Wait! Don't Leave Without Securing Your Site
Get enterprise - grade SSL certificates at a fraction of retail prices.
Save 10% on your first order, by entering coupon code SAVE10 during checkout.

During the certificate enrollment, the browser generates your private key. After you submit the CSR (Certificate Signing Request), the browser creates a key pair and stores it in the local key database.
You can apply for a S/MIME certificate only using the following browsers:
Note: Safari on Mac no longer supports key generation.
Source: Sectigo’s Knowledge Base
Copy Link
Any business that is officially registered with a government authority can qualify for an Extended Validated SSL Certificate. This certificate is issued only after the Certificate Authority (CA) performed an extensive verification of your company and its owner, confirming that your business is trustworthy.
Copy Link
SSL Dragon is a fully approved SSL Certificate Reseller that has a wide range of SSL products issued by trusted Certificate Authorities (CAs) such as Sectigo, RapidSSL, Geotrust, Thawte, and DigiCert.
Since SSL Resellers offer CAs greater access to a large number of clients, this highly successful distribution model allows the CAs to focus on product development and improvement, while the resellers perform most of the sales.
This partnership encourages resellers to buy SSL Certificates in bulk at highly favorable prices and hence charge considerably less for the same SSL Certificate offered by a CA.
Therefore, you don’t need to worry – there is nothing wrong with SSL resellers and the SSL Certificates they offer. Since all CAs are reputable brands, these companies won’t allow any third parties to represent them if they don’t meet the necessary requirements. Thus, you can feel confident that the CAs have verified and authorized SSL Dragon to market their products.
So, instead of shopping directly from Certificate Authorities, you have the chance to buy the same SSL Certificates based on a platinum reseller discount, along with other great value deals, 25-days money-back guarantee, and dedicated support.
Copy Link
You need a CSR in order to apply for an SSL Certificate. Later, when your SSL Certificate is issued to you, then you will also use the CSR code for the activation of the TLS (Transport Layer Security).
Copy Link
Unfortunately, there are no Wildcard EV SSL Certificates on the market. The Certificate Authorities refuse to issue EV Wildcard SSL Certificates because of the security reasons, so as they want to have complete control over the subdomains that they issue an EV SSL to. That is why, your only solution is to buy a Multi-Domain EV SSL Certificate that secures multiple domains and subdomains.
Copy Link
As of June 1, 2021, and in compliance with the CA/Browser Forum Code-signing Baseline Requirements, Sectigo will require RSA keys to be a minimum of 3072 bits in size.
When generating keys and CSRs for code-signing certificates, please ensure you choose an RSA key with a 3072- or 4096-bit key size.
Only the size of the keys is to change, the rest of the process remains the same. Existing RSA 2048 bit certificates will continue to work and no changes are needed to them.
Certificates requested with ECC (elliptic curve) keys are unaffected and Sectigo will still sign certificates with keys using the NIST P-256 and P-384 curves.
Source: Sectigo’s Knowledge Base
Copy Link
As of June 16, 2021, Sectigo no longer accepts WHOIS-based email addresses for Domain Control Validation (DCV) when the WHOIS requires a human lookup for domain information. Whois is a widely used Internet record listing that identifies who owns a domain and how to get in contact with them.
The change won’t affect emails that can be found on WHOIS via automated lookups. These emails will be presented to you during the certificate request process, or via the ‘GetDCVEmailAddressList’ API. The ‘constructed’ email addresses will still be available.
If the email address you need is not displayed or offered during the DCV process, you will need to use one of the alternative methods for the Domain Control Validation below:
Source: Sectigo’s Knowledge Base
Copy Link
Here are the steps that you need to do in order to reissue your Sectigo/Comodo Code Signing certificate:
1) Login at https://secure.trust-provider.com/products/frontpage?area=ssl using the username and password that you used when you configured your Sectigo/Comodo Code Signing certificate initially;
2) Once you are logged in, find the “Replace” button and click on it;
3) You will start the reissue process for your Sectigo/Comodo Code Signing certificate.
4) Follow the steps and instructions that come next, until you complete the Sectigo Code Signing certificate reissue.
Copy Link
Starting June 1, 2023, industry standards mandate storing code signing certificate private keys on FIPS 140 Level 2, Common Criteria EAL 4+ certified hardware. This change enhances security, aligning with EV code signing standards. Certificate Authorities can no longer support browser-based key generation or laptop/server installations. Private keys must be on FIPS 140-2 Level 2 or Common Criteria EAL 4+ certified tokens/HSMs. To sign the code, access the token/HSM and use stored certificate credentials.
In line with the new guidelines, your private key should be on the token shipped by the CA or on your Hardware Security Module.
Copy Link