Ordering DV SSL Certificate
What Is a DV SSL Certificate?
A Domain Validation (DV) certificate is the quickest and most affordable type of SSL/TLS certificate. The Certificate Authority (emSign) simply confirms that you control the domain name - it does not check who you are or what organisation you represent.
When to use a DV certificate:
• Personal websites, blogs, or hobby sites
• Development or staging environments
• Short-term projects
• Any site where speed and low cost matter more than showing your organisation name in the certificate
What a DV certificate does NOT provide:
• It does not verify your organisation's identity
• Visitors cannot see your company name in the certificate - only your domain name is shown
What You Will Need Before You Start
Before beginning, please have the following ready:
• Your CERTInext login credentials (email and password)
• Your domain name (the website address you want to secure, e.g., www.mybusiness.com)
• A CSR (Certificate Signing Request) file - this is generated on your web server or by your IT team. If you don't have one yet, you can skip it during the application and submit it later.
• Access to your domain's email inbox or DNS settings - needed for the domain validation step after you apply
📌 InCommon Users: If your institution is part of the InCommon Certificate Service programme, your login process and group assignment may be pre-configured by your institution's IT administrator. The application steps shown here are the same for InCommon users. Your subscription cost may be covered under your institutional InCommon agreement. Check with your IT/PKI administrator before proceeding.
Overview - The Complete Journey
Ordering a DV SSL certificate on CERTInext involves two main phases:
Phase 1 - Application in CERTInext (6 Steps):
You fill in a 6-step wizard and make payment.
Phase 2 - Post-Submission Actions (via emSign Subscriber Portal):
After payment, you complete domain validation and download your certificate - guided by emails and a dedicated tracking portal.
The entire process, from application to certificate in hand, can take as little as 15–30 minutes for a DV certificate if your domain access is ready.
PHASE 1 - APPLYING FOR THE CERTIFICATE IN CERTInext
Step 1 - Choose Product & Validity
What you see: The first screen of the certificate application wizard. This is where you select exactly what type of certificate you want and for how long.

How to get here
1. Log in to CERTInext.
2. Click the "NEW CERTIFICATE" button in the dark sidebar on the left.
3. The screen titled "Certificates :: New Request" opens.
4. The left panel shows all 6 steps. You start at Step 1: "Choose Product & Validity".
Fields on this screen
Field
What It Is
What to Do
Group
The account/organisation in CERTInext that will own this certificate and be billed for it.
This is pre-filled. Confirm it shows your correct organisation name (e.g., ABC Private limited).
CA Source
The Certificate Authority (CA) that will issue your certificate.
Select emSign or any other integrated CA from the dropdown.
Certificate Type
The category of certificate.
Select SSL/TLS Certificates from the dropdown.
Product
The specific certificate product.
Select DV SSL Certificate (or the specific DV product you need - see the product info box that appears below).
Subscription For
How long the certificate will be valid. Three radio button options are shown.
Select 1 Year Subscription, 2 Years Subscription, or 3 Years Subscription based on your need.
Cost
The price calculated automatically based on your product and validity selection.
Review the displayed amount.
The Blue Information Box
When you select the DV SSL Certificate product, a blue information panel appears at the bottom of the screen. It describes what the product covers:
• For blogs, personal sites & non-business websites
• Secures Single, Wildcard, Multiple Domains & Sub Domains
• Domain Validation
• Fully Automated & Instant Approval
• Average Issuance Timeframe will be in Minutes
• Unlimited Server Licences
• Strongest SHA2 & ECC Encryption
• Major Browser & Mobile Device Compatibility
• Automatic renewal reminders and early renewal options
📌 InCommon Users: Under "Subscription For", you will see the same 1/2/3 year options. InCommon institutional agreements typically issue DV SSL certificates for 30 days/89 days/199 days at a time (in line with CA/Browser Forum rules). Even though your institution's InCommon contract may run for multiple years, each individual certificate must be renewed according to validity defined, but the auto-renew feature (set in Step 5) handles this automatically.
When done, click the Next button at the bottom right.
Step 2 - Certificate Signing Request (CSR)
What you see: A screen where you provide the CSR - a technical file from your web server that the CA uses to create your certificate.
What is a CSR?
A CSR (Certificate Signing Request) is a block of text generated by your web server. It contains your domain name and a public key. The CA uses it to create your certificate. Your IT team, hosting provider, or server administrator can generate this for you.
⚠️ Important note shown on screen: "The public key and signature algorithm from your CSR are used for certificate generation. Subject details such as Organisation, Country, and State are pre-filled from your CSR for convenience but can be edited. The values you submit in the form will be the final values in the issued certificate."
This means: even though fields like Country and State may be pre-filled from your CSR, what you type on the form is what will appear in your issued certificate - not necessarily what was in the CSR.

Your Three Options
Option A - Upload CSR File
1. Click the "Choose File" button next to "Upload CSR".
2. A file browser opens. Navigate to your .csr or .pem file on your computer.
3. Select the file. The filename appears next to the button once selected.
Option B - Paste CSR Text
1. Open your CSR file in a text editor (Notepad, TextEdit, etc.).
2. Copy everything - the entire block starting with -----BEGIN CERTIFICATE REQUEST----- and ending with -----END CERTIFICATE REQUEST-----, including those header and footer lines.
3. Paste the copied text into the "Paste CSR" text box on screen.
4. The text box shows the CSR block once pasted, as visible in the screenshot.
Option C - Skip CSR
1. Tick the "Skip CSR" checkbox at the top of the screen.
2. You can complete the order and pay now, then provide the CSR later.
3. Use this if your IT team hasn't generated the CSR yet but you need to get the order started.
⚠️ Tip: If you are using a shared hosting service (e.g., cPanel, Plesk), log in to your hosting control panel first, go to SSL/TLS settings, and generate a CSR from there. Copy and paste the generated CSR text into the Paste CSR box.
Click the Back button to go back, or Next to proceed.
Step 3 - Certificate Requestor Information
What you see: A screen titled "Certificate Requestor Information" where you confirm the details of the person placing this order.

Fields on this screen
Field
What It Is
What to Do
Name (required - marked with )*
Your full name as the person requesting this certificate. This is who placed the order.
Pre-filled from your account profile. Verify it is your correct full name. Example: John Doe
Requestor Email ID (required - marked with )*
The email address that will receive all notifications about this order - order confirmation, domain validation requests, and the certificate issuance notification. The ℹ️ icon shows additional guidance.
Pre-filled from your account. Make sure this is a monitored inbox - you will need to act on emails sent here. Example: johndoe@xyz.com
Mobile Number
Your contact phone number. The country code is selected from a dropdown (e.g., "+1 United States of America").
Pre-filled from your account. Update if your number has changed.
CERTIFICATE DOWNLOAD DELEGATION (section header with ℹ️)
This optional section lets you authorise another person to download the certificate on your behalf. Useful if the person applying is different from the IT person who will install the certificate.
Only fill this in if a different person should handle the certificate download.
Contact Name (under delegation - optional)
Full name of the person you are delegating download access to (e.g., your server administrator).
Leave blank if only you will download the certificate.
Email ID (under delegation - optional)
Email address of the delegated person. They will also receive the certificate issuance email.
Leave blank if not needed.
📌 Tip: If you are applying for a certificate on behalf of someone else (e.g., a client or colleague), enter your own details as the Requestor, and use the Certificate Download Delegation fields to ensure the certificate recipient also gets notified and can download it.
Click Back to go back, or Next to proceed.
Step 4 - Certificate Information
What you see: A screen titled "Certificate Information" where you enter the domain name that the certificate will protect.

Fields on this screen
Field
What It Is
What to Do
Automatically secure 'www' variant of websites (checkbox)
When ticked, the certificate automatically also covers www.yourdomain.com in addition to yourdomain.com. This means one certificate protects both the bare domain and the www version.
This box is checked by default - leave it ticked unless you specifically only want one version. Most websites need both.
Domain Name (required - marked with )*
The domain name this certificate will secure. This is the web address your visitors type into their browser.
Type or select your domain name. Example: mybusiness.com. The system may show a test/validation domain name during verification (e.g., a long string ending in .dcv-inspector.com) - use your actual domain name, not that test string.
⚠️ Critical: The domain name you enter here must match the Common Name (CN) in the CSR you provided in Step 2. If they don't match, the Certificate Authority will reject the request. If you are unsure, check with your IT team what domain name was used when generating the CSR.
⚠️ Example mismatch to avoid: If your CSR was generated for shop.mybusiness.com but you enter mybusiness.com here, the CA will reject it. Make sure they are identical.
Click Back to go back, or Next to proceed.
Step 5 - Additional Information (Optional)
What you see: A screen titled "Additional Information" with optional fields that help with managing and administering the certificate. None of these are required to get the certificate issued - but some are very useful.

Fields on this screen
Field
What It Is
What to Do
Tags (with ℹ️ and "+ Add Tag" button)
Labels you can attach to this certificate order for your own internal organisation and searching. For example, "Production", "Web Server", or a client name.
Click + Add Tag and type a label. You can add multiple tags. Leave blank if not needed.
Order Remarks
A free-text field for internal notes about this order. Not visible to the CA - just for your own reference.
Type any notes that will help you remember why this order was placed. Example: "For new e-commerce checkout page". Leave blank if not needed.
Technical Point of Contact Information (checkbox with ℹ️)
When ticked, expands to show fields for a technical contact person (e.g., your server administrator) who can be reached about this certificate. This is different from the Requestor.
Tick and fill in if you want to record your IT contact's details. Leave unticked if not needed.
KYC Documents (checkbox with ℹ️)
When ticked, lets you upload identity or business verification documents. Some certificate types or enterprise accounts require these.
Tick only if you have been asked to provide KYC documents. For standard DV certificates, this is usually not required.
Additional email recipients (checkbox)
When ticked, lets you add more email addresses to receive certificate notifications (order updates, issuance alerts).
Tick and add emails if your manager, IT team, or a client also needs to receive notifications.
Auto-renew certificates until coverage (checkbox with ℹ️ - ticked by default)
When ON, CERTInext automatically starts the renewal process before your certificate expires, so your website never goes unprotected.
Leave this ON (it is ticked by default). Highly recommended for all users.
Set renew criteria: Before ___ days of certificate expiry
Defines how many days before expiry the auto-renewal process will be triggered. Default is 15 days.
Leave at 15 days unless you have a specific reason to change it.
📌 InCommon Users: The auto-renew feature works the same way for InCommon certificates. Since InCommon DV certificates are valid for 1 year, the auto-renewal will trigger 15 days before the 1-year mark. Make sure your institutional InCommon agreement is still active at renewal time so the renewed certificate is also covered.
📌 Tip: Even though all fields on this screen are optional, it is good practice to add at least a Tag (e.g., "Production Web Server") to make it easier to find and manage this certificate later in the Orders list.
Click Back to go back, or Next to proceed to the Order Summary.
Step 6 - Order Summary & Payment
What you see: The final screen before submitting your order. It shows a complete summary of everything you have entered, along with the payment breakdown.
Notice: An orange "Payment Pending" badge appears in the top-right corner - this confirms the order has not yet been paid.

What Is Shown on This Screen
Product Information section:
Item
Value
Certificate Type
SSL/TLS Certificates
Product Name
DV SSL Certificate
Validity Period
1 Year
Domain Count
1
Certificate Information section:
Shows the domain name you entered in Step 4 - confirm this is correct before paying.
Payment Information section:
Item
Description
Current Balance
Your account's pre-loaded credit balance in USD. This is your organisation's available credit in CERTInext.
Cost
The base price of the certificate in USD
Grand Total
The final amount you will pay in USD
Important notice on screen:
"On click of Use Credits button, amount will be deducted from group balance."
This means if you click Use Credit, the Grand Total will be deducted from your organisation's pre-loaded balance - no separate card payment needed.
The Subscriber Agreement Checkbox
⚠️ You MUST tick this checkbox before you can pay. The checkbox text reads: "The Subscriber/Requestor hereby agrees to have read, understood and agree to Subscriber Agreement of emSign."
By ticking this, you are legally agreeing to the terms and conditions of the emSign Certificate Authority for issuing this certificate. Click the "Subscriber Agreement" link in the text to read the full terms before ticking.
Payment Buttons
Button
What It Does
Save and Exit
Saves your order as a draft. No payment is made. Status will show "Payment Pending". You can return to complete payment later.
Pay Online
Opens a payment gateway. Pay using a debit card, credit card, or net banking.
Use Credit
Instantly deducts the Grand Total from your organisation's CERTInext credit balance. Most common option for enterprise accounts. No card details required.
📌 InCommon Users: If your InCommon certificate is included under an institutional subscription, the cost shown may be zero USD or a nominal amount. Click Use Credit to proceed. If the cost appears unexpectedly high, contact your IT administrator before paying - the pricing configuration may need to be verified.
Once you click Use Credit or Pay Online and the payment is processed, your order is submitted. You will be taken to the Order Confirmation screen and will receive a confirmation email. Do not close the browser immediately - wait for the confirmation screen to load.
PHASE 2 - POST-SUBMISSION: WHAT HAPPENS AFTER YOU PAY
Immediately After Payment - The Order View Screen in CERTInext
What you see: The "Certificates :: Orders > View Order" page opens automatically after payment. This page shows the complete record of your order.

The Order Header Bar
At the very top of the page, a summary bar shows:
Item
What It Means
Order ID
A unique number for your order (e.g., 1184216685). Keep this for your records and for any support queries.
Ordered Date
The date and time your order was placed (e.g., 25 May 2026, 15:13).
Product
The certificate you ordered (e.g., DV SSL Certificate).
Group
Your organisation's account name (e.g., ABC Group).
CA Source
The issuing CA: emSign or any CA
Certificate Price
The total amount charged in USD
Order Status
Shows "Order Accepted" in an orange badge - this means your payment was received and the order is in the system, but it still needs internal approval within your CERTInext account before proceeding to the CA.
Certificate Status
Shows "Pending for Approver" in an orange badge - this means your organisation's CERTInext account administrator must review and approve the order before emSign begins processing it.
⚠️ Important - Pending for Approver: In enterprise CERTInext accounts, every new certificate order must be approved by an Account Administrator before it is forwarded to emSign. If you are the Administrator, you can approve it yourself from this page using the 3-dot menu (⋮) in the top-right corner. If you are not the Administrator, contact your IT department or CERTInext account manager and ask them to approve Order ID [your order number].
What the Rest of the Order View Page Shows
The page is divided into several information panels:
SSL Subscription Information:
• Subscription For: 1 year
• Subscription Start Date / End Date: Shown as "–" (dashes) at this stage because the certificate has not yet been issued
• Subscription Status: Pending (orange) - will change to Active once issued
Auto-Renewal Configuration:
• Confirms that auto-renew is set to Yes, triggering 15 days before expiry
Certificate Information:
• Shows your domain name
Certificate Requestor Information:
• Confirms Name, Email, and Mobile Number from Step 3
Certificate Signing Request (CSR) Information:
• CN: Your domain name (from the CSR)
• Key Size: 2048 (standard - this is the strength of your encryption key)
• Key Algorithm: RSA (standard encryption algorithm)
Ordered By:
• Shows the name of the user who placed the order and their role (e.g., Administrator)
Renewal Notifications:
• Send email notifications: Yes - you will receive reminder emails before the certificate expires
Reissue History:
• "No records found" - as expected for a brand-new order
📌 The 3-dot menu (⋮) in the top-right corner of the order page gives Administrators access to: Track Order (generate public tracking URL), Download Invoice, Replace CSR, Recall Request, and Cancel Order.
Email 1 - Order Confirmation: "Your Order is Successful"
What you see: Shortly after payment, you receive an email at the Requestor Email ID you provided in Step 3.

Email Subject: ORDER #[your order ID] - Your Order is Successful
Email Content:
Field
Value
Greeting
Dear [Your Name], / Your order is placed successfully.
Order ID
Your unique order number (e.g., 1184216685)
Ordered Date
Date and time of the order in UTC (e.g., 25-May-2026 09:43 (UTC))
Product & Validity
DV SSL Certificate
Identifier
The domain name secured by this certificate
Subscription For
1 Year(s)
The orange "Track Order" button in the email is your key to the next stage. Clicking it takes you to the emSign Subscriber Portal - a separate web page where you complete the remaining steps: domain validation and certificate download.
⚠️ Do not ignore this email. The Track Order link is how you complete the domain validation step. Without completing domain validation, your certificate cannot be issued.
📌 Check your spam/junk folder if you do not see this email within a few minutes of payment. The email is sent from emSign (emudhra.com domain). Add the sender to your safe senders list to avoid future emails going to spam.
Contact details at the bottom of the email:
The email shows a support email address and phone number. Use these if you need help.
The emSign Subscriber Portal - Your Order Tracking Hub
What you see: Clicking the "Track Order" button in the confirmation email opens the emSign Subscriber Portal - a dedicated, public-facing page that guides you through the remaining steps to get your certificate issued.

Page Header: "Hello [Your Name], Please follow the instructions and complete the below verification steps to speed up your certificate issuance process."
The Four Order Actions
This page shows four steps that must be completed, in the Order Actions section:
#
Action
Status at This Stage
1. Submit CSR
Confirming your CSR has been provided
✅ Completed (green)
2. Subscriber Agreement
Confirming you accepted the subscriber agreement at payment
✅ Completed (green)
3. Domain Verification
Proving to the CA that you own/control the domain
🟠 Awaiting Customer Action (orange) - you must complete this
4. Certificate Download
Downloading the issued certificate
🟠 Issuance Pending (orange) - will be available once Step 3 is done
The Order Details Sidebar (right side of page)
Item
What It Shows
Date Ordered
Date you placed the order
Order ID
Your unique reference number
Product & Validity
DV SSL Certificate
Domain Name
The domain being secured (truncated)
Order Status
Order Accepted
Certificate Status
Pending for Approver
📌 InCommon Users: The emSign Subscriber Portal is the same for all users, including InCommon. The domain verification step is required regardless of your InCommon membership - all certificates require you to prove domain control.
📌 You can always come back to this page by clicking the Track Order button in the confirmation email, or by generating the tracking URL from within CERTInext (3-dot menu → Track Order).
Completing Domain Verification (Step 3 on the emSign Portal)
What you see: Clicking on the "3. Domain Verification" row (or the "+" expand icon on the left) expands a section showing your domain and the domain validation controls.

What You See When Expanded
• Total Domains: 1 - confirms one domain needs to be validated
• Under Domain Control Validation (DCV), your domain name is listed with two buttons:
– CAA - for checking the Certification Authority Authorisation record (advanced, typically for IT teams)
– Verify - the button you click to start domain validation
DCV Instructions (shown on the page):
"A Domain Control Validation or DCV must be completed before issuing an SSL/TLS certificate."
"Please click 'Verify Domain' against each domain name to select a DCV method and prove control over each domain."
"In case of Multi-Domain SSL Certificates, if the authorised domain name (base domain) ownership is proven then all the sub-domains that have the same base domain name will be proven automatically."
How to Start - Click the "Verify" Button
Click the orange "Verify" button next to your domain name. A popup window opens, titled:
"Domain Control Validation ([your domain]) – #[Order ID]"
⚠️ Note shown in the popup: "This is technical in nature (if you are not the right person, please contact your IT / Domain administrator)."

If you are not the person who manages your domain's DNS or web server, stop here and forward the tracking URL to your IT or domain administrator and ask them to complete the domain verification step.
Choosing a DCV Method
The popup shows a DCV Method dropdown with options. The two main methods are:
Method 1: DNS TXT Record (Most Preferred - Recommended)
Select "DNS TXT Record (Most Preferred)" from the DCV Method dropdown.
The popup shows a table with a record to add to your DNS:
Record Type
Host
Value
TXT
Your domain name
A unique alphanumeric token (e.g., 5A27BFFF4R95F80945F8D5491A8FFC98)
Both the Host and Value fields have "Copy" buttons next to them - click these to copy the exact values.
Step-by-step instructions:
1. Log in to your domain registrar or DNS provider (e.g., GoDaddy, Cloudflare, Namecheap, Google Domains).
2. Navigate to the DNS Management section for your domain.
3. Add a new TXT record with:
– Host/Name: Copy the Host value from the popup (it may be your full domain name or just @ depending on your provider)
– Value/Content: Copy the long alphanumeric token from the popup
– TTL: Set to the minimum available (e.g., 300 seconds / 5 minutes) for fastest propagation
4. Save the DNS record.
5. Wait 5–30 minutes for the DNS record to propagate (may take up to 48 hours in rare cases).
6. Return to the popup and click "Verify Now" (orange button).
7. If successful, the popup confirms domain ownership.
📌 InCommon Users: The DNS TXT record method is the most reliable and is recommended for InCommon institutional certificates. If your domain is managed by your institution's IT department, provide them with the Host and Value shown in the popup and ask them to add the TXT record.
Method 2: HTTP/HTTPS File-Based Validation
Select "HTTP/HTTPS File-based" from the DCV Method dropdown.

⚠️ Note shown in the popup: "File-based (HTTP/HTTPS URL) DCV method can only be used to prove domain ownership over Fully Qualified Domain Names (FQDNs), exactly as named. In case you wish to have it work for both www and without www, we recommend you to use alternate DCV methods."
Recommendation: Use DNS TXT Record instead unless you have a specific reason to use file-based validation.
The popup shows a table with the file details:
Item
Detail
File Name
A specific filename (e.g., 084984170207f94FB0482A1A70BF9A82.txt) - with a Copy button
File Content
A unique token string (e.g., 30924A299885503882D10144825CD4F5) - with a Copy button
Step-by-step instructions:
1. The popup also provides a "Download file" link - click it to download the ready-made .txt file (saves you creating it manually).
2. Upload the downloaded file to your web server at exactly this path:
http://[yourdomain.com]/.well-known/pki-validation/[filename].txt
The full directory path is shown in the popup for convenience - copy it.
3. Do not change the filename or its contents. The file must be accessible at the exact URL shown.
4. Once the file is uploaded and accessible, click "Verify Now" in the popup.
How to upload the file: Use an FTP client (e.g., FileZilla), your hosting control panel's File Manager (cPanel, Plesk), or ask your hosting provider.
⚠️ Important: Verify that the file is publicly accessible before clicking Verify Now. Open the URL in a browser - if the file downloads or displays the token text, it is accessible. If you see a 404 error, the file is not in the right location.
After Domain Verification Succeeds
Once you click Verify Now and the CA confirms your domain control, a green success popup appears:

✅ "Thank you for proving the domain ownership for [your domain]. Domain Verification is completed successfully. Please track your order and complete your pending actions to speed up the certificate issuance process."
Click OK to dismiss the popup.
The Order Actions list now updates:
#
Action
1. Domain Verification
✅ Completed (green)
2. Submit CSR
✅ Completed (green)
3. Subscriber Agreement
✅ Completed (green)
4. Certificate Download
🟠 Issuance Pending (orange)
The Certificate Status in the right sidebar still shows "Pending for Approver" at this point - the internal Administrator approval in CERTInext is still required before the certificate is fully issued.
⚠️ Reminder about Administrator Approval: Even after domain verification is complete, the certificate will not be issued until the CERTInext account Administrator approves the order. If the Certificate Status stays on "Pending for Approver" for a long time after domain verification, contact your Administrator.
Certificate Issued - Step 4 Becomes Available
Once both domain verification is complete AND the Administrator has approved the order, emSign issues the certificate. The Order Actions list updates:

#
Action
1. Domain Verification
✅ Completed (green)
2. Submit CSR
✅ Completed (green)
3. Subscriber Agreement
✅ Completed (green)
4. Certificate Download
✅ Certificate Issued (green)
The Order Details sidebar on the right updates to show:
• Order Status: Order Accepted (orange - note this is normal at this stage)
• Certificate Status: Certificate Generated (green) ← This is the key status showing the certificate exists and is ready
Downloading the Certificate (Step 4 on the emSign Portal)
What you see: Expanding the "4. Certificate Download" row shows a green "Certificate Issued" badge and a download message.

The Download Message
The expanded section shows:
"Your certificate has been issued and ready for download. An email containing certificate download instructions has been sent to your email ID ([your email]). In case, if you have not received an email, please click Resend Email button to resend the email. Your certificate is based on the CSR submitted by you. Please ensure to import / use the certificate against the same key-pair, from where the CSR was generated. Please follow the necessary instructions in your download notification email to download your certificate."
Two Buttons
Button
What It Does
Resend Email
Resends the certificate download notification email to your registered email address. Use this if you did not receive the email.
Download Certificate
Directly downloads the certificate from this page (without needing the email link).
Email 2 - Certificate Ready: "Your Certificate is ready for download"
What you see: A second email arrives at your Requestor Email ID.

Email Subject: ORDER #[your order ID] - Your Certificate is ready for download
Email Content:
Field
Value
Greeting
Dear [Your Name], / Your Certificate is ready for download!
Order ID
Your unique order number
Ordered Date
Date and time in UTC
Product & Validity
DV SSL Certificate
Identifier
Your domain name
The email contains:
• An orange "Download Certificate" button - click it to go directly to the certificate download page
• OR - A URL you can copy and paste into your browser's address bar to reach the download page
📌 Save this email. The download link allows you to access the certificate directly. If you miss it, use the Resend Email button in the emSign Subscriber Portal, or download directly from CERTInext (Certificates → Orders → View → Download).
Certificate Download - Selecting Your Format
Clicking the "Download Certificate" button (from the email or the emSign portal) takes you to the emSign Subscriber Portal download page.
The Download Landing Page
Page message:
"Thanks for completing the necessary steps. Your certificate has been issued and ready for download. To continue further, please click 'Download Certificate'."
The page confirms:
• Order ID
• Product & Validity: DV SSL Certificate
• Domain Name: Your domain
Click the orange "Download Certificate" button on this page.

Choosing the Download Format
A popup appears titled "Select the Format to download" with four options:

Format
What It Is
Best For
DER encoded binary X.509 (.CER)
A binary (machine-readable) format. The file is not human-readable text.
Java applications, some enterprise systems, older Microsoft environments
Base-64 encoded X.509 (.CER)
A text-based format with a .CER file extension.
Windows systems, IIS web server
Base-64 encoded X.509 (.CRT)
A text-based format with a .CRT file extension - same content as .CER, just a different extension.
Apache, Nginx, Linux web servers - the most commonly used format
Zip
A compressed ZIP archive containing multiple certificate files (the certificate, intermediate chain, and optionally root certificate).
When you need all certificate files in one download - recommended if you are unsure which format to choose
📌 Which format should I choose?
- If you use Apache or Nginx (Linux): choose Base-64 encoded X.509 (.CRT)
- If you use Windows IIS or Microsoft environments: choose Base-64 encoded X.509 (.CER) or DER encoded binary
- If you use cPanel or Plesk shared hosting: choose Base-64 encoded X.509 (.CRT)
- If you are unsure: choose Zip - it contains everything and you can use whichever file you need
Select the format and click the Download button. The certificate file saves to your computer.
⚠️ Important: Your certificate file does NOT include your private key. Your private key was created on your server when you generated the CSR - it never left your server. The certificate file and the private key must both be present on your server to enable HTTPS. Never share your private key with anyone.
After Download - The Order is Complete
Back in CERTInext - Final Order Status
After you download the certificate, return to CERTInext and check Certificates → Orders. Click View on your order. The status has now fully updated:
Order Summary bar:
• Order Status: Order Fulfilled (green badge)
• Certificate Status: Certificate Downloaded (green badge)
SSL Subscription Information panel:
• Subscription Start Date: The date and time the certificate was issued (e.g., 25 May 2026, 15:20)
• Subscription End Date: Exactly 1 year later (e.g., 25 May 2027, 15:20)
• Subscription Status: Active (green)
Issuer CA Information:
• Root CA: emSign QA SSL RSA CA – G1
• CA Type: Public
These details confirm your certificate was successfully issued by emSign and is now active.
Installing the Certificate on Your Server
After downloading, you need to install the certificate on your web server. The exact steps depend on your server type:
Apache / Nginx (Linux - most common):
1. Upload the .crt file and the intermediate/chain certificate file to your server.
2. Edit your server's SSL configuration file to point to these files.
3. Restart Apache or Nginx.
4. Test by visiting your site at https://yourdomain.com - the padlock should appear.
Windows IIS:
1. Open IIS Manager.
2. Go to Server Certificates → Complete Certificate Request.
3. Select your downloaded certificate file.
4. Bind the certificate to your website on port 443.
cPanel / Plesk (Shared Hosting):
1. Log in to your hosting control panel.
2. Go to SSL/TLS → Manage SSL Sites or Install Certificate.
3. Paste the Base-64 certificate contents into the Certificate field.
4. Also paste the CA Bundle / Intermediate Certificate contents.
5. Click Install or Save.
📌 Ask for help if needed: Installing a certificate on a server requires server administration access. If you are not your organisation's IT administrator, hand the downloaded certificate file to your IT team and ask them to install it.
Summary - The Complete DV Certificate Journey
Step
Where
Action
Result
1–6
CERTInext
Fill in application wizard & pay
Order submitted; Order Status: Order Accepted
Post-payment
CERTInext
View Order page
Certificate Status: Pending for Approver
Email 1
Your inbox
Receive "Order Successful" email
Contains "Track Order" button
Track Order Portal
emSign Subscriber
See 4 Order Actions
Steps 1 & 2 already complete
Domain Verification
emSign Subscriber
Click Verify → choose DNS TXT or HTTP file method → complete
Domain validated
Admin Approval
CERTInext
Administrator approves the order
Certificate Status moves to Certificate Generated
Email 2
Your inbox
Receive "Certificate Ready" email
Contains "Download Certificate" button
Download
emSign Subscriber Portal or CERTInext
Choose format (.CRT / .CER / Zip) → download
Certificate file saved to your computer
Install
Your web server
Install certificate on server
HTTPS padlock appears on your website
CERTInext
Orders → View
Final check
Order Status: Order Fulfilled; Certificate Status: Certificate Downloaded; Subscription: Active
📌 InCommon Users - Final Note: The complete journey shown above applies equally to InCommon DV SSL certificates. The only differences are: (1) pricing may be zero USD or flat-rate under your institutional agreement, (2) your subscription validity will be 30 days / 89 days / 199 days per certificate issuance, and (3) auto-renew will trigger annually. Contact your institution's IT/PKI administrator if the certificate shows unexpected costs or if the renewal process requires additional institutional approval steps.
Last updated
