Specifications
| Specification | PositiveSSL |
|---|---|
| Issuer | Sectigo Limited (formerly Comodo CA) |
| Validation | Domain Validation (DV) |
| Domains secured | 1, with and without www |
| Issuance | About 5 minutes after validation |
| Validation methods | DNS (CNAME), HTTP file, or email to admin@, administrator@, webmaster@, hostmaster@, or postmaster@ |
| Certificate validity | Up to 199 days per certificate |
| Plan terms | 1, 2, or 3 years |
| Warranty | $50,000 relying-party warranty ($5,000 per transaction) |
| Key types | RSA 2048-bit or higher, or ECC P-256/P-384 |
| Signature hash | SHA-256 (SHA-2) |
| Encryption | Up to 256-bit |
| Server licenses | Unlimited |
| Reissues | Unlimited and free for your whole plan |
| Site seal | PositiveSSL TrustLogo |
| Browser trust | Sectigo R46 and E46 roots, included in the Mozilla, Apple, Microsoft, and Chrome root stores |
| Refund | 25-day money-back guarantee |
PositiveSSL Features
TLS encryption is up to 256-bit, negotiated by your server and the visitor’s browser, the same as on pricier certificates. Higher validation levels add identity checks, not stronger encryption. Browsers load your site without a “Not secure” warning, and many show a padlock.
The $50,000 warranty protects people who rely on your certificate. If Sectigo issues a certificate in error and they lose money on an online card or bank payment, it pays up to $5,000 per transaction and $50,000 in total.
Install the certificate on as many servers as you need, and reissue it free if you change your private key or move hosts. Show the PositiveSSL TrustLogo site seal in your footer or near a login or checkout form.
At $7.66/yr, it’s the cheapest Sectigo SSL certificate at SSL Dragon. Compare all single-domain SSL certificates.
Which PositiveSSL Certificate Do You Need?
PositiveSSL fits personal websites and blogs, portfolios, small business and informational sites, startup landing pages, and public staging sites. It encrypts what visitors type into contact forms and logins, without proving who runs the site.
For more domains, subdomains, or your company name in the certificate, pick another type. SSL Dragon sells six PositiveSSL certificates, all issued by Sectigo. The Extended Validation (EV) types verify your company first, which takes 1-3 days.
| Certificate | Covers | Validation | From |
|---|---|---|---|
| PositiveSSL (this page) | 1 domain, with and without www | DV | $7.66/yr |
| PositiveSSL Multi-Domain | 3 domains included (SANs), up to 250 | DV | $21.66/yr |
| PositiveSSL Wildcard | 1 domain and its first-level subdomains, such as blog.yoursite.com | DV | $56.33/yr |
| PositiveSSL Multi-Domain Wildcard | Several domains and their first-level subdomains | DV | $156.33/yr |
| PositiveSSL EV | 1 domain, with your verified company details | EV | $75/yr |
| PositiveSSL EV Multi-Domain | Several domains, with your verified company details | EV | $136.66/yr |
Outside the PositiveSSL range:
- Organization Validation (OV) certificates also show your company name, as many ecommerce stores and financial firms want, and take 1-3 days.
- IP address certificates cover a public IP. PositiveSSL can’t cover an IP address or an internal name such as server.local.
- For EssentialSSL, read PositiveSSL vs. EssentialSSL compared.
Comodo PositiveSSL Is Now Sectigo PositiveSSL
The Comodo PositiveSSL certificate is now sold as Sectigo PositiveSSL. It’s the same product, with the same domain validation and one-domain coverage. Francisco Partners bought a majority stake in Comodo CA, the certificate authority behind it, in 2017, and the company was renamed Sectigo on November 1, 2018. That’s why some stores still list Comodo Positive SSL while others say Sectigo Positive SSL.
The certificate chain has changed twice since the rename. Since January 2019, certificates have come from Sectigo-named issuing CAs, and since June 2025 they chain to Sectigo’s newer R46 and E46 roots.
PositiveSSL® is a registered trademark of Sectigo Limited.
How Multi-Year PositiveSSL Plans Work
A 1-, 2-, or 3-year PositiveSSL plan works like a subscription. It covers the whole term, but each certificate in it lasts up to 199 days, Sectigo’s limit since March 2026 under the industry’s 200-day maximum. Under CA/Browser Forum ballot SC-081v3, that maximum falls to 100 days on March 15, 2027, and 47 days on March 15, 2029.
Reissues are free for the whole plan. Before a certificate expires, reissue it from your account and install the new one. Expect to validate the domain again for most reissues, because Sectigo reuses a domain check for no more than 198 days. The industry limit for that falls to 100 days in March 2027 and 10 days in March 2029.
To skip manual reissues, use automated SSL with ACME, a separate Sectigo product from $25/yr. When your plan ends, renew it to keep getting certificates.
| Plan bought now | Certificates over the plan |
|---|---|
| 1 year | About 3 |
| 2 years | About 7 |
| 3 years | About 13 |
Counts assume you reissue at each expiry, under the limits above.
How to Get Your PositiveSSL Certificate
There’s no paperwork. You only prove that you control the domain.
- Choose 1, 2, or 3 years at the top of this page and check out.
- Create a Certificate Signing Request (CSR) with the CSR Generator, or follow the CSR guides for your server.
- Validate the domain with a DNS CNAME record, an HTTP file in /.well-known/pki-validation/, or email validation through admin@, administrator@, webmaster@, hostmaster@, or postmaster@ at your domain. Prefer DNS or HTTP, because email validation ends on March 15, 2028.
- Download the certificate and its CA bundle from your account.
- Install both with the install guides, then test the site with the SSL Checker. Use the full CA bundle that came with this certificate, not one saved from an older certificate.
If validation fails, check these settings:
- CAA records, if you use them, need sectigo.com. Sectigo is phasing out the old comodoca.com entry.
- Firewalls shouldn’t geo-block validation traffic, because Sectigo checks domains from several network locations.
- If DNSSEC is on, make sure it validates. A broken setup blocks issuance.
PositiveSSL FAQ
What is a PositiveSSL certificate?
PositiveSSL is Sectigo’s entry-level SSL/TLS certificate. It uses domain validation, so Sectigo confirms that you control the domain but doesn’t check who you are. Other PositiveSSL types add subdomains, more domains, or company verification.
Is Comodo PositiveSSL the same as Sectigo PositiveSSL?
Yes. Comodo CA became Sectigo in 2018, and Comodo PositiveSSL became Sectigo PositiveSSL with the same validation and coverage. Every PositiveSSL certificate sold today is issued by Sectigo, whichever name a store uses, and current browsers trust it.
How much does PositiveSSL cost?
At SSL Dragon, PositiveSSL costs $9 for 1 year, $16 for 2 years, or $23 for 3 years. The 3-year plan is the cheapest way to buy it, at $7.66/yr. These prices also apply to Comodo PositiveSSL, the same certificate under its former name. Every plan includes a 25-day money-back guarantee.
What does PositiveSSL secure?
One domain name in both forms, such as yoursite.com and www.yoursite.com, or a single subdomain such as blog.yoursite.com. It doesn’t cover several subdomains or a second domain. For those, choose PositiveSSL Wildcard or PositiveSSL Multi-Domain.
How fast is PositiveSSL issued, and how do I download it?
About 5 minutes after you complete domain validation. Then download the certificate and its CA bundle from your SSL Dragon account and install both on your server. If issuance takes longer, check that your DNS record or validation file is in place.
Is SSL being phased out?
Not SSL certificates. The SSL protocol was retired in favor of TLS years ago, but the certificates kept the old name, and every HTTPS site still needs one. Their lifetimes are getting shorter, though, from up to 199 days today to 100 days in March 2027 and 47 days in March 2029.
Can I still buy or renew PositiveSSL?
Yes. Sectigo still issues PositiveSSL, and you can buy or renew it on this page. If your current provider has moved to another certificate brand, you can switch. Order a plan here, validate your domain, and install the new certificate before the old one expires.
Is Sectigo a trusted certificate authority?
Sectigo’s root certificates are in the Mozilla, Apple, Microsoft, and Chrome root stores, so current desktop and mobile browsers trust PositiveSSL. Since June 2025, new certificates chain to Sectigo’s R46 and E46 roots, and Sectigo’s CA bundle adds cross-signed certificates for older devices. If a device still shows an error, the SSL error tutorials explain the fixes.
Why pay for PositiveSSL when free certificates exist?
Free certificates encrypt traffic just as well, but they’re built for automation. Let’s Encrypt certificates last 90 days, dropping to 64 days on February 10, 2027, and 45 days on February 16, 2028. PositiveSSL certificates last longer between reissues and come with a $50,000 warranty, a site seal, and SSL Dragon support.





