hero-faq-1

FAQs

How long does it take to get an SSL certificate for an IP address?

About 5 minutes for the GoGetSSL Public IP SAN (DV). Sectigo and Comodo InstantSSL Pro take 1–2 business days because Business Validation requires verification of company documents.

Copy Link

What if I need to secure a private or internal IP address?

A public CA cannot issue for private IPs. Sectigo Private PKI is the production answer; self-signed certs are only suitable for non-trusted internal testing.

Copy Link

Does an IP certificate use weaker encryption than a domain certificate?

No. Same TLS 1.2 and 1.3 protocols, same RSA and ECC key options, same warranty levels.

Copy Link

Can one certificate cover an IP address and a domain name?

Yes. The GoGetSSL Public IP SAN supports up to 250 SAN entries combining public IPs and fully-qualified domain names on a single certificate. For domain-only setups across many hostnames, see the Multi-Domain SAN certificate range.

Copy Link

Can I get an SSL certificate for any IP address?

No. Only public, routable IPs are eligible. DV and BV are both available for IP certificates, but EV is not: the CA/Browser Forum does not permit Extended Validation for IPs at all.

Copy Link

Will my signed software stop working when the certificate expires?

No. Code signed with a valid timestamp stays trusted past expiry; only new signing ends. Use tsa.digicert.com or timestamp.sectigo.com as a free TSA.

Copy Link

Can I sign code in CI/CD without a physical USB token?

Yes. DigiCert KeyLocker cloud HSM signing lets you sign over an API with no token, and it covers macOS or Linux build agents where a USB token isn’t practical.

Copy Link

Which is the cheapest EV code signing certificate SSL Dragon carries?

Comodo EV and Sectigo EV both start at $287/year, the joint-lowest EV options on this page. Multi-year orders lower the per-year cost, with annual reissuance under the 460-day rule.

Copy Link

Do I need an EV code signing certificate for Windows drivers?

For kernel-mode drivers, yes; Microsoft’s WHQL portal rejects anything below EV. User-mode drivers can be signed with OV under the same Authenticode flow as ordinary applications.

Copy Link

What’s the difference between OV and EV code signing certificates?

EV requires registered-organization vetting and is the only tier accepted for Windows kernel-mode drivers; OV permits individual developers at lower cost. EV vetting typically takes 3–5 business days longer than OV.

Copy Link