For the complete documentation index, see llms.txt. This page is also available as Markdown.

Step 5 - Additional Information (Optional)

This screen contains optional fields that help with managing and administering the certificate. None of these are required to get the certificate issued - but several are very useful and are recommended. This step is the same for all four DV variants.

Fields on This Screen

Tags (with “+ Add Tag” Button)

  • Tags are labels that help categorize and organize certificate orders for easier tracking and reporting.

  • Common examples include:

    • Project Name (e.g., "ProdApp")

    • Environment (e.g., "Production", "UAT", "Development")

    • Server Name

    • Department or Business Unit

    • Cost Center

  • Tags are used internally within CERTInext and are not included in the certificate itself.

  • Click + Add Tag to create a new tag.

  • Multiple tags can be added to a single order.

  • Using tags is highly recommended to simplify searching, filtering, and reporting.

Order Remarks

  • Allows you to add internal notes related to the certificate request.

  • Remarks are visible only within CERTInext and are not included in the certificate.

  • Useful for recording:

    • Business justification

    • Change request numbers

    • Ticket references

    • Renewal notes

    • Deployment instructions

  • Example:

    • "Replacing certificate for production web server."

    • "Renewal of expiring VPN certificate."

  • Leave blank if no additional comments are required.

Technical Point of Contact (Technical POC)

  • Allows you to specify the individual responsible for the technical management of the certificate.

  • Typically used to identify:

    • Server administrators

    • Infrastructure teams

    • Network administrators

    • Application owners

  • The Technical POC may be different from the requestor who submits the order.

  • Enable this option if technical ownership needs to be formally recorded.

  • Particularly useful in enterprise environments with multiple teams and administrators.

  • Leave disabled if not required.

KYC Documents (Optional)

  • Allows supporting identity or business verification documents to be uploaded.

  • Some certificate types or account configurations may require document verification.

  • Typical examples include:

    • Business registration documents

    • Organization verification documents

    • Government-issued identification

  • For most standard DV SSL/TLS certificates, KYC documents are not required.

  • Upload documents only when specifically requested during the certificate validation process.

Additional Email Recipients

  • Allows additional stakeholders to receive certificate-related notifications.

  • Useful when multiple people need visibility into the certificate lifecycle.

  • Typical recipients include:

    • IT Administrators

    • Security Teams

    • Application Owners

    • Operations Teams

    • Project Managers

  • These recipients can receive notifications such as:

    • Order confirmations

    • Domain validation requests

    • Certificate issuance alerts

    • Renewal reminders

    • Revocation notifications

  • Enable the option and enter the required email addresses.

Auto-Renew Certificates Until Coverage (Enabled by Default)

  • Automatically renews and reissues certificates throughout the selected subscription coverage period.

  • Helps ensure certificates do not expire unexpectedly.

  • Recommended for most production environments.

  • When enabled:

    • CERTInext automatically initiates the renewal process before certificate expiry.

    • Renewal notifications are sent according to configured policies.

  • When disabled:

    • Renewals must be performed manually.

    • There is a higher risk of certificate expiry if renewal is overlooked.

  • It is recommended to leave this option enabled unless there is a specific operational requirement for manual renewals.

Set Renew Criteria: Before __ Days of Expiry

  • Defines how many days before certificate expiration the automatic renewal process should begin.

  • The default value is 15 days before expiry.

  • Organizations can increase this value to provide additional time for:

    • Validation activities

    • Approval workflows

    • Deployment planning

    • Change management processes

  • Example:

    • 15 Days: Renewal starts 15 days before expiration.

    • 30 Days: Renewal starts 30 days before expiration.

    • 60 Days: Renewal starts 60 days before expiration.

  • For large enterprises, a longer renewal window is often recommended to accommodate internal processes and avoid service disruption.

💡 TIP

Even though all fields on this screen are optional, it is good practice to: (1) add at least a Tag such as 'Production Web Server' or 'Wildcard - All Subdomains' to make the certificate easy to find later, and (2) leave Auto-renew turned ON to avoid your website showing a security warning due to an expired certificate.

📌 InCommon Note

The Auto-renew feature works the same way for InCommon certificates. Since InCommon DV certificates are issued for 30 days/ 90 days / 199 days at a time, auto-renewal will trigger 15 days (or your set number of days) before each expiry. Make sure your institutional InCommon agreement is still active at renewal time so the renewed certificate is also covered under the agreement.

Click Back to go back, or Next to proceed to the Order Summary.

Last updated