my.website.com.
  • Wrong Key Encryption (e.g. 4096 bit). Please make the Key Encryption 2048 bit.
  • Your CSR is password protected. Please disable the password so that the Certificate Authority issuing the SSL Certificate can read the CSR code.
  • The CSR code is missing some required fields or information. You can find the complete list of fields on our CSR Generator.
  • Your CSR may have other information that is incorrect or not allowed. Please see this FAQ article with details on allowed information and formatting.

To fix your CSR code you need to generate a new one. After that, try configuring or reissuing your SSL Certificate with the new CSR code. If the problem persists, please open a ticket with us and send us your the CSR code. We will decode the CSR and tell you what the problem is, so that you can fix it.

Copy Link

What information the CSR must contain?

The CSR must contain the following mandatory encrypted information: your Country, State, City/Town, Name of the company, Department from your company, and the Domain name or IP address that you want the SSL Certificate to be issued for.

It may also contain this optional information: the email address where your CSR code and the Private Key will be sent to once they are both generated.

To avoid any errors, please make sure that:

  1. You DO NOT enter “http://” or “https://” along with your domain name as a common name when generating the CSR. Please enter only “www.domain.com” or “domain.com” as a common name. Also, make sure you don’t have any extra spaces before or after your domain name.
  2. When generating the CSR code you were given a CSR code and a Private Key. Make sure that you only enter the CSR code in the SSL Configuration form. DO NOT enter the Private Key, but save it and keep it in a safe location on your computer or email, because you will need it when installing the SSL Certificate on your website/server.
  3. The CSR that you enter in the SSL Configuration form should include the following two lines: “—–BEGIN CERTIFICATE REQUEST—–” header and “—–END CERTIFICATE REQUEST—–” footer.
  4. For Wildcard SSL Certificates – When generating the CSR code for a Wildcard SSL Certificate, you have to include an asterisk and dot (*.) before your domain name. In other words, you should fill in *.yourdomain.com as a common name in your CSR.
  5. For Multi-Domain Wildcard SSL Certificates – Any Multi-Domain Wildcard SSL Certificate should start with a non-Wildcard domain. This means that you need to generate the CSR for a single domain – example.com – without any asterisk sign “*.”. Please read more in this FAQ.
  6. For IP Address SSL Certificates – For Sectigo InstantSSL Premium, the common name should be your IP address. For GoGetSSL Public IP SAN SSL Certificate, you will be asked to generate a CSR with NO Common Name. Here is how to do it.
  7. Your CSR is not configured for the following countries:
    • AF – AF – Afghanistan
    • BY – BLR – The Republic of Belarus
    • CU – CUB – Cuba
    • ER – ERI – Eritrea
    • GN – GIN – Guinea
    • IR – IRN – Iran, Islamic Republic of
    • KP – PRK – Korea, Democratic People’s Republic of
    • LR – LBR – Liberia
    • RU – RUS – The Russian Federation
    • SS – SSD – South Sudan
    • SY – SYR – Syrian Arab Republic
    • ZW – ZWE – Zimbabwe

Copy Link

Where can I find my Private Key?

This is one of the most frequent questions that we get. Unfortunately we cannot send you the Private Key, because it is private, and we do not store it anywhere in our system or database. The Private Key is always confidential, and it is only you who should have it. If we were to have or store your Private Key, this would compromise the “security” of your SSL Certificate.

If you used the CSR Generator on our website to generate your CSR code, then the CSR and the Private Key were both shown to you during the CSR generation process. They were also sent to your email address in case you included your email address in the CSR Generator. The message that was sent to your email address came from [email protected] and has the following subject: “Your CSR code and your Private Key”.

If you generated your CSR on your server, then your CSR code and your Private Key were both provided to you by your server. You had to copy and store them in a safe place. In some cases, some servers may show the CSR code and the Private Key, and at the same time store both these pieces of code for you on the server. In other cases, the server only provides you the CSR code and keeps the Private Key hidden on the server.

re-issue-certificateThis being said, please look for the Private Key in your email address or your server. If you cannot find it, then you will have to generate a new CSR code on your server, or on the CSR Generator on our website. The CSR code will come with a Private Key.

Once a new CSR code (and Private Key) were generated, you will have to go to the SSL Certificate details page inside your SSL Dragon account, and click on the “Reissue certificate” button from the left side bar on the page. You will have to pass the domain validation again, and once you do that, the SSL Certificate will be re-issued to you based on the new CSR code that you entered. Also, the re-issued SSL Certificate will pair with the Private Key which came along with the new CSR code.

If you cannot find the “Reissue certificate” button on the SSL Certificate details page inside your SSL Dragon account, then please send us the new CSR code via a Support Ticket inside your SSL Dragon account, or directly at [email protected] and we will re-generate the SSL Certificate for you, using the new CSR code. Please do not send us your Private Key so as it is confidential. Store it in a safe place in your email or computer, so as you will need it when installing your SSL Certificate.

Copy Link

What if I lost my CSR or Private Key?

In order to prevent the situation when you lose your CSR code and Private Key, we automatically send them to the email which you provided when using the SSL CSR Generator from above. Please check your email, and look for a message from SSL Dragon ([email protected]).

However, if you lost or cannot find the email message from us, and you did not save a copy of your CSR code and Private Key, then you will not be able to apply for an SSL Certificate, and you will not be able to install your SSL Certificate on your website and server. But, that is easy to solve by generating a new CSR code and a new Private Key by using the SSL CSR Generator from above.

Copy Link

How to get an LEI number?

LEI number registration is a four-step process:

  1. Choose the LEI plan that suits your budget
  2. Complete our intuitive LEI application form
  3. Submit your LEI form and payment
  4. Wait for the LEI code to arrive by e-mail.

Copy Link

What happens when an LEI number expires?

You must renew your LEI code annually to keep the LEI status ACTIVE. Failure to do so will display your LEI as LAPSED in the Global Lei Index. An expired LEI may incur non-compliance fines and block financial transactions.

Copy Link

Do you offer a money back guarantee?

We guarantee a 100% refund only for non-issued LEI codes. If the LEI code is issued and the user cancels it, there will be NO refund. Please note we do not guarantee a refund if the information provided during entity verification is fake and wrong.

Copy Link