hero-faq-1

FAQs

What if I put some wrong information in the CSR?

Whether you accidentally or purposefully enter some incorrect information during the CSR generation process, the CSR and the Private Key will still be issued to you immediately. However, once you use the CSR code to apply for an SSL Certificate, you may or may not be issued an SSL Certificate. It is solely at the Certificate Authority’s discretion to approve or decline your SSL Certificate issuance if you entered incorrect information about you and your company.

If you found out that the CSR is wrong and you already configured the SSL, please open a ticket with us and provide the correct CSR.

If you realized that you entered incorrect information in the CSR while generating it, you simply have to put aside, ignore or delete your existing CSR and Private Key. After that, you should generate a new CSR code (which will automatically generate a new Private Key too), using correct information about yourself and your company. Use the newer CSR when applying for an SSL Certificate, and then your newer Private Key when installing your SSL Certificate on your website and server.

Copy Link

Brand Validation Reasons

 

In some cases, the CAs may require manual verification if your order fails any internal rules of Brand Validation. It takes around 24-48 hours to pass this manual check, and the CA will either issue or reject an order in such cases.

Here are the most common reasons why certificate authorities decide to do the brand validation for some orders:

  1. Orders from some countries are reviewed manually more often than others, for example:  South Korea, North Korea, Japan;
  2. Restricted countries – Russia (RU), Belarus (BY) (since 2022), Afghanistan (AF), Crimea (Russia), Cote d’Ivoire (CI), Cuba (CU), Eritrea (ER), Guinea (GN), Iraq (IQ), Iran (IR), Democratic People’s Republic of Korea (KP), Liberia (LR), Myanmar (MM), Rwanda (RW), Sudan (SD), Sierra Leone (SL), South Sudan (SS), Syrian Arab Republic (SY), Venezuela (VE), Zimbabwe (ZW) – SSL are NOT issued for these countries: https://sectigo.com/knowledge-base/detail/Banned-Country-List-1527076085907/kA01N000000zFKI and https://knowledge.digicert.com/solution/Embargoed-Countries-and-Regions.html
  3. The domain name includes a brand name, such as: facebook-app.com, sony-shop.net, dellshop.com, etc;
  4. The domain name may have a hidden brand name. For example, your domain is “sibmama.com”, but the automated validation system may read it as “sIBMama” and flag the “IBM” brand. The certificate authority wants to check such orders manually;
  5. The domain name has “stop words”, such as: pay, online, secure, booking, shop, bank, transfer, money, e-payment, payment, protection, violence, terrorists, and others. These words and many others are set as triggering words inside the validation system, and make the certificate authority review such orders manually;
  6. Domain name is blacklisted OR has a bad reputation.
    partner-order-id

What you can do to speed up the process?

Please contact Sectigo and Thawte, RapidSSL, GeoTrust, DigiCert directly via live chat and discuss the situation with the CA’s representative.

Please mention your “Partner Order ID” in your message.  You can find your “Partner Order ID” on the details page of your SSL Certificate inside your SSL Dragon account. See the screenshot on the right.

Copy Link

How to buy an SSL Certificate?
Infographic showing steps to buy an SSL Certificate
  1. Choose the SSL Certificate, then select the period (1, 2, or 3 years) and number of domains (only for Multi-Domain SSL Certificates), and click “Buy Now”;
  2. You’ll be redirected to your Shopping Cart, where you need to confirm the period and, for Multi-Domain SSL Certificates, the number of additional domains. Review your Order Summary then click “Continue”;
  3. On the Review & Checkout page, you’ll find the “New Customer” fillable form which you need to complete to create your SSL Dragon account. Afterward, insert your Promotional Code (if you have it), any Additional Information (if necessary), select the desired Payment Method,  confirm that you’ve read and accepted our Terms of Service, and click on “Checkout”;
  4. You’ll be redirected to your Invoice which you need to pay using your selected Payment Method. Once the payment is done, you will see your order number and additional details on your Order Confirmation page. You will find your SSL Certificate in “My Account” at “SSL Certificates” -> “My SSL Certificates

Copy Link

Which BV certificates have the quickest validation?

BV SSL Certificates issued by GeoTrust, Thawte, and DigiCert have a quicker and easier Business Validation process compared to those issued by Sectigo.

With GeoTrust, Thawte, and DigiCert, the Certificate Authority does most of the company validation process all by itself, and in rare cases requires the customers to provide additional information and legal letters signed by a notary, certified public accountant, or an attorney.

On the other side, Sectigo relies a lot on the customer to provide all the information about his/her company, as well as updating the company’s DUNS listing (on the Dun & Bradstreet website) and providing legal letters signed by a notary, a certified public accountant, or an attorney.

You can read what the Business Validation process with these different brands consists of at this link.

Copy Link

Can I change the domain in my SSL Certificate?

Yes, you can change the domain name that your SSL Certificate is issued to. The procedure involves the reconfiguration and reissue of your SSL Certificate, and there are some additional steps if you have a Business Validation or Extended Validation Certificate.

Domain Validation SSL Certificates

You can reissue your SSL Certificate from your SSL Dragon account by following the next steps:
1) Log into your SSL Dragon account;
2) Go to “SSL Certificates” -> “My SSL Certificates“;
3) You will see the list of products that you bought from SSL Dragon. Click on the SSL Certificate which you would like to reissue;
4) Click on the “Reissue certificate” button on the left side (see the screenshot on the right);
5) Reconfigure your SSL Certificate. As a part of the reconfiguration, please create a new CSR code and enter the new domain name in it.
6) For Multi-Domain SSL – Don’t forget to include the SAN list in the SANs field;
7) After reconfiguring your SSL Certificate, you will have to pass the Domain Validation again.

For Domain Validation SSL Certificates, your SSL Certificate will be reissued for the new domain name after you pass the domain validation successfully.

Business Validation SSL Certificates

To change the domain name in your Business Validation SSL Certificate, you have to go through the same reconfiguration and domain validation process as described under the “Domain Validation” section above. After that, you have to pass the entire Business Validation process again, so as the Certificate Authority needs to verify the legal existence of your domain name, company, and your company’s phone number. You can read how to pass the Business Validation process at this link.

Your BV SSL Certificate will be reissued for the new domain name after you pass the Business Validation process again.

Extended Validation SSL Certificates

To change the domain name in your Extended Validation SSL Certificate, you have to go through the same reconfiguration and domain validation process as described under the “Domain Validation” section above. After that, you have to pass the entire Extended Validation process again, so as the Certificate Authority needs to verify the legal existence of your domain name, company, and your company’s phone number. You can read how to pass the Extended Validation process at this link.

Your EV SSL Certificate will be reissued for the new domain name after you pass the Extended Validation process again.

Copy Link

Where can I check how well my SSL Certificate is installed?

Two great tools to check how well your SSL Certificate is installed are:
1) SSL Server Test
2) Why No Padlock?

You only have to paste your https URL to get a free report and an A++ to F grade on your SSL Certificate installation. These tools will tell you what are the vulnerabilities of your SSL Certificate installation, and will offer you detailed information on how to fix them.

We also recommend you to read our article called: How to move your website from HTTP to HTTPS easily and with no pain.

Copy Link

How can I contact a Certificate Authority?
partner-order-id

You can contact the Certificate Authorities directly when you have any questions related to your SSL Certificates. You can contact them anytime, either by phone or email, or better – by using the Live Chat feature.

Please don’t forget to mention your Partner Order ID, which you can find on the SSL Certificate’s details page inside your SSL Dragon account (see screenshot on the right).

Here is the contact information of all Certificate Authorities we collaborate with:

Sectigo/GoGetSSL

Live Status Checker: https://secure.trust-provider.com/products/ORDERSTATUSCHECKER

Live Chat & Ticket System: https://sectigo.com/support

Phone (USA): +1 (888) 266-6361
Phone (International): +1 (914) SECTIGO (732-8446)

More contact information on Sectigo’s official website

Thawte

Online chat: https://www.thawte.com/chat/chat_sales.html

Phone (USA): +1 (888) 484 2983
Phone (UK): +44 203 450 5486
Phone (Australia & Asia Pacific): +61 3 9914 5641

More contact information on Thawte’s official website

GeoTrust

Online chat: https://www.geotrust.com/support/chat/

Phone (USA): +1 (866) 511-4141
Phone (UK): +44 203 0240907
Phone (Australia): +61 3 9914 5661

More contact information on GeoTrust’s official website

RapidSSL

Online chat: https://www.rapidssl.com/chat/intro.html

Phone (USA): +1 (866) 795-4669
Phone (Europe, UK, Australia): +44 203 024 0906

DigiCert

Phone (USA): +1 (801) 701-9600
More contact information on DigiCert’s official website

Copy Link

Where can I download my SSL Certificate from?

You can download the SSL Certificate directly from the SSL Certificate page within your SSL Dragon account.

Simply use the Download Intermediate/Chain and Download Certificate buttons.

Or you can use the Send Certificate button, too.

We provide you the SSL Certificate in the exact same format in which we get it from the Certificate Authority.

Also, you can use any text editing tool such as Notepad and create the actual files that you need:

Go to your SSL Dragon account, then to your SSL Certificate details page, you will find the 3 large pieces of codes that your SSL Certificate is made of:

  1. The CSR code is the one which you generated along with your Private Key, and which you used to configure your SSL Certificate. If you need this code as a file, you can copy and paste this code in Notepad, and then save it as a .csr format file.
  2. The CRT code which is your actual SSL Certificate code. Save this one as a .crt format file.
  3. The CA Bundle code has the root and intermediate certificates in it. Save this one as a .ca-bundle format file.

You won’t be able to find your Private Key inside your SSL Dragon account, because we don’t have it, and we don’t store it. Private Keys are private, and it is only you who should have it. If you cannot find your Private Key, we recommend reading this article so as it may help you to find it, or generate a new one.

Copy Link

Where can I find root and intermediate certificates?

If you go to your SSL Dragon account, then to your SSL Certificate details page, you will find the 3 large pieces of codes that your SSL Certificate is made of:

1) The CSR code is the one that you generated along with your Private Key, and which you used to configure your SSL Certificate
2) The CRT code which is your actual SSL Certificate code
3) The CA Bundle code contains the root and intermediate certificates in it

Also, listed below you will find all the Sectigo Root and Intermediate CA certificates and the bundle files required to complete the SSL certificate installation across various servers and email clients.

DV ECC Files

DV RSA files

  • Sectigo RSA DV CA – TXT file
  • USERTrust RSA CA – TXT file
  • RSA DV Bundle – TXT file
  • RSA DV Bundle with SHA-1 – TXT file – includes SHA-1 AddTrust External Root CA required for legacy platforms and Zimbra.

OV ECC files

OV RSA files

  • Sectigo RSA OV CA – TXT file
  • USERTrust RSA CA – TXT file
  • RSA OV Bundle – TXT file
  • RSA OV Bundle with SHA-1 – TXT file – includes SHA-1 AddTrust External Root CA required for legacy platforms and Zimbra.

EV ECC files

EV RSA files

  • Sectigo RSA EV CA – TXT file
  • USERTrust RSA CA – TXT file
  • RSA EV Bundle – TXT file
  • RSA EV Bundle with SHA-1 –  TXT file – includes SHA-1 AddTrust External Root CA required for legacy platforms and Zimbra.

Code Signing – Intermediate

Standard

  • Sectigo RSA Code Signing CA – TXT file

EV Code Signing

  • Sectigo RSA Extended Validation Code Signing CA – TXT file

For Code Signing Certificates, issued on or after June 1, 2021

Standard

  • Sectigo Public Code Signing CA R36 – TXT file
  • SectigoPublicCodeSigningRootR46_AAA [ Cross Signed ] – TXT file

EV Code Signing

  • Sectigo Public Code Signing CA EV R36 – TXT file
  • SectigoPublicCodeSigningRootR46_AAA [ Cross Signed ] – TXT file

Secure Email 

  • Sectigo RSA Client Authentication and Secure Email CA – TXT file

Note: Few legacy systems that no longer receive updates from their vendor may not trust Sectigo SHA-2 Certificates. To enable them to trust the SHA-2 Certificates, Sectigo recommends including the Cross Signed Certificate into the Server Certificate chain. This will enable those legacy systems to trust the SHA-2 Certificates.

Source: Sectigo’s Knowledge Base

Copy Link

Where can I find my SSL Certificate?

You can get the SSL Certificate from your SSL Dragon account by following the next steps:
1) Log into your SSL Dragon account;
2) Go to SSL Certificates;
3) Then go to My SSL Certificates;
4) You will see the list of products which you bought from us. Click on the SSL Certificate which you bought;
5) When you are on the SSL Certificate page, scroll down, and you will see the codes that the SSL Certificate is made of.

The 3 large pieces of codes that you will see are:
1) The CSR code is the one that you generated along with your Private Key, and which you used to configure your SSL Certificate. If you need this code as a file, you can copy and paste this code in Notepad, and then save it as a .csr format file.
2) The CRT code which is your actual SSL Certificate code. Save this one as a .crt format file.
3) The CA Bundle code has the root and intermediate certificates in it. Save this one as a .ca-bundle format file.

You won’t be able to find your Private Key inside your SSL Dragon account, because we don’t have it, and we don’t store it. Private Keys are private, and it is only you who should have it. If you cannot find your Private Key, we recommend reading this article so as it may help you to find it, or generate a new one.

Copy Link