For the complete documentation index, see llms.txt. This page is also available as Markdown.

Ordering DV SSL Certificate

What Is a DV SSL Certificate?

A Domain Validation (DV) certificate is the quickest and most affordable type of SSL/TLS certificate. The Certificate Authority (emSign) simply confirms that you control the domain name - it does not check who you are or what organisation you represent.

When to use a DV certificate:

• Personal websites, blogs, or hobby sites

• Development or staging environments

• Short-term projects

• Any site where speed and low cost matter more than showing your organisation name in the certificate

What a DV certificate does NOT provide:

• It does not verify your organisation's identity

• Visitors cannot see your company name in the certificate - only your domain name is shown

What You Will Need Before You Start

Before beginning, please have the following ready:

• Your CERTInext login credentials (email and password)

• Your domain name (the website address you want to secure, e.g., www.mybusiness.com)

• A CSR (Certificate Signing Request) file - this is generated on your web server or by your IT team. If you don't have one yet, you can skip it during the application and submit it later.

• Access to your domain's email inbox or DNS settings - needed for the domain validation step after you apply

📌 InCommon Users: If your institution is part of the InCommon Certificate Service programme, your login process and group assignment may be pre-configured by your institution's IT administrator. The application steps shown here are the same for InCommon users. Your subscription cost may be covered under your institutional InCommon agreement. Check with your IT/PKI administrator before proceeding.

Overview - The Complete Journey

Ordering a DV SSL certificate on CERTInext involves two main phases:

Phase 1 - Application in CERTInext (6 Steps):

You fill in a 6-step wizard and make payment.

Phase 2 - Post-Submission Actions (via emSign Subscriber Portal):

After payment, you complete domain validation and download your certificate - guided by emails and a dedicated tracking portal.

The entire process, from application to certificate in hand, can take as little as 15–30 minutes for a DV certificate if your domain access is ready.

PHASE 1 - APPLYING FOR THE CERTIFICATE IN CERTInext

Step 1 - Choose Product & Validity

What you see: The first screen of the certificate application wizard. This is where you select exactly what type of certificate you want and for how long.

How to get here

1. Log in to CERTInext.

2. Click the "NEW CERTIFICATE" button in the dark sidebar on the left.

3. The screen titled "Certificates :: New Request" opens.

4. The left panel shows all 6 steps. You start at Step 1: "Choose Product & Validity".

Fields on this screen

Field

What It Is

What to Do

Group

The account/organisation in CERTInext that will own this certificate and be billed for it.

This is pre-filled. Confirm it shows your correct organisation name (e.g., ABC Private limited).

CA Source

The Certificate Authority (CA) that will issue your certificate.

Select emSign or any other integrated CA from the dropdown.

Certificate Type

The category of certificate.

Select SSL/TLS Certificates from the dropdown.

Product

The specific certificate product.

Select DV SSL Certificate (or the specific DV product you need - see the product info box that appears below).

Subscription For

How long the certificate will be valid. Three radio button options are shown.

Select 1 Year Subscription, 2 Years Subscription, or 3 Years Subscription based on your need.

Cost

The price calculated automatically based on your product and validity selection.

Review the displayed amount.

The Blue Information Box

When you select the DV SSL Certificate product, a blue information panel appears at the bottom of the screen. It describes what the product covers:

• For blogs, personal sites & non-business websites

• Secures Single, Wildcard, Multiple Domains & Sub Domains

• Domain Validation

• Fully Automated & Instant Approval

• Average Issuance Timeframe will be in Minutes

• Unlimited Server Licences

• Strongest SHA2 & ECC Encryption

• Major Browser & Mobile Device Compatibility

• Automatic renewal reminders and early renewal options

📌 InCommon Users: Under "Subscription For", you will see the same 1/2/3 year options. InCommon institutional agreements typically issue DV SSL certificates for 30 days/89 days/199 days at a time (in line with CA/Browser Forum rules). Even though your institution's InCommon contract may run for multiple years, each individual certificate must be renewed according to validity defined, but the auto-renew feature (set in Step 5) handles this automatically.

When done, click the Next button at the bottom right.

Step 2 - Certificate Signing Request (CSR)

What you see: A screen where you provide the CSR - a technical file from your web server that the CA uses to create your certificate.

What is a CSR?

A CSR (Certificate Signing Request) is a block of text generated by your web server. It contains your domain name and a public key. The CA uses it to create your certificate. Your IT team, hosting provider, or server administrator can generate this for you.

⚠️ Important note shown on screen: "The public key and signature algorithm from your CSR are used for certificate generation. Subject details such as Organisation, Country, and State are pre-filled from your CSR for convenience but can be edited. The values you submit in the form will be the final values in the issued certificate."

This means: even though fields like Country and State may be pre-filled from your CSR, what you type on the form is what will appear in your issued certificate - not necessarily what was in the CSR.

Your Three Options

Option A - Upload CSR File

1. Click the "Choose File" button next to "Upload CSR".

2. A file browser opens. Navigate to your .csr or .pem file on your computer.

3. Select the file. The filename appears next to the button once selected.

Option B - Paste CSR Text

1. Open your CSR file in a text editor (Notepad, TextEdit, etc.).

2. Copy everything - the entire block starting with -----BEGIN CERTIFICATE REQUEST----- and ending with -----END CERTIFICATE REQUEST-----, including those header and footer lines.

3. Paste the copied text into the "Paste CSR" text box on screen.

4. The text box shows the CSR block once pasted, as visible in the screenshot.

Option C - Skip CSR

1. Tick the "Skip CSR" checkbox at the top of the screen.

2. You can complete the order and pay now, then provide the CSR later.

3. Use this if your IT team hasn't generated the CSR yet but you need to get the order started.

⚠️ Tip: If you are using a shared hosting service (e.g., cPanel, Plesk), log in to your hosting control panel first, go to SSL/TLS settings, and generate a CSR from there. Copy and paste the generated CSR text into the Paste CSR box.

Click the Back button to go back, or Next to proceed.

Step 3 - Certificate Requestor Information

What you see: A screen titled "Certificate Requestor Information" where you confirm the details of the person placing this order.

Fields on this screen

Field

What It Is

What to Do

Name (required - marked with )*

Your full name as the person requesting this certificate. This is who placed the order.

Pre-filled from your account profile. Verify it is your correct full name. Example: John Doe

Requestor Email ID (required - marked with )*

The email address that will receive all notifications about this order - order confirmation, domain validation requests, and the certificate issuance notification. The ℹ️ icon shows additional guidance.

Pre-filled from your account. Make sure this is a monitored inbox - you will need to act on emails sent here. Example: johndoe@xyz.com

Mobile Number

Your contact phone number. The country code is selected from a dropdown (e.g., "+1 United States of America").

Pre-filled from your account. Update if your number has changed.

CERTIFICATE DOWNLOAD DELEGATION (section header with ℹ️)

This optional section lets you authorise another person to download the certificate on your behalf. Useful if the person applying is different from the IT person who will install the certificate.

Only fill this in if a different person should handle the certificate download.

Contact Name (under delegation - optional)

Full name of the person you are delegating download access to (e.g., your server administrator).

Leave blank if only you will download the certificate.

Email ID (under delegation - optional)

Email address of the delegated person. They will also receive the certificate issuance email.

Leave blank if not needed.

📌 Tip: If you are applying for a certificate on behalf of someone else (e.g., a client or colleague), enter your own details as the Requestor, and use the Certificate Download Delegation fields to ensure the certificate recipient also gets notified and can download it.

Click Back to go back, or Next to proceed.

Step 4 - Certificate Information

What you see: A screen titled "Certificate Information" where you enter the domain name that the certificate will protect.

Fields on this screen

Field

What It Is

What to Do

Automatically secure 'www' variant of websites (checkbox)

When ticked, the certificate automatically also covers www.yourdomain.com in addition to yourdomain.com. This means one certificate protects both the bare domain and the www version.

This box is checked by default - leave it ticked unless you specifically only want one version. Most websites need both.

Domain Name (required - marked with )*

The domain name this certificate will secure. This is the web address your visitors type into their browser.

Type or select your domain name. Example: mybusiness.com. The system may show a test/validation domain name during verification (e.g., a long string ending in .dcv-inspector.com) - use your actual domain name, not that test string.

⚠️ Critical: The domain name you enter here must match the Common Name (CN) in the CSR you provided in Step 2. If they don't match, the Certificate Authority will reject the request. If you are unsure, check with your IT team what domain name was used when generating the CSR.

⚠️ Example mismatch to avoid: If your CSR was generated for shop.mybusiness.com but you enter mybusiness.com here, the CA will reject it. Make sure they are identical.

Click Back to go back, or Next to proceed.

Step 5 - Additional Information (Optional)

What you see: A screen titled "Additional Information" with optional fields that help with managing and administering the certificate. None of these are required to get the certificate issued - but some are very useful.

Fields on this screen

Field

What It Is

What to Do

Tags (with ℹ️ and "+ Add Tag" button)

Labels you can attach to this certificate order for your own internal organisation and searching. For example, "Production", "Web Server", or a client name.

Click + Add Tag and type a label. You can add multiple tags. Leave blank if not needed.

Order Remarks

A free-text field for internal notes about this order. Not visible to the CA - just for your own reference.

Type any notes that will help you remember why this order was placed. Example: "For new e-commerce checkout page". Leave blank if not needed.

Technical Point of Contact Information (checkbox with ℹ️)

When ticked, expands to show fields for a technical contact person (e.g., your server administrator) who can be reached about this certificate. This is different from the Requestor.

Tick and fill in if you want to record your IT contact's details. Leave unticked if not needed.

KYC Documents (checkbox with ℹ️)

When ticked, lets you upload identity or business verification documents. Some certificate types or enterprise accounts require these.

Tick only if you have been asked to provide KYC documents. For standard DV certificates, this is usually not required.

Additional email recipients (checkbox)

When ticked, lets you add more email addresses to receive certificate notifications (order updates, issuance alerts).

Tick and add emails if your manager, IT team, or a client also needs to receive notifications.

Auto-renew certificates until coverage (checkbox with ℹ️ - ticked by default)

When ON, CERTInext automatically starts the renewal process before your certificate expires, so your website never goes unprotected.

Leave this ON (it is ticked by default). Highly recommended for all users.

Set renew criteria: Before ___ days of certificate expiry

Defines how many days before expiry the auto-renewal process will be triggered. Default is 15 days.

Leave at 15 days unless you have a specific reason to change it.

📌 InCommon Users: The auto-renew feature works the same way for InCommon certificates. Since InCommon DV certificates are valid for 1 year, the auto-renewal will trigger 15 days before the 1-year mark. Make sure your institutional InCommon agreement is still active at renewal time so the renewed certificate is also covered.

📌 Tip: Even though all fields on this screen are optional, it is good practice to add at least a Tag (e.g., "Production Web Server") to make it easier to find and manage this certificate later in the Orders list.

Click Back to go back, or Next to proceed to the Order Summary.

Step 6 - Order Summary & Payment

What you see: The final screen before submitting your order. It shows a complete summary of everything you have entered, along with the payment breakdown.

Notice: An orange "Payment Pending" badge appears in the top-right corner - this confirms the order has not yet been paid.

What Is Shown on This Screen

Product Information section:

Item

Value

Certificate Type

SSL/TLS Certificates

Product Name

DV SSL Certificate

Validity Period

1 Year

Domain Count

1

Certificate Information section:

Shows the domain name you entered in Step 4 - confirm this is correct before paying.

Payment Information section:

Item

Description

Current Balance

Your account's pre-loaded credit balance in USD. This is your organisation's available credit in CERTInext.

Cost

The base price of the certificate in USD

Grand Total

The final amount you will pay in USD

Important notice on screen:

"On click of Use Credits button, amount will be deducted from group balance."

This means if you click Use Credit, the Grand Total will be deducted from your organisation's pre-loaded balance - no separate card payment needed.

The Subscriber Agreement Checkbox

⚠️ You MUST tick this checkbox before you can pay. The checkbox text reads: "The Subscriber/Requestor hereby agrees to have read, understood and agree to Subscriber Agreement of emSign."

By ticking this, you are legally agreeing to the terms and conditions of the emSign Certificate Authority for issuing this certificate. Click the "Subscriber Agreement" link in the text to read the full terms before ticking.

Payment Buttons

Button

What It Does

Save and Exit

Saves your order as a draft. No payment is made. Status will show "Payment Pending". You can return to complete payment later.

Pay Online

Opens a payment gateway. Pay using a debit card, credit card, or net banking.

Use Credit

Instantly deducts the Grand Total from your organisation's CERTInext credit balance. Most common option for enterprise accounts. No card details required.

📌 InCommon Users: If your InCommon certificate is included under an institutional subscription, the cost shown may be zero USD or a nominal amount. Click Use Credit to proceed. If the cost appears unexpectedly high, contact your IT administrator before paying - the pricing configuration may need to be verified.

Once you click Use Credit or Pay Online and the payment is processed, your order is submitted. You will be taken to the Order Confirmation screen and will receive a confirmation email. Do not close the browser immediately - wait for the confirmation screen to load.

PHASE 2 - POST-SUBMISSION: WHAT HAPPENS AFTER YOU PAY

Immediately After Payment - The Order View Screen in CERTInext

What you see: The "Certificates :: Orders > View Order" page opens automatically after payment. This page shows the complete record of your order.

The Order Header Bar

At the very top of the page, a summary bar shows:

Item

What It Means

Order ID

A unique number for your order (e.g., 1184216685). Keep this for your records and for any support queries.

Ordered Date

The date and time your order was placed (e.g., 25 May 2026, 15:13).

Product

The certificate you ordered (e.g., DV SSL Certificate).

Group

Your organisation's account name (e.g., ABC Group).

CA Source

The issuing CA: emSign or any CA

Certificate Price

The total amount charged in USD

Order Status

Shows "Order Accepted" in an orange badge - this means your payment was received and the order is in the system, but it still needs internal approval within your CERTInext account before proceeding to the CA.

Certificate Status

Shows "Pending for Approver" in an orange badge - this means your organisation's CERTInext account administrator must review and approve the order before emSign begins processing it.

⚠️ Important - Pending for Approver: In enterprise CERTInext accounts, every new certificate order must be approved by an Account Administrator before it is forwarded to emSign. If you are the Administrator, you can approve it yourself from this page using the 3-dot menu (⋮) in the top-right corner. If you are not the Administrator, contact your IT department or CERTInext account manager and ask them to approve Order ID [your order number].

What the Rest of the Order View Page Shows

The page is divided into several information panels:

SSL Subscription Information:

• Subscription For: 1 year

• Subscription Start Date / End Date: Shown as "–" (dashes) at this stage because the certificate has not yet been issued

• Subscription Status: Pending (orange) - will change to Active once issued

Auto-Renewal Configuration:

• Confirms that auto-renew is set to Yes, triggering 15 days before expiry

Certificate Information:

• Shows your domain name

Certificate Requestor Information:

• Confirms Name, Email, and Mobile Number from Step 3

Certificate Signing Request (CSR) Information:

• CN: Your domain name (from the CSR)

• Key Size: 2048 (standard - this is the strength of your encryption key)

• Key Algorithm: RSA (standard encryption algorithm)

Ordered By:

• Shows the name of the user who placed the order and their role (e.g., Administrator)

Renewal Notifications:

• Send email notifications: Yes - you will receive reminder emails before the certificate expires

Reissue History:

• "No records found" - as expected for a brand-new order

📌 The 3-dot menu (⋮) in the top-right corner of the order page gives Administrators access to: Track Order (generate public tracking URL), Download Invoice, Replace CSR, Recall Request, and Cancel Order.

Email 1 - Order Confirmation: "Your Order is Successful"

What you see: Shortly after payment, you receive an email at the Requestor Email ID you provided in Step 3.

Email Subject: ORDER #[your order ID] - Your Order is Successful

Email Content:

Field

Value

Greeting

Dear [Your Name], / Your order is placed successfully.

Order ID

Your unique order number (e.g., 1184216685)

Ordered Date

Date and time of the order in UTC (e.g., 25-May-2026 09:43 (UTC))

Product & Validity

DV SSL Certificate

Identifier

The domain name secured by this certificate

Subscription For

1 Year(s)

The orange "Track Order" button in the email is your key to the next stage. Clicking it takes you to the emSign Subscriber Portal - a separate web page where you complete the remaining steps: domain validation and certificate download.

⚠️ Do not ignore this email. The Track Order link is how you complete the domain validation step. Without completing domain validation, your certificate cannot be issued.

📌 Check your spam/junk folder if you do not see this email within a few minutes of payment. The email is sent from emSign (emudhra.com domain). Add the sender to your safe senders list to avoid future emails going to spam.

Contact details at the bottom of the email:

The email shows a support email address and phone number. Use these if you need help.

The emSign Subscriber Portal - Your Order Tracking Hub

What you see: Clicking the "Track Order" button in the confirmation email opens the emSign Subscriber Portal - a dedicated, public-facing page that guides you through the remaining steps to get your certificate issued.

Page Header: "Hello [Your Name], Please follow the instructions and complete the below verification steps to speed up your certificate issuance process."

The Four Order Actions

This page shows four steps that must be completed, in the Order Actions section:

#

Action

Status at This Stage

1. Submit CSR

Confirming your CSR has been provided

✅ Completed (green)

2. Subscriber Agreement

Confirming you accepted the subscriber agreement at payment

✅ Completed (green)

3. Domain Verification

Proving to the CA that you own/control the domain

🟠 Awaiting Customer Action (orange) - you must complete this

4. Certificate Download

Downloading the issued certificate

🟠 Issuance Pending (orange) - will be available once Step 3 is done

The Order Details Sidebar (right side of page)

Item

What It Shows

Date Ordered

Date you placed the order

Order ID

Your unique reference number

Product & Validity

DV SSL Certificate

Domain Name

The domain being secured (truncated)

Order Status

Order Accepted

Certificate Status

Pending for Approver

📌 InCommon Users: The emSign Subscriber Portal is the same for all users, including InCommon. The domain verification step is required regardless of your InCommon membership - all certificates require you to prove domain control.

📌 You can always come back to this page by clicking the Track Order button in the confirmation email, or by generating the tracking URL from within CERTInext (3-dot menu → Track Order).

Completing Domain Verification (Step 3 on the emSign Portal)

What you see: Clicking on the "3. Domain Verification" row (or the "+" expand icon on the left) expands a section showing your domain and the domain validation controls.

What You See When Expanded

• Total Domains: 1 - confirms one domain needs to be validated

• Under Domain Control Validation (DCV), your domain name is listed with two buttons:

– CAA - for checking the Certification Authority Authorisation record (advanced, typically for IT teams)

– Verify - the button you click to start domain validation

DCV Instructions (shown on the page):

"A Domain Control Validation or DCV must be completed before issuing an SSL/TLS certificate."

"Please click 'Verify Domain' against each domain name to select a DCV method and prove control over each domain."

"In case of Multi-Domain SSL Certificates, if the authorised domain name (base domain) ownership is proven then all the sub-domains that have the same base domain name will be proven automatically."

How to Start - Click the "Verify" Button

Click the orange "Verify" button next to your domain name. A popup window opens, titled:

"Domain Control Validation ([your domain]) – #[Order ID]"

⚠️ Note shown in the popup: "This is technical in nature (if you are not the right person, please contact your IT / Domain administrator)."

If you are not the person who manages your domain's DNS or web server, stop here and forward the tracking URL to your IT or domain administrator and ask them to complete the domain verification step.

Choosing a DCV Method

The popup shows a DCV Method dropdown with options. The two main methods are:

Method 1: DNS TXT Record (Most Preferred - Recommended)

Select "DNS TXT Record (Most Preferred)" from the DCV Method dropdown.

The popup shows a table with a record to add to your DNS:

Record Type

Host

Value

TXT

Your domain name

A unique alphanumeric token (e.g., 5A27BFFF4R95F80945F8D5491A8FFC98)

Both the Host and Value fields have "Copy" buttons next to them - click these to copy the exact values.

Step-by-step instructions:

1. Log in to your domain registrar or DNS provider (e.g., GoDaddy, Cloudflare, Namecheap, Google Domains).

2. Navigate to the DNS Management section for your domain.

3. Add a new TXT record with:

– Host/Name: Copy the Host value from the popup (it may be your full domain name or just @ depending on your provider)

– Value/Content: Copy the long alphanumeric token from the popup

– TTL: Set to the minimum available (e.g., 300 seconds / 5 minutes) for fastest propagation

4. Save the DNS record.

5. Wait 5–30 minutes for the DNS record to propagate (may take up to 48 hours in rare cases).

6. Return to the popup and click "Verify Now" (orange button).

7. If successful, the popup confirms domain ownership.

📌 InCommon Users: The DNS TXT record method is the most reliable and is recommended for InCommon institutional certificates. If your domain is managed by your institution's IT department, provide them with the Host and Value shown in the popup and ask them to add the TXT record.

Method 2: HTTP/HTTPS File-Based Validation

Select "HTTP/HTTPS File-based" from the DCV Method dropdown.

⚠️ Note shown in the popup: "File-based (HTTP/HTTPS URL) DCV method can only be used to prove domain ownership over Fully Qualified Domain Names (FQDNs), exactly as named. In case you wish to have it work for both www and without www, we recommend you to use alternate DCV methods."

Recommendation: Use DNS TXT Record instead unless you have a specific reason to use file-based validation.

The popup shows a table with the file details:

Item

Detail

File Name

A specific filename (e.g., 084984170207f94FB0482A1A70BF9A82.txt) - with a Copy button

File Content

A unique token string (e.g., 30924A299885503882D10144825CD4F5) - with a Copy button

Step-by-step instructions:

1. The popup also provides a "Download file" link - click it to download the ready-made .txt file (saves you creating it manually).

2. Upload the downloaded file to your web server at exactly this path:

http://[yourdomain.com]/.well-known/pki-validation/[filename].txt

The full directory path is shown in the popup for convenience - copy it.

3. Do not change the filename or its contents. The file must be accessible at the exact URL shown.

4. Once the file is uploaded and accessible, click "Verify Now" in the popup.

How to upload the file: Use an FTP client (e.g., FileZilla), your hosting control panel's File Manager (cPanel, Plesk), or ask your hosting provider.

⚠️ Important: Verify that the file is publicly accessible before clicking Verify Now. Open the URL in a browser - if the file downloads or displays the token text, it is accessible. If you see a 404 error, the file is not in the right location.

After Domain Verification Succeeds

Once you click Verify Now and the CA confirms your domain control, a green success popup appears:

"Thank you for proving the domain ownership for [your domain]. Domain Verification is completed successfully. Please track your order and complete your pending actions to speed up the certificate issuance process."

Click OK to dismiss the popup.

The Order Actions list now updates:

#

Action

1. Domain Verification

✅ Completed (green)

2. Submit CSR

✅ Completed (green)

3. Subscriber Agreement

✅ Completed (green)

4. Certificate Download

🟠 Issuance Pending (orange)

The Certificate Status in the right sidebar still shows "Pending for Approver" at this point - the internal Administrator approval in CERTInext is still required before the certificate is fully issued.

⚠️ Reminder about Administrator Approval: Even after domain verification is complete, the certificate will not be issued until the CERTInext account Administrator approves the order. If the Certificate Status stays on "Pending for Approver" for a long time after domain verification, contact your Administrator.

Certificate Issued - Step 4 Becomes Available

Once both domain verification is complete AND the Administrator has approved the order, emSign issues the certificate. The Order Actions list updates:

#

Action

1. Domain Verification

✅ Completed (green)

2. Submit CSR

✅ Completed (green)

3. Subscriber Agreement

✅ Completed (green)

4. Certificate Download

✅ Certificate Issued (green)

The Order Details sidebar on the right updates to show:

• Order Status: Order Accepted (orange - note this is normal at this stage)

• Certificate Status: Certificate Generated (green) ← This is the key status showing the certificate exists and is ready

Downloading the Certificate (Step 4 on the emSign Portal)

What you see: Expanding the "4. Certificate Download" row shows a green "Certificate Issued" badge and a download message.

The Download Message

The expanded section shows:

"Your certificate has been issued and ready for download. An email containing certificate download instructions has been sent to your email ID ([your email]). In case, if you have not received an email, please click Resend Email button to resend the email. Your certificate is based on the CSR submitted by you. Please ensure to import / use the certificate against the same key-pair, from where the CSR was generated. Please follow the necessary instructions in your download notification email to download your certificate."

Two Buttons

Button

What It Does

Resend Email

Resends the certificate download notification email to your registered email address. Use this if you did not receive the email.

Download Certificate

Directly downloads the certificate from this page (without needing the email link).

Email 2 - Certificate Ready: "Your Certificate is ready for download"

What you see: A second email arrives at your Requestor Email ID.

Email Subject: ORDER #[your order ID] - Your Certificate is ready for download

Email Content:

Field

Value

Greeting

Dear [Your Name], / Your Certificate is ready for download!

Order ID

Your unique order number

Ordered Date

Date and time in UTC

Product & Validity

DV SSL Certificate

Identifier

Your domain name

The email contains:

• An orange "Download Certificate" button - click it to go directly to the certificate download page

• OR - A URL you can copy and paste into your browser's address bar to reach the download page

📌 Save this email. The download link allows you to access the certificate directly. If you miss it, use the Resend Email button in the emSign Subscriber Portal, or download directly from CERTInext (Certificates → Orders → View → Download).

Certificate Download - Selecting Your Format

Clicking the "Download Certificate" button (from the email or the emSign portal) takes you to the emSign Subscriber Portal download page.

The Download Landing Page

Page message:

"Thanks for completing the necessary steps. Your certificate has been issued and ready for download. To continue further, please click 'Download Certificate'."

The page confirms:

• Order ID

• Product & Validity: DV SSL Certificate

• Domain Name: Your domain

Click the orange "Download Certificate" button on this page.

Choosing the Download Format

A popup appears titled "Select the Format to download" with four options:

Format

What It Is

Best For

DER encoded binary X.509 (.CER)

A binary (machine-readable) format. The file is not human-readable text.

Java applications, some enterprise systems, older Microsoft environments

Base-64 encoded X.509 (.CER)

A text-based format with a .CER file extension.

Windows systems, IIS web server

Base-64 encoded X.509 (.CRT)

A text-based format with a .CRT file extension - same content as .CER, just a different extension.

Apache, Nginx, Linux web servers - the most commonly used format

Zip

A compressed ZIP archive containing multiple certificate files (the certificate, intermediate chain, and optionally root certificate).

When you need all certificate files in one download - recommended if you are unsure which format to choose

📌 Which format should I choose?

- If you use Apache or Nginx (Linux): choose Base-64 encoded X.509 (.CRT)

- If you use Windows IIS or Microsoft environments: choose Base-64 encoded X.509 (.CER) or DER encoded binary

- If you use cPanel or Plesk shared hosting: choose Base-64 encoded X.509 (.CRT)

- If you are unsure: choose Zip - it contains everything and you can use whichever file you need

Select the format and click the Download button. The certificate file saves to your computer.

⚠️ Important: Your certificate file does NOT include your private key. Your private key was created on your server when you generated the CSR - it never left your server. The certificate file and the private key must both be present on your server to enable HTTPS. Never share your private key with anyone.

After Download - The Order is Complete

Back in CERTInext - Final Order Status

After you download the certificate, return to CERTInext and check Certificates → Orders. Click View on your order. The status has now fully updated:

Order Summary bar:

• Order Status: Order Fulfilled (green badge)

• Certificate Status: Certificate Downloaded (green badge)

SSL Subscription Information panel:

• Subscription Start Date: The date and time the certificate was issued (e.g., 25 May 2026, 15:20)

• Subscription End Date: Exactly 1 year later (e.g., 25 May 2027, 15:20)

• Subscription Status: Active (green)

Issuer CA Information:

• Root CA: emSign QA SSL RSA CA – G1

• CA Type: Public

These details confirm your certificate was successfully issued by emSign and is now active.

Installing the Certificate on Your Server

After downloading, you need to install the certificate on your web server. The exact steps depend on your server type:

Apache / Nginx (Linux - most common):

1. Upload the .crt file and the intermediate/chain certificate file to your server.

2. Edit your server's SSL configuration file to point to these files.

3. Restart Apache or Nginx.

4. Test by visiting your site at https://yourdomain.com - the padlock should appear.

Windows IIS:

1. Open IIS Manager.

2. Go to Server Certificates → Complete Certificate Request.

3. Select your downloaded certificate file.

4. Bind the certificate to your website on port 443.

cPanel / Plesk (Shared Hosting):

1. Log in to your hosting control panel.

2. Go to SSL/TLS → Manage SSL Sites or Install Certificate.

3. Paste the Base-64 certificate contents into the Certificate field.

4. Also paste the CA Bundle / Intermediate Certificate contents.

5. Click Install or Save.

📌 Ask for help if needed: Installing a certificate on a server requires server administration access. If you are not your organisation's IT administrator, hand the downloaded certificate file to your IT team and ask them to install it.

Summary - The Complete DV Certificate Journey

Step

Where

Action

Result

1–6

CERTInext

Fill in application wizard & pay

Order submitted; Order Status: Order Accepted

Post-payment

CERTInext

View Order page

Certificate Status: Pending for Approver

Email 1

Your inbox

Receive "Order Successful" email

Contains "Track Order" button

Track Order Portal

emSign Subscriber

See 4 Order Actions

Steps 1 & 2 already complete

Domain Verification

emSign Subscriber

Click Verify → choose DNS TXT or HTTP file method → complete

Domain validated

Admin Approval

CERTInext

Administrator approves the order

Certificate Status moves to Certificate Generated

Email 2

Your inbox

Receive "Certificate Ready" email

Contains "Download Certificate" button

Download

emSign Subscriber Portal or CERTInext

Choose format (.CRT / .CER / Zip) → download

Certificate file saved to your computer

Install

Your web server

Install certificate on server

HTTPS padlock appears on your website

CERTInext

Orders → View

Final check

Order Status: Order Fulfilled; Certificate Status: Certificate Downloaded; Subscription: Active

📌 InCommon Users - Final Note: The complete journey shown above applies equally to InCommon DV SSL certificates. The only differences are: (1) pricing may be zero USD or flat-rate under your institutional agreement, (2) your subscription validity will be 30 days / 89 days / 199 days per certificate issuance, and (3) auto-renew will trigger annually. Contact your institution's IT/PKI administrator if the certificate shows unexpected costs or if the renewal process requires additional institutional approval steps.

Last updated