Ordering DV Certificates - Draft
This documentation uses the term TLS (Transport Layer Security) rather than SSL (Secure Sockets Layer). While the terms "SSL" and "TLS" are often used interchangeably within the industry, SSL is a deprecated and insecure predecessor to TLS and should not be used when referring to modern secure communication protocols.
Although public-trust TLS certificates may technically support legacy SSL-compatible deployments, eMudhra strongly advocates the use of current, secure TLS protocols and industry-recommended cryptographic standards. eMudhra certificates are designed and intended to enable secure authentication, data integrity, and privacy through supported versions of TLS, ensuring robust protection for internet communications.
What Is a DV SSL/TLS Certificate?
A Domain Validation (DV) certificate is the quickest and most affordable type of SSL/TLS certificate. The Certificate Authority (emSign) simply confirms that you control the domain name - it does not check who you are or what organization you represent.
When to use a DV certificate:
• Personal websites, blogs, or hobby sites
• Development or staging environments
• Short-term projects
• Any site where speed and low cost matter more than showing your organization name in the certificate
What a DV certificate does NOT provide:
• It does not verify your organization's identity
• Visitors cannot see your company name in the certificate - only your domain name is shown
The Four DV SSL Certificate Variants
DV certificates verify only that you control the domain being secured - no company identity check is required. This makes them fast to issue (often within minutes) and the most popular choice for websites, blogs, applications, and internal services. CERTInext offers four variants:
Variant
Best Used When...
DV SSL Certificate
You need to secure a single specific domain, such as www.mybusiness.com or shop.mybusiness.com.
DV Wildcard SSL Certificate
You need to secure your main domain and ALL its subdomains (*.mybusiness.com). One certificate covers mail, portal, api, shop - any subdomain you create now or in future.
DV UCC SSL Certificate (Multi-Domain)
You need to secure several completely different domains or subdomains under a single certificate, e.g., mybusiness.com, mybusiness.net, and shop.mybusiness.com.
DV Wildcard UCC SSL Certificate
You need to protect multiple wildcard domains together, e.g., *.mybusiness.com and *.mybusiness.net - ideal for organizations managing several brands or regions.
⚠️ IMPORTANT
A DV certificate proves only that you control the domain - it does NOT show your organization's name in the certificate. If your website needs to display a verified company name in the certificate details, you need an OV (Organization Validated) or EV (Extended Validation) certificate, available separately on CERTInext.
How to Use This Guide
The guide is divided into two phases that apply to all four variants:
• Phase 1 - Applying for the Certificate in CERTInext: A 6-step wizard you complete online.
• Phase 2 - Post-Submission: What Happens After You Pay: Actions you take via email and the emSign Subscriber Portal to validate your domain and download your certificate.
Where a step or field differs between variants, a clearly marked 'Variant Difference' section explains exactly what changes. Everything else is identical across all four variants.
📌 InCommon Note
If your institution is part of the InCommon Certificate Service (a programme for US universities and research institutions operated by Internet2), your CERTInext login and group assignment may be pre-configured by your IT administrator. The application steps in this guide are identical for InCommon users. Your subscription cost may be covered under your institutional InCommon agreement - certificates may appear at $0.00 or a flat negotiated rate. Check with your IT/PKI administrator before placing an order.
Before You Start - What You Will Need
Please gather the following before beginning your certificate application. Having these ready will allow you to complete the entire process in one session.
Field / Element
What It Is
What To Do
CERTInext Login
Your username and password for the CERTInext platform (certinext.io).
Log in before starting. If you do not have an account, contact your IT administrator or eMudhra support.
Your Domain Name
The website address you want to secure.
• DV SSL: e.g., www.mybusiness.com
• DV Wildcard SSL: e.g., *.mybusiness.com
• DV UCC SSL: e.g., mybusiness.com + mybusiness.net
• DV Wildcard UCC SSL: e.g., *.mybusiness.com + *.mybusiness.net
Write this down before starting. Make sure it exactly matches what your web server uses.
CSR File
A Certificate Signing Request - a block of encoded text generated by your web server or IT team. It contains your domain name and a public key that the CA uses to create your certificate.
If you do not have a CSR, ask your IT team or hosting provider to generate one. Alternatively, you can skip CSR at application time and provide it later. See Step 2 for full guidance.
DNS or Server Access
After paying, you must prove you control your domain - either by adding a TXT record to your DNS settings or uploading a small file to your web server.
Contact your DNS provider (e.g., GoDaddy, Cloudflare) or your IT administrator. For Wildcard variants, DNS TXT record is the only recommended method.
Payment Method
Either a CERTInext credit balance (pre-loaded by your organization) or a credit/debit card for online payment.
Confirm with your accounts or IT team which method to use.
Overview - The Complete Certificate Journey
Ordering any DV SSL certificate on CERTInext follows the same two-phase journey:
Phase / Step
What Happens
PHASE 1 - In CERTInext
Step 1: Choose Product & Validity
Select which DV variant you want and how long you need it to be valid (1, 2, or 3 years).
Step 2: Certificate Signing Request (CSR)
Upload, paste, or skip your CSR file.
Step 3: Requestor Information
Confirm your name, email, and contact number as the person placing this order.
Step 4: Certificate Information
Enter the domain name(s) the certificate will protect.
Step 5: Additional Information (Optional)
Set tags, auto-renewal preferences, and extra notification recipients.
Step 6: Order Summary & Payment
Review all details and pay. Your order is submitted.
PHASE 2 - Via Email & emSign Portal
Order Confirmed
You receive an email with a Track Order link.
Domain Verification
In the emSign Subscriber Portal, prove you control your domain (required for all DV certificates).
Administrator Approval
Your CERTInext account Administrator reviews and approves the order (enterprise accounts).
Certificate Issued
emSign issues the certificate.
Download & Install
Download the certificate file and install it on your web server.
📌 NOTE
The entire process - from application to having the certificate installed on your server - typically takes 15–60 minutes for DV certificates, provided you have DNS access ready. DNS changes may take up to 30 minutes to propagate.
PHASE 1 - APPLYING FOR THE CERTIFICATE IN CERTInext
Step 1 - Choose Product & Validity
Click on the 'New Certificate' button at left top corner of Navigation menu. This is the first screen of the certificate application wizard. It is where you tell CERTInext which type of certificate you want and for how long.
How to Get Here
1. Log in to CERTInext (certinext.io).
2. Click the NEW CERTIFICATE button in the dark sidebar on the left.
3. The screen titled 'Certificates :: New Request' opens.
4. The left panel shows all 6 steps. You begin at Step 1: Choose Product & Validity.

Fields on This Screen
Field / Element
What It Is
What To Do
Group
The account and organization in CERTInext that will own this certificate and be billed for it.
Pre-filled automatically. Confirm it shows your correct organization name. You cannot change this field.
CA Source
The Certificate Authority (CA) that will issue your certificate.
Select emSign from the dropdown. emSign is the CA powered by eMudhra.
Certificate Type
The broad category of certificate.
Select SSL/TLS Certificates from the dropdown.
Product
The specific certificate variant you want.
See the Variant Differences table below - select the product that matches your need.
Subscription For
How long the certificate will be valid. Three radio button options are shown.
Select 1 Year, 2 Years, or 3 Years. Most users choose 1 Year. Note: CA/Browser Forum rules require maximum 1 year for publicly trusted certificates - if you choose 2 or 3 years, you will need to reissue each year, but your billing covers the full period.
No. of Domains (UCC variants only)
Appears only for UCC and Wildcard UCC products. Sets how many domains the certificate will protect.
Select the number of domains you need. The base price covers up to 4 domains. Each additional domain beyond 4 costs $12 extra. Plan ahead - you can add SANs at ordering time.
Cost
The price, calculated automatically based on your selections.
Review the displayed amount in USD. Tax (if applicable) is added at checkout on the Order Summary page.
Variant Differences - What to Select as 'Product'
Your Situation
Select This Product
Securing one specific domain only (e.g., www.mybusiness.com)
DV SSL Certificate
Securing all subdomains of one domain (e.g., *.mybusiness.com)
DV SSL Certificate Wildcard
Securing multiple different domains in one certificate
DV SSL Certificate UCC
Securing multiple wildcard domains in one certificate
DV SSL Certificate Wildcard UCC
The Blue Information Box
When you select any DV product, a blue information panel appears at the bottom of the screen. It summarises what the product covers. Key details shown for all DV variants:
• Domain Validation - automated and fast (no company identity check required)
• Fully Automated & Instant Approval - issuance typically within minutes
• Unlimited Server Licences - install on as many servers as you need
• Strongest SHA2 & ECC Encryption supported
• Major Browser & Mobile Device Compatibility
• Automatic renewal reminders and early renewal options
📌 InCommon Note
Under 'Subscription For', you will see the same 1/2/3 year options. InCommon institutional agreements typically issue DV certificates for 30 days / 90 days / 199 days at a time, in line with CA/Browser Forum rules. Even if your InCommon contract runs for multiple years, each individual certificate is issued for a maximum of 30 days / 90 days / 199 days respectively and must be renewed accordingly. The auto-renew feature (set in Step 5) handles this automatically.
When done, click the Next button at the bottom right.
Step 2 - Certificate Signing Request (CSR)
This screen is where you provide the CSR - a technical file from your web server that the Certificate Authority uses to create your certificate.

What Is a CSR?
A CSR (Certificate Signing Request) is a block of text generated by your web server. It contains your domain name (called the Common Name) and a public key. The CA reads this information to create your certificate. Your IT team, hosting provider, or server administrator can generate a CSR for you.
📌 NOTE
The public key and signature algorithm from your CSR are used for certificate generation. Subject details such as Organization, Country, and State are pre-filled from your CSR for convenience but can be edited on screen. The values you submit in the form will be the final values in the issued certificate - not necessarily what was in the CSR.
Variant Differences - CSR Requirements
Variant
CSR Common Name (CN) Format & Key Size
DV SSL Certificate
CN = yourdomain.com (e.g., www.mybusiness.com). Key size: 2048-bit RSA minimum.
DV Wildcard SSL Certificate
CN = *.yourdomain.com - the asterisk and dot are REQUIRED (e.g., *.mybusiness.com). Key size: 4096-bit RSA recommended for stronger security.
DV UCC SSL Certificate
CN = your primary domain (e.g., mybusiness.com). Additional domains are added as Subject Alternative Names (SANs). Key size: 2048-bit RSA minimum.
DV Wildcard UCC SSL Certificate
CN = your primary wildcard domain (e.g., *.mybusiness.com). Additional wildcard domains are SANs. Key size: 4096-bit RSA recommended.
⚠️ IMPORTANT
Wildcard certificates MUST have the asterisk in the Common Name: *.yourdomain.com - NOT yourdomain.com. A CSR generated without the asterisk will NOT work for a Wildcard certificate and the order will be rejected by the CA.
If your CSR was generated for the wrong domain, ask your IT team to generate a new CSR with the correct Common Name before proceeding.
Your Three Options on This Screen
Option A - Upload CSR File
1. Click the Choose File button next to 'Upload CSR'.
2. A file browser opens. Navigate to your .csr or .pem file on your computer.
3. Select the file. The filename appears next to the button once selected.
Option B - Paste CSR Text
4. Open your CSR file in any text editor (Notepad on Windows, TextEdit on Mac).
5. Copy the entire block - starting with -----BEGIN CERTIFICATE REQUEST----- and ending with -----END CERTIFICATE REQUEST-----, including those header and footer lines.
6. Paste the copied text into the 'Paste CSR' text box on screen.
Option C - Skip CSR
7. Tick the 'Skip CSR' checkbox at the top of the screen.
8. You can complete the order and pay now, then provide the CSR later.
9. Use this if your IT team has not generated the CSR yet but you need to start the order.
💡 TIP
If you use a shared hosting service such as cPanel or Plesk: Log in to your hosting control panel, go to SSL/TLS settings, and generate a CSR from there. For standard DV SSL, enter your domain as the Common Name. For Wildcard variants, enter *.yourdomain.com with the asterisk. Copy the CSR text from your hosting panel and paste it into the Paste CSR box on this screen.
Click Back to go back, or Next to proceed.
Step 3 - Certificate Requestor Information
This screen captures the details of the person placing this certificate order. This is the same for all four DV variants.

Fields on This Screen
Field / Element
What It Is
What To Do
Name * (Required)
Your full name as the person requesting this certificate - the person placing the order, not necessarily the person who will install it.
Pre-filled from your CERTInext account profile. Verify it is your correct full name. Do not use initials or a nickname.
Requestor Email ID * (Required)
The email address that will receive ALL notifications about this order - order confirmation, domain validation requests, and the certificate download notification. This is the most important field on this screen.
Pre-filled from your account. Make sure this is a monitored inbox - you will need to act on emails sent here promptly. Do not use a distribution list or a shared inbox that you cannot monitor.
Mobile Number
Your contact phone number, used for urgent notifications. The country code is selected from a dropdown (e.g., +1 for United States, +91 for India).
Pre-filled from your account. Update if your number has changed. For US users, select +1 United States.
CERTIFICATE DOWNLOAD DELEGATION
An optional section that lets you authorise a different person to download the certificate on your behalf. Useful when the person applying is different from the IT person who will install the certificate.
Only fill this in if someone else should handle the download. Otherwise, leave it blank.
Contact Name (Delegation - Optional)
Full name of the person you are delegating download access to, such as your server administrator.
Leave blank if you will download the certificate yourself.
Email ID (Delegation - Optional)
Email address of the delegated person. They will also receive the certificate issuance email and can download the certificate using the link in that email.
Leave blank if not needed.
💡 TIP
If you are applying on behalf of a client or colleague, enter your own details as the Requestor (so you receive all notifications). Use the Certificate Download Delegation fields to ensure the person who will actually install the certificate also receives the download email.
Click Back to go back, or Next to proceed.
Step 4 - Certificate Information
This screen is where you enter the domain name(s) that the certificate will protect. This step has significant differences between variants.

Screenshot: Step 4 - Certificate Information (DV SSL Certificate - single domain)

Screenshot: Step 4 - Certificate Information (DV Wildcard SSL Certificate - wildcard domain)

Screenshot: Step 4 - Certificate Information (DV UCC / Wildcard UCC - multiple domains)
Fields on This Screen - All Variants
Field / Element
What It Is
What To Do
Domain Name * (Required - all variants)
The primary domain name this certificate will secure. This is the web address typed into your visitors' browsers.
Type or select your domain. The exact format depends on your variant - see Variant Differences below. This must match the Common Name in your CSR.
Automatically secure 'www' variant (DV SSL & DV UCC only - checkbox)
When ticked, the certificate also covers the www version of your primary domain. For example, if you enter mybusiness.com, the certificate automatically also covers www.mybusiness.com at no extra cost.
This checkbox is ticked by default for DV SSL and DV UCC variants. Leave it ticked unless you specifically only need one version. Wildcard variants do NOT have this checkbox - they already cover www as a subdomain.
Additional Domain Names (UCC & Wildcard UCC variants only)
Fields to enter each additional domain or subdomain you want secured by this single certificate. Each domain gets its own text box.
Click the + button to add more domain fields. Enter each domain on a separate line. You can also use 'Import additional domain' to upload a CSV or text file listing multiple domains - useful when securing many domains at once.
Import Additional Domain (UCC & Wildcard UCC variants only)
Allows uploading a file (CSV or text) containing multiple domain names, saving time when you have many domains to add.
Click this option and select your file if you have more than 5–6 domains to add.
Clear (UCC & Wildcard UCC variants only)
Removes all additional domain names entered on this screen.
Use with caution - clicking this removes all your domain entries and cannot be undone without re-entering them.
Variant Differences - What to Enter as the Domain Name
Variant
Domain Format to Enter
DV SSL Certificate
Enter your specific domain name only - no asterisk. The www checkbox will handle both www and non-www if ticked.
DV Wildcard SSL Certificate
Enter the wildcard format: *.yourdomain.com - the asterisk (*) and dot (.) prefix are REQUIRED. Do not enter without the asterisk.
DV UCC SSL Certificate
Enter your primary domain in the Domain Name field, then add all additional domains in the Additional Domain Name fields below.
DV Wildcard UCC SSL Certificate
Enter your primary wildcard domain (*.yourdomain.com) in the Domain Name field, then add additional wildcard or standard domains below.
⚠️ IMPORTANT
Critical - The domain name entered here MUST match the Common Name (CN) in your CSR. If they do not match, the Certificate Authority will reject the request. If you are unsure what domain name was used in the CSR, check with your IT team before proceeding.
Example mismatch to avoid: If your CSR was generated for *.mybusiness.com but you enter mybusiness.com here (without the asterisk), the CA will reject it.
📌 NOTE
UCC Multi-Domain Rule: For DV UCC certificates, if you prove ownership of a base domain (e.g., mybusiness.com), all subdomains of that same base domain (e.g., mail.mybusiness.com, blog.mybusiness.com) will be validated automatically. However, completely different domains (e.g., anotherbusiness.com) each require separate domain verification. Validating a subdomain does NOT prove ownership of the parent domain.
Click Back to go back, or Next to proceed.
Step 5 - Additional Information (Optional)
This screen contains optional fields that help with managing and administering the certificate. None of these are required to get the certificate issued - but several are very useful and are recommended. This step is the same for all four DV variants.

Fields on This Screen
Field / Element
What It Is
What To Do
Tags (with + Add Tag button)
Labels you can attach to this certificate order for your own internal organization and searching. For example: 'Production', 'Finance', 'Web Server', 'Q1-2026', or a client name. Tags are for your reference only - the CA does not see them.
Click + Add Tag and type a label. You can add multiple tags. Recommended: add at least one tag to make this certificate easy to find later in the Orders list.
Order Remarks
A free-text field for internal notes about this order. Not visible to the CA - only for your reference.
Type any notes that will help you remember why this order was placed. Example: 'For new e-commerce checkout page, replacing expired cert'. Leave blank if not needed.
Technical Point of Contact Information (checkbox)
When ticked, expands to show fields for a technical contact person - typically your server administrator who manages the certificate. Different from the Requestor.
Tick and fill in if you want to record the IT person responsible for this certificate. Useful for enterprise accounts with multiple administrators. Leave unticked if not needed.
KYC Documents (checkbox)
When ticked, lets you upload identity or business verification documents. Some enterprise accounts or specific certificate types require these.
Tick only if you have been specifically asked to provide KYC documents. For standard DV certificates, this is usually NOT required.
Additional Email Recipients (checkbox)
When ticked, lets you add extra email addresses to receive all certificate notifications - order updates, domain validation prompts, and issuance alerts.
Tick and add email addresses if your manager, IT team, or a client also needs to receive notifications about this certificate.
Auto-renew Certificates Until Coverage (checkbox - ticked by default)
When ON, CERTInext automatically starts the renewal process before your certificate expires, so your website never goes unprotected with an expired certificate.
Leave this ON (it is ticked by default). Highly recommended for all users. Turning it off means you must manually remember to renew.
Set Renew Criteria: Before ___ Days of Expiry
Defines how many days before the certificate expires that the auto-renewal process will be triggered. Default is 15 days.
Leave at 15 days unless you have a specific reason to change it. Tip: Setting it to 30 days gives more time to resolve any renewal issues.
💡 TIP
Even though all fields on this screen are optional, it is good practice to: (1) add at least a Tag such as 'Production Web Server' or 'Wildcard - All Subdomains' to make the certificate easy to find later, and (2) leave Auto-renew turned ON to avoid your website showing a security warning due to an expired certificate.
📌 InCommon Note
The Auto-renew feature works the same way for InCommon certificates. Since InCommon DV certificates are issued for 30 days/ 90 days / 199 days at a time, auto-renewal will trigger 15 days (or your set number of days) before each expiry. Make sure your institutional InCommon agreement is still active at renewal time so the renewed certificate is also covered under the agreement.
Click Back to go back, or Next to proceed to the Order Summary.
Step 6 - Order Summary & Payment
This is the final screen before submitting your order. It shows a complete summary of everything you have entered, along with the payment breakdown. Review all details carefully before paying - once payment is made, changes require going through the order management tools.

📌 NOTE
An orange 'Payment Pending' badge appears in the top-right corner of this screen - this confirms the order has NOT yet been paid.
What Is Shown on This Screen
Product Information Section
Item
Value
Certificate Type
SSL/TLS Certificates
Product Name
The DV variant you selected (e.g., DV SSL Certificate, DV SSL Certificate Wildcard, etc.)
Validity Period
1 Year, 2 Years, or 3 Years - as selected in Step 1
Domain Count
Number of domains covered (1 for standard/Wildcard; your selected number for UCC variants)
Certificate Information Section
Shows the domain name(s) you entered in Step 4. Confirm these are correct before paying. For UCC variants, all additional domains are listed here.
Payment Information Section
Item
Description
Current Balance
Your account's pre-loaded credit balance in USD. This is your organization's available credit in CERTInext.
Certificate Price
Base price of the selected DV product in USD.
Additional SAN Cost
For UCC variants only: the charge for each domain beyond the base 4 included domains.
Grand Total
The total amount you will pay in USD (Certificate Price + any Additional SAN Cost). Tax is included if applicable.
The Subscriber Agreement Checkbox
⚠️ IMPORTANT
You MUST tick this checkbox before the payment buttons become active.
The checkbox text reads: 'The Subscriber/Requestor hereby agrees to have read, understood and agree to Subscriber Agreement of emSign.'
By ticking this, you are legally agreeing to the terms and conditions of the emSign Certificate Authority for issuing this certificate. Click the 'Subscriber Agreement' link in the text to read the full terms before ticking.
Payment Buttons
Field / Element
What It Is
What To Do
Save and Exit
Saves your order as a draft. No payment is made. Order status will show 'Payment Pending'. You can return later to complete payment.
Use this if you are not ready to pay but want to save your progress.
Pay Online
Opens a payment gateway. Pay using a debit card, credit card, or net banking/bank transfer. Amount is debited immediately.
Use this if your organization does not have a pre-loaded credit balance.
Use Credit
Instantly deducts the Grand Total from your organization's pre-loaded CERTInext credit balance. No card details required. Most common option for enterprise accounts.
Use this if your organization has credits loaded. Click this after ticking the Subscriber Agreement.
📌 InCommon Note
If your InCommon certificate is included under an institutional subscription, the cost shown may be $0.00 or a nominal flat rate. Click Use Credit to proceed. If the cost appears unexpectedly high, contact your IT administrator before paying - the pricing configuration may need to be verified with your InCommon account manager.
📌 NOTE
Once you click Use Credit or Pay Online and payment is processed, your order is submitted. You will be taken to the Order Confirmation screen and will receive a confirmation email. Do not close the browser immediately - wait for the confirmation screen to load.
PHASE 2 - POST-SUBMISSION: WHAT HAPPENS AFTER YOU PAY
Immediately After Payment - The Order View Screen
The 'Certificates :: Orders > View Order' page opens automatically after payment. This page is your central reference for tracking the certificate order within CERTInext.

The Order Header Bar
At the very top of the page, a summary bar shows the key details of your order:
Field / Element
What It Is
What To Do
Order ID
A unique number for your order (e.g., 1184216685). Record this number - you will need it for any support queries and to find your order later.
Write this down or take a screenshot of this page.
Ordered Date
The date and time your order was placed.
Confirms your order was submitted.
Product
The DV variant you ordered.
Confirm this matches what you intended.
Group
Your organization's account name.
Confirms billing account.
CA Source
The issuing CA: emSign.
Confirm this shows emSign.
Certificate Price
The total amount charged in USD.
Matches the Grand Total from Step 6.
Order Status
Shows 'Order Accepted' in an orange badge - this means payment was received and the order is in the system, but it still needs internal approval within your CERTInext account before proceeding to the CA.
No action needed from you for this status.
Certificate Status
Shows 'Pending for Approver' in an orange badge - your organization's CERTInext account administrator must review and approve the order before emSign begins processing it.
If you are the Administrator, approve it using the 3-dot menu. If not, contact your IT department.
⚠️ IMPORTANT
Pending for Approver: In enterprise CERTInext accounts, every new certificate order must be approved by an Account Administrator before it is forwarded to emSign. If you are the Administrator, you can approve it from this page by clicking an approve button at the bottom. If you are not the Administrator, contact your IT department or CERTInext account manager and ask them to approve the order, quoting your Order ID.
What the Rest of the Order View Page Shows
Section
What It Shows at This Stage
SSL Subscription Information
Subscription For: 1 year (or your selected period). Subscription Start/End Date: shown as dashes - will fill in once the certificate is issued. Subscription Status: Pending (orange).
Auto-Renewal Configuration
Confirms auto-renew is set to Yes, triggering the number of days before expiry you set in Step 5.
Certificate Information
Shows your domain name(s) as entered in Step 4.
Certificate Requestor Information
Confirms your Name and Email from Step 3.
CSR Information
CN (Common Name): your domain. Key Size: 2048 (DV SSL/UCC) or 4096 (Wildcard variants). Key Algorithm: RSA.
Ordered By
Shows the name and role of the user who placed the order.
Renewal Notifications
Send email notifications: Yes - you will receive reminder emails before the certificate expires.
Reissue History
Shows 'No records found' - as expected for a brand-new order.
📌 NOTE
The 3-dot menu in the top-right corner gives Administrators access to: Track Order (generate public tracking URL), Download Invoice, Replace CSR, Recall Request, Cancel Order, and - once issued - Download Certificate and Reissue Certificate.
Email 1 - Order Confirmation: 'Your Order is Successful'
Shortly after payment, you receive an email at the Requestor Email ID you provided in Step 3.

Email Detail
Value
Subject Line
ORDER #[your order ID] - Your Order is Successful
Greeting
Dear [Your Name], Your order is placed successfully.
Order ID
Your unique order number - save this.
Ordered Date
Date and time of the order in UTC.
Product & Validity
The DV variant and duration you selected.
Identifier
Your domain name (or primary domain for UCC variants).
Subscription For
1 Year (or your selected period).
Track Order Button
The orange button in the email. Clicking it opens the emSign Subscriber Portal - where you complete domain verification and download your certificate.
⚠️ IMPORTANT
Do not ignore this email. The Track Order link is how you complete the domain validation step. Without completing domain validation, your certificate cannot be issued.
💡 TIP
Check your spam or junk folder if you do not see this email within a few minutes of payment. The email is sent from the emSign / eMudhra domain. Add the sender to your safe senders list to avoid future emails going to spam.
If you provided a Certificate Download Delegation email address in Step 3, that person will also receive a copy of relevant notifications.
The emSign Subscriber Portal - Your Order Tracking Hub
Clicking the Track Order button in the confirmation email opens the emSign Subscriber Portal - a separate, public-facing web page that guides you through the remaining steps to get your certificate issued. You do not need to log in to CERTInext to access this page.

Page Header
The page displays: 'Hello [Your Name], Please follow the instructions and complete the below verification steps to speed up your certificate issuance process.'
The Four Order Actions
This page shows four steps in the Order Actions section. Steps 1 and 2 are automatically completed when you paid:
Order Action
Status at This Stage
1. Submit CSR
Completed (green tick) - automatically done when you submitted your CSR in Step 2.
2. Subscriber Agreement
Completed (green tick) - automatically confirmed when you ticked the agreement in Step 6.
3. Domain Verification
Awaiting Customer Action (orange) - YOU must complete this step.
4. Certificate Download
Issuance Pending (orange) - becomes available once Step 3 is completed.
The Order Details Sidebar (Right Side of the Page)
Detail
Value
Date Ordered
Date you placed the order.
Order ID
Your unique reference number.
Product & Validity
Your DV variant and duration.
Domain Name
The domain (or primary domain) being secured.
Order Status
Order Accepted.
Certificate Status
Pending for Approver - awaiting Administrator approval in CERTInext.
📌 InCommon Note
The emSign Subscriber Portal is the same for all users, including InCommon members. Domain verification is required for ALL DV certificates regardless of your InCommon membership - you must always prove domain control.
You can always return to this page by clicking the Track Order button in the confirmation email, or by generating the tracking URL from within CERTInext using the 3-dot menu on your order.
Completing Domain Verification (Step 3 on the emSign Portal)
Domain verification is the most important step after payment. The Certificate Authority must confirm that you control the domain before it can issue the certificate. This section explains how to complete it.

What You See When You Expand Domain Verification
Click on the '3. Domain Verification' row (or the + expand icon on the left). The section expands to show:
• Total Domains: the number of domains that need to be verified (1 for DV SSL and Wildcard; your selected count for UCC variants).
• Under Domain Control Validation (DCV): your domain name(s) listed, each with a Verify button and a CAA button.
• The CAA button is for advanced DNS checks - typically for IT teams only. Use the Verify button.
How to Start - Click the Verify Button
Click the orange Verify button next to your domain name. A popup window titled 'Domain Control Validation ([your domain]) - #[Order ID]' opens.
⚠️ IMPORTANT
Note shown in the popup: 'This is technical in nature (if you are not the right person, please contact your IT / Domain administrator).'
If you are not the person who manages your domain's DNS settings or web server, stop here. Copy the portal URL from your browser address bar and forward it to your IT or domain administrator. Ask them to complete the domain verification step on your behalf.
Choosing a Domain Control Validation (DCV) Method
The popup shows a DCV Method dropdown. Two methods are available:
Method 1 - DNS TXT Record (Most Preferred - Recommended for All Variants)
This method proves you control the domain by adding a special text record to your domain's DNS settings. It is recommended for all DV variants and is the only suitable method for Wildcard certificates.

Select 'DNS TXT Record (Most Preferred)' from the DCV Method dropdown. The popup shows a table with the record to add:
Record Detail
What It Contains
Record Type
TXT
Host
Your domain name (or a specific validation subdomain). Use the Copy button to copy the exact value.
Value
A unique alphanumeric token generated for your order (e.g., 5A27BFFF4R95F80945F8D5491A8FFC98). Use the Copy button - even a single character difference will cause verification to fail.
Step-by-Step Instructions for DNS TXT Record
1. Log in to your domain registrar or DNS provider (e.g., GoDaddy, Cloudflare, Namecheap, Google Domains, AWS Route 53).
2. Navigate to the DNS Management section for your domain.
3. Add a new TXT record:
• Host/Name: Paste the Host value copied from the popup.
• Value/Content: Paste the long alphanumeric token copied from the popup.
• TTL: Set to the minimum available (e.g., 300 seconds / 5 minutes) for fastest propagation.
4. Save the DNS record.
5. Wait 5–30 minutes for the DNS record to propagate. In rare cases, propagation can take up to 48 hours.
6. Return to the DCV popup in the emSign Subscriber Portal and click the orange 'Verify Now' button.
7. If successful, a green confirmation popup appears.
💡 TIP
You can check if your DNS record has propagated using a free tool such as dnschecker.org - search for your domain and the TXT record type. Once the value appears worldwide, click Verify Now.
Method 2 - HTTP/HTTPS File-Based Validation (For DV SSL and DV UCC Only)
This method proves domain control by uploading a small text file to your web server at a specific URL. The CA then checks that the file exists and contains the correct token.
⚠️ IMPORTANT
File-based validation is NOT suitable for Wildcard certificates (DV Wildcard SSL and DV Wildcard UCC). For Wildcard domains, use the DNS TXT Record method only.
Note shown in the popup: 'File-based (HTTP/HTTPS URL) DCV method can only be used to prove domain ownership over Fully Qualified Domain Names (FQDNs), exactly as named.'

The popup shows:
File Detail
What It Contains
File Name
A specific filename (e.g., 084984170207f94FB0482A1A70BF9A82.txt). Use the Copy button.
File Content
A unique token string (e.g., 30924A299885503882D10144825CD4F5). Use the Copy button.
Download File link
Click this to download the ready-made .txt file - saves you creating it manually.
Full path
The exact URL where the file must be accessible (e.g., http://yourdomain.com/.well-known/pki-validation/filename.txt).
Step-by-Step Instructions for File-Based Validation
1. Click 'Download file' in the popup to download the ready-made file.
2. Upload the file to your web server at exactly this path: http://[yourdomain.com]/.well-known/pki-validation/[filename].txt
3. Do not change the filename or its contents.
4. Verify the file is accessible: open the URL in a browser. If you see the token text displayed or the file downloads, it is accessible. A 404 error means the file is not in the right location.
5. Once the file is accessible at the correct URL, click 'Verify Now' in the popup.
💡 TIP
To upload the file, use: your hosting control panel's File Manager (cPanel, Plesk), an FTP client such as FileZilla, or ask your hosting provider to upload it for you.
Variant Differences - Domain Verification
Variant
DCV Method
DV SSL Certificate
DNS TXT Record (recommended) or HTTP/HTTPS File-Based
DV Wildcard SSL Certificate
DNS TXT Record ONLY
DV UCC SSL Certificate
DNS TXT Record (recommended) or HTTP/HTTPS File-Based
DV Wildcard UCC SSL Certificate
DNS TXT Record ONLY for each wildcard domain
📌 InCommon Note
The DNS TXT Record method is recommended for all InCommon institutional certificates. If your domain DNS is managed by your institution's IT department, provide them with the Host and Value shown in the popup and ask them to add the TXT record. For UCC variants with multiple domains from different departments, each domain administrator may need to be contacted separately.
After Domain Verification Succeeds
Once you click Verify Now and the CA confirms your domain control, a green success popup appears:
📌 NOTE
Thank you for proving the domain ownership for [your domain]. Domain Verification is completed successfully. Please track your order and complete your pending actions to speed up the certificate issuance process.
Click OK. The Order Actions list updates - Domain Verification now shows a green Completed status. Steps 1, 2, and 3 will all show green.
⚠️ IMPORTANT
Reminder about Administrator Approval: Even after domain verification is complete, the certificate will NOT be issued until the CERTInext account Administrator approves the order. If the Certificate Status stays on 'Pending for Approver' for a long time after domain verification, contact your IT department and ask them to approve the order in CERTInext.
Certificate Issued - Step 4 Becomes Available
Once both domain verification is complete AND the Administrator has approved the order, emSign issues the certificate. The Order Actions list on the emSign Subscriber Portal updates to show all four steps as Completed (green), and Step 4 - Certificate Download becomes active.

The Order Details sidebar on the right updates to show:
• Order Status: Order Accepted (orange - this is normal at this stage)
• Certificate Status: Certificate Generated (green) - this is the key status confirming your certificate exists and is ready to download
Downloading the Certificate
You can download the issued certificate in two ways: via the emSign Subscriber Portal (Step 4) or directly from CERTInext. Both methods give you the same certificate files.
Method A - Download via the emSign Subscriber Portal

Expanding the '4. Certificate Download' row shows a green 'Certificate Issued' badge and the following message:
📌 NOTE
Your certificate has been issued and ready for download. An email containing certificate download instructions has been sent to your email address. If you have not received an email, please click Resend Email to resend it. Your certificate is based on the CSR submitted by you. Please ensure to import / use the certificate against the same key-pair from where the CSR was generated.
Button
What It Does
Resend Email
Resends the certificate download notification email to your registered email address. Use this if you did not receive Email 2.
Download Certificate
Directly downloads the certificate from this page - without needing the email link.
Method B - Email 2: 'Your Certificate is ready for download'
A second email arrives at your Requestor Email ID (and delegated email, if set).

Email Detail
Value
Subject Line
ORDER #[your order ID] - Your Certificate is ready for download
Download Certificate button
Orange button - click to go directly to the certificate download page.
Download URL
A URL you can copy and paste into your browser if the button does not work.
💡 TIP
Save this email. The download link allows you to access the certificate directly at any time. If you miss it, use the Resend Email button in the emSign Subscriber Portal, or download directly from CERTInext via the 3-dot menu on your order.
Choosing the Download Format
Clicking the Download Certificate button (from the email or the emSign portal) takes you to the emSign download page. Click the orange Download Certificate button on that page. A popup titled 'Select the Format to download' appears with four options:

Field / Element
What It Is
What To Do
DER Encoded Binary X.509 (.CER)
A binary (machine-readable) format. The file is not human-readable text.
Java applications, some enterprise systems, older Microsoft environments.
Base-64 Encoded X.509 (.CER)
A text-based format with a .CER file extension. Human-readable text containing the certificate.
Windows systems, IIS (Internet Information Services) web server.
Base-64 Encoded X.509 (.CRT)
A text-based format with a .CRT file extension. Same content as .CER - just a different file extension recognised by Linux servers.
Apache, Nginx, and other Linux-based web servers. The most commonly used format.
Zip (Recommended if Unsure)
A compressed ZIP archive containing multiple certificate files: your server certificate, the intermediate CA chain certificate, and the root CA certificate.
When you need all certificate files in one download. Recommended if you are unsure which format to choose.
💡 TIP
Which format should I choose?
- Apache or Nginx (Linux): choose Base-64 encoded X.509 (.CRT)
- Windows IIS or Microsoft environments: choose Base-64 encoded X.509 (.CER)
- cPanel or Plesk (shared hosting): choose Base-64 encoded X.509 (.CRT)
- If you are unsure: choose Zip - it contains everything and you can use whichever file you need
⚠️ IMPORTANT
Your certificate file does NOT contain your private key. Your private key was created on your server when you generated the CSR - it never left your server. The certificate file and the private key must BOTH be present on your server to enable HTTPS. Never share your private key with anyone.
Wildcard and Wildcard UCC certificates: if you install the certificate on multiple servers (e.g., web server, mail server, API server), each server needs a copy of both the certificate file AND the matching private key.
Method C - Download Directly from CERTInext
1. Log in to CERTInext.
2. Go to Certificates > Orders in the left sidebar.
3. Find your certificate order in the list (Certificate Status should show 'Certificate Generated' in green).
4. Click View to open the order details.
5. Click the 3-dot menu in the top-right corner.
6. Select 'Download Certificate' from the menu.
📌 NOTE
The 3-dot menu also shows 'Reissue Certificate' - this allows you to reissue the certificate (for example, if you need to provide a new CSR due to a key compromise) within the same validity period. The reissued certificate will have the same expiry date as the original. Contact your administrator before reissuing.
Final Order Status - The Order is Complete
After you download the certificate, return to CERTInext and check Certificates > Orders. Click View on your order. The status has now fully updated.
Status Field
Final Value
Order Status
Order Fulfilled (green badge)
Certificate Status
Certificate Downloaded (green badge)
Subscription Start Date
The date and time the certificate was issued (e.g., 27 May 2026, 10:30 UTC)
Subscription End Date
Exactly 1 year later (e.g., 27 May 2027, 10:30 UTC) - or the end of your selected validity period
Subscription Status
Active (green)
Issuer CA Information - Root CA
emSign QA SSL RSA CA - G1 (or similar emSign root CA name)
CA Type
Public
📌 NOTE
These details confirm your certificate was successfully issued by emSign and is now active. Your website is ready to be secured with HTTPS once the certificate is installed on your server.
Last updated
