hero-faq-1

FAQs

What happens to my certificate when the 47-day lifespan rule takes full effect in 2029?

Existing certificates remain valid until their issued expiration date. New certificates issued after each phase deadline must comply with the new ceiling: 200 days now, 100 days from March 2027, 47 days from March 2029. At 47 days, automation becomes a practical requirement; see our ACME page for setup guidance.

Copy Link

Can I install one multi-domain wildcard certificate on multiple servers?

Yes. Every product on this page includes unlimited server licensing. Note that “unlimited” refers to the right to install, not to security best practice. Distributing the same private key across many servers increases blast radius if any one server is compromised. Use private key rotation policies appropriate to your deployment scale.

Copy Link

Why isn’t there an EV multi-domain wildcard option?

Covered in the validation section above. Short version: the CA/Browser Forum’s Baseline Requirements prohibit wildcard SAN entries on Extended Validation certificates. This is industry-wide, not an SSL Dragon limitation. Buyers who need EV identity on one specific hostname typically run two certificates side by side — an EV single-domain on the flagship hostname, and the multi-domain wildcard on the rest of the portfolio.

Copy Link

What’s the difference between a multi-domain wildcard and a UCC certificate?

Functionally none, in most cases. UCC (Unified Communications Certificate) is the older naming used in Microsoft Exchange and Communications Server contexts. A multi-domain wildcard works as a UCC and supports the same FQDN flexibility Exchange requires for its autodiscover, mail, and webmail hostnames.

Copy Link

Can I add or remove domains after the certificate is issued?

Yes, free and unlimited via reissue. The expiration date stays the same; reissuing does not extend validity. For DV, you only need to prove control of any newly added domains; for OV, organization validation can usually be reused within the certificate’s lifetime, so reissues complete faster after the first one.

Copy Link

How many domains can a multi-domain wildcard SSL certificate secure?

Most products on this page support up to 250 total SANs (1 primary domain + 249 additional). Default packages start at 3 or 4 SANs included; you add more individually at checkout. A few Sectigo OV multi-domain wildcards support higher caps; check the specific product page for the exact ceiling.

Copy Link

Why does the report show “Not Supported” for HSTS even though my SSL works?

HSTS is a server response header, not part of the certificate. The cert can be perfectly valid while HSTS stays unconfigured. Add it in the web server config: Apache uses Header always set Strict-Transport-Security, Nginx uses add_header Strict-Transport-Security.

Copy Link

Does the SSL checker work for certificates from any Certificate Authority?

Yes. It reads whatever certificate the server presents, from Let’s Encrypt, Sectigo, DigiCert, GeoTrust, RapidSSL, Thawte, GoGetSSL, Google Trust Services, and others. SSL Dragon’s SSL certificate catalog covers six of those CAs side by side.

Copy Link

Can I check the SSL certificate of an internal or local hostname?

No, public checkers can’t reach internal hosts behind firewalls. From a machine on the same network, run openssl s_client -connect host:443 -servername host for equivalent output. The OpenSSL command-line tool ships with most Linux distributions and is available for Windows.

Copy Link

What does it mean if the report shows an “incomplete chain”?

Your server isn’t sending all the intermediate certificates browsers need. The short fix: Apache uses SSLCertificateChainFile or a combined bundle, Nginx expects a fullchain.pem file, and IIS rebuilds the chain through the certificate import wizard.

Copy Link