hero-faq-1

FAQs

Do I need a hardware token for code signing?

A hardware token is one of three options. Cloud signing services such as DigiCert KeyLocker and SSL.com eSigner skip the physical token entirely: the key sits in a CA-managed HSM and you sign over an API, which works well for CI/CD. See the hardware delivery section above.

Copy Link

What’s the difference between OV and EV?

EV vetting typically takes 3–5 business days longer than OV, and only EV qualifies for kernel-mode driver signing. Pricing, identity checks, and the SmartScreen behavior comparison are all in the OV vs EV section above.

Copy Link

What is a code signing certificate?

It’s an X.509 certificate that lets a publisher attach a verifiable digital signature to software. Unlike a CSR (just the order request submitted to the CA), the issued certificate binds a vetted identity to a public key that operating systems use to confirm a file’s origin.

Copy Link

Does SSL Dragon offer a refund if I buy the wrong certificate?

Yes. A 25-day money-back guarantee applies to every single-domain certificate. The SSL Dragon support team can also help you reissue or switch to a different certificate type (for example, moving from single-domain to wildcard) before issuance if your needs change.

Copy Link

How long is a single domain SSL certificate valid?

Each issued certificate is valid for up to 200 days under the CA/Browser Forum rules in effect since March 15, 2026. SSL Dragon’s subscription terms (running from one to three years) cover the full purchase period regardless of how many reissuances the lifespan cap requires. Your price is locked even though each individual certificate respects the current 200-day limit.

Copy Link

How much does a single domain SSL certificate cost?

DV starts at $7.66/yr (Comodo PositiveSSL). OV starts at $37.33/yr (Comodo InstantSSL), and EV starts at $75/yr (Comodo PositiveSSL EV). Choosing a 2- or 3-year subscription term lowers the per-year cost while locking in the price for the full period.

Copy Link

Can a single domain SSL certificate secure subdomains like mail.example.com?

No. Only the primary FQDN and its WWW counterpart are covered, so a separate hostname like mail.example.com falls outside scope. To secure all hosts under one parent domain in a single product, the Wildcard SSL certificate is the right fit. To put several distinct domains together on one certificate, look at the Multi-Domain (SAN) SSL certificate.

Copy Link

What’s the difference between DV, OV, and EV single domain SSL certificates?

Validation depth and issuance time are what differ. Encryption is identical at 256-bit AES across all three. DV issues in about 5 minutes after an automated domain check, OV in 1–2 business days after a business identity check, and EV in 1–3 business days after extended vetting.

Copy Link

Does a single domain SSL certificate cover both www.example.com and example.com?

Yes, automatically, with every standard single-domain certificate from Sectigo, DigiCert, GeoTrust, RapidSSL, and GoGetSSL. There is no “include both” checkbox at checkout and no need to specify the second name during the CSR generation.

Copy Link

Is a multi-domain SSL certificate cheaper than buying separate certificates?

Yes. Pricing starts at $21.66/year for 3 domains, less than three separate single-domain certs.

Copy Link