Ordering EV Certificate - Draft
What Is an EV Certificate?
An Extended Validation (EV) SSL/TLS certificate provides the highest level of identity assurance available for websites. It encrypts all data flowing between a visitor’s browser and your server and prominently displays your organization’s verified identity to visitors.
Unlike Domain Validation (DV) or Organization Validation (OV) certificates, EV certificates require the Certificate Authority (CA) to perform rigorous, multi-step verification of your organization’s legal existence, physical address, operational status, and the authority of the individuals signing and approving the certificate request. This process is governed by strict CA/Browser Forum EV Guidelines.
EV certificates require two authorized individuals from your organization: a Contract Signer (who signs the legal Subscriber Agreement) and a Certificate Approver (who formally authorizes certificate issuance). These can be the same person if they hold the appropriate authority.
The issuance timeline is typically 1–5 business days because the CA must complete full Extended Validation. Once issued, your certificate provides the strongest available browser trust indicators.
1.3 The Two EV Product Variants - At a Glance
CERTInext offers two variants of the EV certificate, each designed for a different hosting scenario:
Feature
Description
EV SSL Certificate
Secures a single primary domain (e.g., yourcompany.com + optionally www.yourcompany.com). Ideal for organizations that need the highest trust level on one website.
EV SSL Certificate UCC
Secures multiple domain names (up to 4 included, expandable) under one certificate. Ideal for organizations with several websites or portals that all require EV-level trust.
Extra Domain Cost (UCC)
EV SSL Certificate: N/A | EV SSL Certificate UCC: $126 per domain beyond 4
DCV Verifications
EV SSL Certificate: 1 | EV SSL Certificate UCC: One per domain
Interim DV Certificate
EV SSL Certificate: Not applicable | EV SSL Certificate UCC: Issued automatically after DCV; precedes the full EV certificate
Phase 2 Order Actions
EV SSL Certificate: 7 actions | EV SSL Certificate UCC: 8 actions (includes Interim DV Certificate action)
Wildcard Domains
Not supported on EV certificates (CA/Browser Forum policy)
Choosing the Right EV Product
Use EV SSL Certificate if you need the highest identity assurance on exactly one domain.
Use EV SSL Certificate UCC if you need EV-level trust across multiple distinct domains (e.g., companyportal.com + companyshop.com + companyintranet.com).
Note: Wildcard domains (*.domain.com) are NOT permitted on EV certificates under CA/Browser Forum rules.
1.4 Prerequisites - Before You Begin
Have the following ready before starting an application:
Field / Option
What It Is
What To Do
CERTInext account
Log in at your organization’s CERTInext portal URL. Your administrator provides login credentials.
Log in before starting. Confirm you have permission to place certificate orders.
Certificate Signing Request (CSR)
A CSR is a block of encrypted text generated on your web server. It contains your public key and basic organizational details. Generate it using your web server software (e.g., OpenSSL, IIS, cPanel) before starting.
Generate using a minimum 2048-bit RSA or 256-bit ECDSA key. Ensure the domain in the CSR matches the domain you will enter in Step 5.
Domain name(s) to secure
Know the exact domain(s) you want the certificate to protect. For EV SSL UCC, list all domains upfront.
Confirm you own and control the domain(s). The CA will verify domain ownership during validation.
Organization details
Full legal organization name, registered address, country, state/province, locality, and postal code -exactly as they appear in official government or business registration records.
Gather from official company registration documents. Mismatches with registry data are the most common cause of EV validation delays.
DUNS Number or Company Registration Number
A 9-digit DUNS number (from Dun & Bradstreet) or local government-issued company registration number. Used for EV organization identity verification.
Find your DUNS number at dnb.com. If your organization doesn’t have one, DUNS registration is free for businesses.
Contract Signer
An authorized individual (e.g., Director, VP, IT Director) with legal authority to sign the Subscriber Agreement on behalf of your organization.
Identify this person before starting. They will receive a signing link by email. Can be the same person as the Certificate Approver.
Certificate Approver
An authorized individual (e.g., CISO, IT Director) with authority to approve EV certificate issuance for your organization.
Identify this person before starting. They will receive an approval link by email. Can be the same person as the Contract Signer.
Account credit or payment method
Sufficient account credit balance or a payment card for the Pay Online option.
Confirm balance or have a payment card ready before proceeding to Step 8.
Access to DNS provider (for DCV)
After payment you must prove domain ownership via DNS. You or your IT/domain administrator will need to create a DNS TXT record at your domain’s DNS provider.
Coordinate with your DNS administrator in advance. For EV SSL UCC, each domain requires its own TXT record.
PHASE 1: Applying for the Certificate in CERTInext
This phase covers the eight-step application wizard inside CERTInext. Click New Certificate in the left navigation panel of CERTInext to begin. You will see a progress bar on the left side showing all eight steps. Steps with a tick mark are completed. You can click Back at any step to return and edit without losing later data.
Step 1 - Choose Product & Validity
This is the first screen you see after clicking New Certificate. You select which EV product to purchase and for how long.

1a. Common Fields (both products)
Field / Option
What It Is
What To Do
Group
Your organization account name in CERTInext. Pre-assigned and cannot be changed here.
No action needed -confirm this is your correct account.
CA Source
The Certificate Authority that will issue the certificate. emsign (eMudhra’s trusted CA) is pre-selected.
Leave as emsign unless your administrator has configured an alternative.
Certificate Type
The category of certificate. SSL/TLS Certificates is pre-selected.
Leave as SSL/TLS Certificates.
Product
The specific EV certificate product you wish to purchase.
Click the dropdown and select the desired EV product: ‘EV SSL Certificate’ for single domain, or ‘EV SSL Certificate UCC’ for multi-domain. See Section 1.3 for guidance.
Subscription For
The validity period: 1 Year, 2 Years, or 3 Years.
Select the appropriate validity period. Note: EV certificates cannot exceed 1 year under CA/Browser Forum rules, but multi-year subscriptions provide continuous coverage through automatic renewal.
Cost
The price for the selected product and validity period (in USD). Auto-calculated.
Review before clicking Next. EV SSL Certificate = $173 for 1 year.
1b. Product-Specific Fields
▶ Product Difference - No. of Domains field
The ‘No. of Domains’ dropdown appears ONLY for EV SSL Certificate UCC. It is not present for EV SSL Certificate.
Field / Option
What It Is
What To Do
No. of Domains (UCC only)
Sets how many domains the certificate will cover. The default and minimum included in the base price is ‘Upto 4’.
Leave at ‘Upto 4’ if you need four or fewer domains. Additional domains beyond 4 can be added in Step 5
Extra SAN note (UCC only)
A note displayed beneath the Cost field informing you of the per-domain cost for SANs beyond the included base.
Note this cost before proceeding. Each extra domain added in Step 5 increases the Grand Total accordingly.
1c. Certificate Features Panel
A blue information panel at the bottom of the screen describes what all EV SSL/TLS certificates include:
• Secures Single, Multiple Domains & Sub Domains
• Domain & Extended Organization Validation
• Average Issuance Timeframe: 1–5 Business Days
• Unlimited Server Licenses
• Strongest SHA2 & ECC Encryption
• Major Browser & Mobile Device Compatibility
• Priority Support
• Automatic Renewal Reminders and Early Renewal Options
IMPORTANT
• EV certificates take 1–5 business days to issue due to rigorous identity verification by the CA. Plan ahead if you have a launch deadline.
• EV certificates cannot exceed 1 year of validity per CA/Browser Forum rules.
After reviewing all fields and the cost, click Next to proceed to Step 2.
Step 2 - Certificate Signing Request (CSR)
A Certificate Signing Request (CSR) is a file you generate on your web server before applying for the certificate. It contains your domain name, organization details, and your public key. The CA uses your CSR to generate your certificate.

IMPORTANT NOTE displayed on screen
The public key and signature algorithm from your CSR are used for certificate generation. Subject details such as Organization, Country, and State are pre-filled from your CSR for convenience but can be edited. The values you submit in the form will be the final values in the issued certificate.
Field / Option
What It Is
What To Do
Skip CSR
An option to bypass CSR submission at this stage if you do not yet have one prepared. The CSR will then need to be provided before the certificate can be issued.
Only use Skip CSR if specifically instructed by your administrator. In most cases, have your CSR ready before starting the application.
Upload CSR (Choose File button)
Upload a CSR file (.csr or .pem) directly from your computer.
Click Choose File, navigate to your saved CSR file, and select it. The CSR text will be loaded automatically.
Paste CSR (text area)
An alternative to file upload -paste the raw CSR text directly into this box.
Copy the full CSR text from your server (including the -----BEGIN CERTIFICATE REQUEST----- and -----END CERTIFICATE REQUEST----- lines) and paste it into this field.
CSR Format - What It Looks Like
A valid CSR begins with: -----BEGIN CERTIFICATE REQUEST-----
Followed by several lines of base64-encoded text.
Ends with: -----END CERTIFICATE REQUEST-----
Ensure you copy the entire block including the BEGIN and END lines.
Key Size Requirement
Your CSR must be generated using a minimum 2048-bit RSA key or 256-bit ECDSA key. Never share your private key -only the CSR (public portion) should be uploaded. Ensure the domain in your CSR matches the domain you will enter in Step 5.
After uploading or pasting your CSR, click Next to proceed to Step 3.
Step 3 - Organization Information
This step collects the legal details of your organization. For EV certificates, these details are verified against official government business registries and must match exactly. They will appear in your issued certificate, visible to your website visitors.

Entering Your Organization Details
Enter the legal details of your organization exactly as they appear in official government records and business registries. These details are used for Extended Validation.
Field / Option
What It Is
What To Do
Organization Name *
The full legal name of your registered business or institution.
Enter your organization’s exact legal name as registered with the government (e.g., “ABC Corporation Inc.”). Do not use abbreviations.
Organization Unit
The department or division within your organization responsible for this certificate (optional).
Enter a department name (e.g., “Information Technology”, “Web Services”), or leave blank.
Business Category *
The legal classification of your organization.
Select the option that best matches: Private Organization (most companies), Government Entity, Business Entity, or Non-Commercial Entity.
Street Address 1 *
The first line of your organization’s official registered address.
Enter the building number and street name of your registered office.
Street Address 2 *
The second line of your organization’s address.
Enter the suite, floor, or additional address detail (e.g., “Suite 400”, “Time Square Building”).
Country *
The country where your organization is legally registered.
Select from the dropdown. Defaults to United States of America (USA).
State / Province *
The state or province of your registered address.
Select from the dropdown list.
Locality *
The city or town of your registered address.
Enter the city name.
Postal Code *
The ZIP code or postal code of your registered address.
Enter your 5-digit ZIP code or full postal code.
IMPORTANT
• All organization information must match your official legal registration documents exactly -including capitalization and punctuation.
• Use your registered office address, not a P.O. Box or mailing address.
• Discrepancies between entered information and registry data are the most common cause of EV validation delays or rejections.
• For EV certificates, the Organization Name is verified against official business registries and will appear in your certificate.
Pre-validated Organizations
If your organization has been previously validated by the CA, it may appear at the top of the selection list. Selecting it will pre-fill all fields and may allow the CA to skip re-validation, speeding up issuance significantly. New organizations require full Extended Validation.
After entering all organization details and confirming accuracy, click Next to proceed to Step 4.
Step 4 - Organization Representative Information
This step identifies the person who will act as the certificate subscriber -the individual within your organization who is formally requesting this certificate. They will receive a consent email during the verification phase (Phase 2, Action 2).

Field / Option
What It Is
What To Do
Choose User (New / Existing)
Toggle between creating a new user profile or selecting an existing one from your account. New: enter details manually. Existing: select from a pre-existing list.
If this is your first certificate order or the representative is not yet in the system, choose New. Otherwise, choose Existing and select the appropriate user.
Name *
Full name of the organization representative.
Enter the person’s legal first and last name. Do not use nicknames or abbreviations.
Email ID *
The work email address of the representative. A verification consent email will be sent here during Phase 2.
Enter a valid, monitored organizational email address. Must be a work email -not a personal email (Gmail, Yahoo, etc.). Do not use a shared or unmonitored mailbox. The consent link is individual and time-sensitive.
Mobile Number
The representative’s mobile/phone number (optional).
Select the country dial code from the dropdown, then enter the number.
Certificate Download Delegation (Optional)
Use this section if a different person (other than the Organization Representative) should receive notifications when the certificate is ready to download -for example, your web server administrator.
Field / Option
What It Is
What To Do
Contact name (Delegation)
Name of the person delegated to download the certificate.
Enter only if using Certificate Download Delegation.
Email ID (Delegation)
Email address of the delegated downloader.
Enter only if using Certificate Download Delegation. This person will receive the download notification email.
IMPORTANT
• Use official organizational email addresses only. Personal emails are not acceptable for EV certificates.
• The Organization Representative’s email will receive the certificate requester consent email. Ensure this person is available to respond promptly.
• The consent email is addressed to the individual -it should not be forwarded.
After completing the representative’s details, click Next to proceed to Step 5.
Step 5 - Certificate Information
This step shows a summary of your organization’s details (auto-filled, read-only) and collects the domain name(s) the certificate will protect, along with your company registration number.

5a. Organization Summary (Read-Only - All Products)
The top portion of this screen displays the organization details you confirmed in Step 3. These fields are informational only. If any detail is incorrect, click Back to return to Step 3 and correct it before proceeding.
Field
Value shown (example)
Organization Name
Your organization’s legal name (e.g., ABC Corporation Inc.)
Organization Unit
Department name or blank if not specified
Business Category
Private Organization / Government Entity / Business Entity / Non-Commercial Entity
Street Address 1
Registered street address
Street Address 2
Additional address details or blank
Country
Country of registration (e.g., United States of America (USA))
State / Province
State or province (e.g., New York)
Locality
City (e.g., New York)
Postal Code
ZIP/postal code (e.g., 11697)
5b. Domain Name Fields - Differences by Product
▶ Product Difference - Domain Fields
The domain entry section below the organization summary is the key difference between the two EV products. Read the sub-section for your chosen product carefully.
EV SSL Certificate - Single Domain

Field / Option
What It Is
What To Do
Automatically secure ‘www’ variant of websites
A checkbox that, when ticked, instructs the system to also secure the www.yourdomain.com version of your domain automatically, at no extra cost.
Tick this box if your website is accessed both with and without ‘www’ (which is the case for most websites). Leave unticked only if your domain is exclusively accessed without www.
Domain Name *
The single fully-qualified domain name (FQDN) the certificate will protect (e.g., yourcompany.com).
Type the domain name exactly as it should appear in the certificate. Do not include ‘http://’ or ‘https://’. Example: yourcompany.com or portal.yourcompany.com
Company DUNS / Company Registration Number *
A 9-digit DUNS number (Dun & Bradstreet) or local government-issued company registration number. Used for EV organization identity verification.
Enter your 9-digit DUNS number. If you do not have a DUNS number, enter your local government-issued company registration/incorporation number. Find your DUNS at dnb.com -registration is free for businesses.
EV SSL Certificate UCC - Multiple Domains

Field / Option
What It Is
What To Do
Automatically secure ‘www’ variant of websites
Tick to also secure the www variant of the PRIMARY domain automatically.
Tick if applicable for your primary domain. Note: this applies to the primary domain ONLY. Additional domain names do not automatically include their www variant.
Domain Name *
The primary (main) domain name the certificate will protect (domain #1 of your total).
Enter your primary domain name (e.g., yourcompany.com). Do not include ‘https://’ or ‘www.’.
Additional Domain Names *
A multi-entry field where you add all extra domain names beyond the primary domain (domains #2, #3, #4, etc.). Each domain appears as a removable tag.
Click inside the input box and type each additional domain, pressing Enter or clicking the ‘+’ button after each one. You can also click ‘Import additional domain’ to paste or upload a list in bulk. Click ‘x’ on any domain tag to remove it.
Import additional domain (button)
Allows bulk import of multiple domain names at once instead of adding them one by one.
Click to open an import dialog. Paste a list of domain names (one per line) and confirm.
Clear (button)
Removes all entries from the Additional Domain Names list.
Use only if you want to start the domain list from scratch.
Company DUNS / Company Registration Number *
A 9-digit DUNS number or local company registration number.
Enter your DUNS number or company registration number. Same as EV SSL Certificate.
IMPORTANT
• List ALL domains you need secured in a single order. Adding domains post-issuance requires a reissue of the certificate.
• Wildcard domains (e.g., *.yoursite.com) are NOT supported on EV certificates per CA/Browser Forum policy.
• IP addresses cannot be added as SANs for EV certificates.
• The www variant auto-secure option applies to the PRIMARY domain only.
• The total domain count (primary + additional) must not exceed your purchased ‘No. of Domains’ without paying the extra SAN fee ($126 per domain).
After entering all domain name(s) and the registration number, click Next to proceed to Step 6.
Step 6 - Authorized Signatory Information
This step is unique to EV certificates. EV certificates require two specifically authorized individuals from your organization: a Contract Signer (who signs the legal Subscriber Agreement) and a Certificate Approver (who authorizes certificate issuance). These can be the same person if they hold appropriate authority.

6a. Contract Signer Information
The Contract Signer is the individual with authority to enter into legal agreements on behalf of your organization (e.g., Director, VP, authorized officer). They will receive and must electronically sign the eMudhra emSign Subscriber Agreement.
Field / Option
What It Is
What To Do
Same as Organization Representative (checkbox)
Copies the Organization Representative’s details from Step 4 into this section.
Check this box if the same person from Step 4 is also your Contract Signer. The fields will auto-fill.
Choose User *
‘New’ or ‘Existing’ contact.
Select ‘New’ to enter new details, or ‘Existing’ to pick from saved contacts.
Name *
Full legal name of the Contract Signer.
Enter their full name exactly as it appears on official documents.
Email ID *
Work email of the Contract Signer. The Subscriber Agreement signing link will be sent here.
Enter a valid organizational work email. The agreement link is sent to this address. The Subscriber Agreement is a legally binding document -ensure this email reaches the correct authorized person.
Telephone
Contact phone number (optional).
Select country code and enter the full telephone number.
6b. Certificate Approver Information
The Certificate Approver is the individual who gives final authorization for the EV certificate to be issued (e.g., CISO, IT Director, delegated manager). This is an EV-specific requirement under CA/Browser Forum guidelines.
Field / Option
What It Is
What To Do
Same as Contract Signer (checkbox)
Copies the Contract Signer’s details into the Certificate Approver section.
Check this if the same person is both Contract Signer and Certificate Approver (common in smaller organizations).
Choose User *
‘New’ or ‘Existing’ contact.
Select ‘New’ to enter new details, or ‘Existing’ to pick from saved contacts.
Name *
Full legal name of the Certificate Approver.
Enter their full name.
Email ID *
Work email of the Approver. The EV Certificate Request Approval link will be sent here.
Enter a valid organizational work email. Ensure the Approver is available and watching their email.
Telephone
Contact phone number (optional).
Select country code and enter the full number.
IMPORTANT
• The Contract Signer must have legal authority to bind your organization to contractual agreements (e.g., Director, VP, authorized officer).
• The Certificate Approver must have authority to authorize security certificate issuance (e.g., CISO, IT Director, or delegated manager).
• Both roles can be fulfilled by the same person if they hold appropriate authority.
• Do not use external consultants or vendors in these roles.
After completing the authorized signatory details, click Next to proceed to Step 7.
Step 7 - Additional Information (Optional)
This step is the same for both EV products. All fields are optional but some, such as auto-renewal, are pre-configured with sensible defaults.

Field / Option
What It Is
What To Do
Tags
Custom labels you can attach to this order for internal tracking and reporting within CERTInext (e.g., ‘Production’, ‘Project-Alpha’, ‘2026-Q2’).
Click ‘+ Add Tag’, type your tag text, and press Enter. Add multiple tags as needed. Tags are for your internal use only and do not appear on the certificate.
Order Remarks
A free-text notes field for any special instructions or internal references related to this order.
Type any notes relevant to your team or to support if you need to raise a query. This text is visible to the CA and CERTInext administrators.
Technical Point of Contact Information
Checkbox -expands to collect the name, email, and phone number of the technical person responsible for managing this certificate (e.g., the system administrator who will install it).
Tick and fill in only if the technical contact is different from the Organization Representative entered in Step 4. Useful for larger organizations.
KYC Documents
Checkbox -expands to allow you to upload Know Your Customer (KYC) verification documents (e.g., company registration certificate, utility bill, government ID).
Tick and upload documents if the CA requests them or if you want to proactively provide them to speed up the EV verification process.
Additional email recipients
Checkbox -expands to add extra email addresses that should receive certificate-related notifications.
Tick and add email addresses if others in your organization (e.g., a manager, security team) should also receive order status updates and the download notification.
Auto-renew certificates until coverage
Checkbox (ticked by default) -instructs CERTInext to automatically initiate certificate renewal before expiry.
Leave ticked (recommended). Only untick if you want to manage renewals manually. Without auto-renewal, your certificate may expire without notice, causing browsers to show security warnings.
Set renew criteria - Before [N] days of certificate expiry
Configures how many days before expiry the auto-renewal process begins. Default is 15 days.
Click the dropdown to adjust the lead time (e.g., 30 days gives more time for any renewal complications). 15 days is the standard minimum recommended.
Review and adjust any optional settings, then click Next to proceed to the Order Summary.
Step 8 - Order Summary & Payment
The final step before payment. Review everything carefully. A ‘Payment Pending’ badge appears in the top-right corner.

8a. Product Information Panel
Field / Option
What It Is
What To Do
Certificate Type
The category of certificate (SSL/TLS Certificates).
Verify this matches your intended purchase.
Product Name
The specific EV product selected (e.g., EV SSL Certificate or EV SSL Certificate UCC).
Confirm this is the correct product variant.
Validity Period
The subscription duration selected in Step 1 (e.g., 1 Year).
Confirm the correct duration.
Domain Count
The total number of domains the certificate will cover.
For EV SSL Certificate: 1. For EV SSL Certificate UCC: reflects the total number of domains entered in Step 5.
▶ Product Difference - Order Summary for EV SSL Certificate UCC
The Order Summary in Step 8 shows all the following for UCC:
Domain Count: 4 (or your selected number)
domain name: [primary domain]
additional domain names: [all additional domains listed, comma-separated]
Grand Total: $417 (for up to 4 domains, 1 year). Additional SANs beyond 4 = $126 per domain.
8b. Certificate Information Panel
A summary of all organization details and domain name(s) entered across previous steps. Scroll through to verify all values are correct.
8c. Payment Information Panel
Field / Option
What It Is
What To Do
Current Balance
Your organization’s current pre-paid credit balance in USD.
Verify you have sufficient balance if paying by credit. If the balance is less than the Grand Total, use Pay Online instead.
Certificate Price (upto 4) (UCC only)
The base certificate price covering the included number of domains (up to 4).
Informational -auto-calculated.
Additional SAN Cost (UCC only)
The additional cost for any domains beyond the included base quantity. Format shown: ‘$[rate] per [count]’.
Informational. Verify this matches the number of extra domains you added in Step 5.
Grand Total
The final total amount in USD payable for this order.
Verify this matches your expectation before proceeding to payment. EV SSL Certificate = $173 (1 year). EV SSL Certificate UCC = $417 (up to 4 domains, 1 year).
Subscriber Agreement checkbox
A mandatory checkbox confirming you have read and agreed to eMudhra emSign’s Subscriber Agreement.
You MUST tick this checkbox before payment. Click the ‘Subscriber Agreement’ hyperlink to read the full terms if you have not done so.
8d. Payment Buttons
Button
Action
Save and Exit
Saves your application as a draft and exits the wizard. You can return to complete payment later from the Orders list.
Pay Online
Opens a payment gateway to pay the Grand Total using a credit/debit card or other supported online payment method.
Use Credit
Deducts the Grand Total from your organization’s pre-paid credit balance in CERTInext immediately. Order is submitted upon confirmation.
IMPORTANT
• Review ALL information carefully before payment. Once payment is made, changes to domain name or key organization details require a certificate reissue.
• Ensure your domain name and organization name are correct -these appear in the certificate and are visible to your website visitors.
Tick the Subscriber Agreement checkbox, then click either Pay Online or Use Credit to submit your order. After successful payment, you will be taken to the Order View page.
PHASE 2: Post-Submission - What Happens After You Pay
After payment, your order enters a multi-step verification and issuance workflow. For EV certificates, the CA must verify your identity, organization, domain ownership, and organizational authority before issuing the certificate. Most steps require action from you or your authorized signatories.
Two portals are involved
1. CERTInext (certinext.io) -where you placed your order. Use it to track order status.
2. emSign Subscriber Portal -where you and your authorized signatories complete all verification steps.
The emSign portal link is sent to you in the order confirmation email and is also accessible via CERTInext > Certificates > Orders > your order > Track Order Status.
2.1 CERTInext Order View - Immediately After Payment
You are automatically redirected to the Order View page in CERTInext. Bookmark or note the Order ID displayed at the top -you will need it if you contact support.

Field
Meaning
Order ID
Unique reference number for your certificate order. Keep this safe.
Ordered Date
Date and time the order was placed.
Product
The EV certificate product ordered.
Group
Your organization account name.
CA Source
Certificate Authority: emSign.
Certificate Price
Total amount charged for this order (USD).
Order Status
‘Order Accepted’ (orange badge) -the order has been received and accepted for processing.
Certificate Status
‘Pending for Approver’ (orange badge) -the certificate is awaiting verification and issuance steps.
Note - Subscription Dates
Subscription Start Date and Subscription End Date will be blank at this stage. They are populated once the certificate is issued and the subscription becomes Active.
2.2 Order Confirmation Email
Within minutes of payment, the Organization Representative receives an email notification confirming the order was placed successfully.

Email Field
Content
Subject
ORDER #[Order ID] -Your Order is Successful
Order ID
Your unique order reference number
Ordered Date
Date and time (UTC)
Product & Validity
Product name and subscription period
Identifier
The primary domain name secured by this certificate
Subscription Per
e.g., 1 Year(s)
Track Order button
Orange button linking to the emSign Subscriber Portal for your order
Click ‘Track Order’ to open the emSign Subscriber Portal where you will complete the remaining verification actions. You can also access this portal via the link in subsequent notification emails.
Tracking Order Status in CERTInext
In CERTInext, navigate to Certificates > Orders and click your order to view its full details.
Click the three-dot menu (top-right of the order) to open the “Track Order Status” popup. This popup shows a unique Order Status Tracking URL.
“Open URL”: Opens the emSign Subscriber Portal in your browser.
“Share URL”: Sends the tracking link via email to the Organization Representative.
2.3 emSign Subscriber Portal - Order Actions Overview
The emSign Subscriber Portal is the central place where all post-payment verification steps are tracked and completed. Access it via the “Track Order” link in your confirmation email.
The portal displays:
• Request Information: Certificate Requester, Contract Signer, and Certificate Approver details
• Order Details panel (right side): Date, Order ID, Product, Domain, Order Status, Certificate Status
• Order Actions: A numbered list of all verification steps required for certificate issuance

The Order Actions
▶ Product Difference - Number of Order Actions by Product
EV SSL Certificate has 7 Order Actions.
EV SSL Certificate UCC has 8 Order Actions (adds Action 7: Interim DV Certificate).
Action
Name and Description
Action 1. Submit CSR
Confirms your CSR was accepted. Auto-completed if you submitted a CSR in Step 2. Only pending if you selected “Skip CSR”.
Action 2. Certificate Requester Verification
The Organization Representative confirms they authorized this certificate request. A consent email is sent to their email address.
Action 3. Subscriber Agreement
The Contract Signer electronically signs the emSign Subscriber Agreement -the legal contract between your organization and the CA.
Action 4. EV Certificate Request Approval
The Certificate Approver gives formal institutional authorization for EV certificate issuance. Mandatory for all EV certificates.
Action 5. Organization Verification
The CA verifies that your organization is a real, legally registered entity. May be automatic or require a Verified Professional Letter (VPL).
Action 6. Domain Verification (DCV)
You prove to the CA that your organization controls the domain(s) on the certificate. Required before certificate issuance.
Action 7 (UCC only). Interim DV Certificate
EV SSL Certificate UCC only: a temporary DV-level certificate is automatically issued after domain verification, while EV organization checks are finalized.
Action 7 (EV SSL) / Action 8 (EV SSL UCC). Certificate Download
Available once all other steps are complete. The CA issues your certificate and it becomes available for download.
Action Status Colors
Green = Completed. Orange = Awaiting Customer Action (you must do something).
‘Issuance Pending’ (orange) on the final certificate action means the CA is still processing -no action needed yet.
Certificate Status in the right panel shows the overall progress: ‘Pending for Approver’ → ‘Approved’ → ‘Certificate Generated’.
Use the Resync button (circular arrow icon) next to any action to refresh its status or resend notification emails.
2.4 Action 1: Submit CSR
If you uploaded or pasted your CSR in Step 2 of the application, this action is automatically marked Completed. No action is needed.
If you selected “Skip CSR” during application, this step shows as pending. You must submit your CSR here before the certificate can be issued.
• Click the “+” to expand Action 1.
• Paste or upload your CSR in the provided field.
• Click Submit.
2.5 Action 2: Certificate Requester Verification
The Organization Representative (Certificate Requester from Step 4) must confirm they authorized this certificate request. This is a consent step required for all EV SSL certificates.
2.5a Consent Required Email
The Organization Representative receives an email with the subject: ‘ORDER #[ID] -Certificate Requester consent required for SSL EV request’.

• Click the orange “Click here to provide consent” button in the email.
2.5b emSign Consent Page

• Review the Order Details and Organization Details on the page.
• Read the consent statement: “Accepting this consent means that you confirm your certificate request.”
• Click “Approve” to confirm, or “Reject” to decline.
• A confirmation popup appears: “Are you sure you want to accept the consent?” -Click “Yes”.
2.5c Consent Accepted Confirmation
Success: “Thank you for completing the pending actions. This would help us to speed up the certificate issuance process.”
• Click “Proceed for Verification” to return to the full Order Actions list.

IMPORTANT
• The consent email may land in the spam/junk folder. Check there if not received within 15 minutes.
• If the consent link has expired, use the Resync button (circular arrow) next to Action 2 in the portal to send a new consent email.
• The consent email is addressed to the individual -it should not be forwarded.
2.6 Action 3: Subscriber Agreement
The Contract Signer (from Step 6) must electronically sign the eMudhra emSign Subscriber Agreement -the legal contract between your organization and the Certificate Authority.
2.6a Agreement Email
The Contract Signer receives an email with the subject: ‘ORDER #[ID] -Sign Subscriber Agreement for EV SSL Request’.

• Click the orange “Agreement Link” button in the email.
2.6b emSign Subscriber Portal - Subscriber Agreement Page

• Review the full Subscriber Agreement document (10 pages) displayed on screen.
• On the right panel, complete the Accept Agreement form:
◦ Your Name: Pre-filled with the Contract Signer’s name. Verify it is correct.
◦ Place: Enter the city/location where you are signing (e.g., “New York”).
◦ Email ID: Pre-filled and masked for privacy. Verify the masked email is correct.
◦ Check box: “I am the authorized person to sign this agreement.”
◦ Check box: “I agree to all the terms & conditions of this agreement.”
◦ Click “Accept Agreement” (both checkboxes must be ticked first).
Success: “Thank you for providing your consent and completing the Subscriber Agreement step successfully.”
IMPORTANT
• Read the Subscriber Agreement carefully -it is a legally binding document.
• The Place field should reflect your actual current location, not your company’s registered address.
• Both checkboxes are mandatory. The “Accept Agreement” button remains inactive until both are checked.
• Once signed, the agreement cannot be revoked without cancelling the order.
2.7 Action 4: EV Certificate Request Approval
The Certificate Approver (from Step 6) must give final authorization for the EV certificate issuance. This step is mandatory for all EV certificates under CA/Browser Forum rules.
2.7a Approval Email
The Certificate Approver receives an email with the subject: ‘ORDER #[ID] -Approve SSL EV Certificate request’.

• Click the orange “Approve EV Certificate request” button in the email.
2.7b emSign Subscriber Portal - EV Certificate Approval Page

• Review Order Details (Order ID, Date, Ordered By, Domain, Certificate Requester Name/Email).
• Review Organization Details (Organization Name, Domain).
• Under “Approve SSL EV request”, click the orange “Approve” button (or “Reject” if there is an issue).
• A confirmation popup asks: “Are you sure you want to approve the SSL EV certificate request?” -Click “Yes”.
Success: “Thank you for approving the SSL EV certificate request successfully.”
IMPORTANT
• The Approver’s action is a formal institutional authorization. Ensure the Approver reviews the domain and organization details before approving.
• If the Approver has not received the email, use the Resync button next to Action 4 in the portal.
2.8 Action 5: Organization Verification
The CA verifies that your organization is a real, legally registered entity. This is the most detailed verification step for EV certificates. The CA first attempts automatic verification using public business registries.
2.8a Automatic Verification
If the CA can verify your organization automatically through public business registries, this step completes without any action from you -it will simply move to “Completed”. Only if automatic verification cannot confirm your organization will a Verified Professional Letter (VPL) be requested.
2.8b Verified Professional Letter (VPL)
If automatic verification fails, the CA will request a Verified Professional Letter.
Step A -Email requesting VPL:

• Subject: ORDER #[ID] -Submit Verified Professional Letter for SSL EV request
• The email explains that the CA could not verify your organization through public sources and requests a VPL.
• Click the orange “Submit Verified Professional Letter” button.
Step B -VPL Upload Form in emSign Portal:
The VPL is an official letter on your organization’s letterhead (or from a legal authority) that establishes your organization’s identity. It should confirm: Legal name, DBA name (if applicable), Physical address, Contract Signer authority, and Certificate Approver authority.

Field / Option
What It Is
What To Do
Organization Name
Auto-filled with your organization’s name. Read-only.
No action needed. Verify it displays your correct organization name.
Document Source *
Describes the origin or type of the letter.
Enter a brief description of the document source (e.g., “Company Official Letterhead”, “Notarized Business Registration Document”).
Document (PDF only) *
The actual VPL file to upload. Platform accepts PDF files only.
Click “Choose File”, select your VPL PDF file, and confirm the upload. Ensure the file is not password-protected.
Document Description *
A brief description of what the document contains.
Enter a short description (e.g., “Professional letter verifying ABC Inc legal registration and authorized signatories”).
Issuer Name *
Full name of the person who prepared or signed this letter.
Enter the full name of the attorney, notary, company officer, or authorized professional who issued the letter.
Issuer Email ID *
Email address of the person who issued the letter.
Enter a valid work email address for the Issuer. The CA validation agent may contact them to verify the letter.
Issuer Contact No. *
Phone number of the Issuer.
Select the country code and enter the full phone number. The CA may call to verify the letter.
• Click “Submit For Verification” to submit the VPL.
Success: “Thank you for submitting the Legal Option Letter for [organization] successfully.”
2.8c Organization Authentication Code
After the VPL is reviewed, the CA sends an Organization Authentication Code to the email address publicly listed for your organization (from public registries such as WHOIS or business databases).
Two emails are sent simultaneously:
• An email to the publicly listed organizational contact containing the 6-digit Authentication Code.
• An email to the Organization Representative containing a Verification Link to the emSign portal where the code must be entered.


Step C -Entering the Authentication Code:

• Click the link in the Verification Link email.
• On the emSign portal page, enter:
◦ Organization Authentication Code: Enter the 6-digit code received by the public registry contact.
◦ Designation: Enter your job title at the organization (e.g., “IT Manager”, “Systems Administrator”).
• Click “Submit”.
Success: “Thank you for submitting the organization authentication code for [organization] and completing the verification successfully.”
IMPORTANT
• The authentication code is sent to the publicly listed organizational contact -not necessarily to you. Coordinate internally with whoever receives that email to obtain the code.
• The code expires in 24 hours. If it expires, use the Resync button next to Action 5 in the portal to trigger a new code.
• Your Designation must reflect your actual role at the organization.
2.9 Action 6: Domain Control Validation (DCV)
Domain Control Validation is the process by which you prove to the Certificate Authority that you genuinely control each domain on your certificate. This is mandatory for ALL SSL/TLS certificates before issuance.
2.9a Domain List
When you expand Action 6 (Domain Verification), you see:
• ‘Total Domains: [N]’ -the count of domains requiring verification.
• Each domain listed with a status icon (orange warning = pending, green = verified) and a ‘Verify’ button.
• For EV SSL Certificate: 1 domain to verify.
• For EV SSL Certificate UCC: one entry per domain -you must verify each domain individually.
▶ Product Difference - Multiple DCV for EV SSL Certificate UCC
EV SSL Certificate UCC requires domain verification for EVERY domain listed on the certificate.
Total Domains: Shows the total count (e.g., “Total Domains: 4”).
Each domain is listed individually with its own status icon, “CAA” button, and “Verify” button.
DCV must be initiated and completed for each domain separately by clicking “Verify” next to each one.
If the authorized domain name (base domain) ownership is proven, all sub-domains that have the same base domain name will be proven automatically (e.g., proving xyz.com automatically proves blog.xyz.com). Note: the reverse is NOT allowed.

2.9b DCV Method - DNS TXT Record (Recommended)
Click the ‘Verify’ button next to a domain. A modal dialog appears.

Technical Note
The DCV modal includes a note: “This is technical in nature. If you are not the right person, please contact your IT / Domain administrator.” If you do not manage your DNS records yourself, forward the TXT record details (Host and Value) to your DNS administrator and ask them to create the record.
Field / Option
What It Is
What To Do
DCV Method dropdown
The method used to prove domain ownership. ‘DNS TXT Record (Most Preferred)’ is the recommended and pre-selected method.
Leave as ‘DNS TXT Record (Most Preferred)’ unless your DNS provider does not support TXT records.
Record Type
The type of DNS record to create: TXT.
Always TXT for this method.
Host
The hostname for the DNS TXT record. This is the domain name itself (Copy button available).
Copy this value exactly. Log in to your DNS provider’s management panel, navigate to DNS settings for this domain, and use this as the Host/Name field when creating the TXT record.
Value
The unique verification token that must be entered as the TXT record’s value (Copy button available).
Copy this token exactly. Enter it as the Value/Content of the new TXT record at your DNS provider. Do not add any extra spaces or characters. For UCC: each domain gets its own unique Host and Value -do not reuse values between domains.
Verify Now button
Triggers the CA’s system to check your DNS for the TXT record.
ONLY click Verify Now after you have saved the DNS TXT record at your DNS provider AND allowed sufficient time for DNS propagation (15–30 minutes minimum, up to 48 hours).
Close button
Closes the modal without verifying.
Click Close if you need to set up the DNS record first and return to verify later.
InCommon Note - DNS Propagation
After creating the DNS TXT record at your DNS provider, changes may take anywhere from a few minutes to 48 hours to propagate globally (depending on your DNS TTL settings). It is best practice to wait at least 15–30 minutes before clicking ‘Verify Now’. If verification fails, wait longer and try again. Do not delete the TXT record until verification succeeds.
2.9c Domain Verification Success

After successful verification, a success popup appears: “Thank you for proving the domain ownership for [domain]. Domain Verification is completed successfully.”
Click OK to dismiss. The domain’s status icon turns green.
For EV SSL Certificate UCC: repeat the Verify process for each remaining domain until all show green / Completed.
2.10 Action 7: Interim DV Certificate (EV SSL Certificate UCC Only)
▶ Product Difference - Action 7 is unique to EV SSL Certificate UCC
This action does NOT appear for the standard EV SSL Certificate.
No action is required from you. Once all domain verifications (Action 6) are complete, the system automatically processes and issues the Interim DV Certificate.
Monitor this step’s status in the portal. It will move from “Issuance Pending” to “Completed” automatically.
An Interim Domain Validated (DV) Certificate is a temporary, basic certificate issued once domain verification is complete, before the full EV organization validation is finalized. It provides DV-level HTTPS coverage for your domains while the CA completes the Extended Validation checks (organization verification, approver confirmation, etc.).
[SCREENSHOT: emSign Portal -Interim DV Certificate (Action 7) -Issuance Pending]
What happens next:
• Once the Interim DV Certificate is issued, you may optionally install it on your server for immediate basic HTTPS coverage.
• The full EV Certificate (Action 8) will be issued after all remaining EV-specific verifications are approved.
• When the full EV Certificate is issued, replace the Interim DV Certificate on your server with the EV certificate.
IMPORTANT
• The Interim DV Certificate is NOT the final EV Certificate. Do not consider your EV order complete until the full EV Certificate (Action 8) is issued.
• The EV Certificate provides the highest browser trust indicators. The Interim DV Certificate does not.
• Replace the Interim DV Certificate with the full EV Certificate promptly once it is issued.
2.11 Certificate Issuance & Download
Once all Order Actions are marked Completed, the CA processes and issues the certificate. This typically happens automatically within minutes to a few hours of the final action being completed. No action is required from you at this stage.
2.11a Download Notification Email
The Organization Representative receives an email with the subject: ‘ORDER #[ID] -Your Certificate is ready for download’.
[SCREENSHOT: Email -Certificate Ready: ‘ORDER #[ID] -Your Certificate is ready for download’]
• The email contains Order ID, Ordered Date, Product & Validity, and the Identifier (domain).
• It includes an orange “Download Certificate” button linking to the emSign Subscriber download page.
• Click the “Download Certificate” button in the email. This opens the emSign Subscriber download page.
2.11b emSign Subscriber Portal - Certificate Download Page
[SCREENSHOT: emSign -Certificate download page showing Order ID, Product, Domain Name and Download Certificate button]
The download confirmation page shows:
• A green tick with: “Thanks for completing the necessary steps.”
• “Your certificate has been issued and ready for download. To continue further, please click Download Certificate.”
• Order ID, Product & Validity, and Domain Name details.
• Orange “Download Certificate” button.
2.11c Certificate Download in Order Actions
Expanding the final Certificate Download action in the Order Actions list reveals the following:
[SCREENSHOT: emSign Subscriber Portal -Certificate Download (expanded panel with Resend Email and Download Certificate buttons)]
Text shown in expanded panel
Your certificate has been issued and ready for download. An email containing certificate download instructions has been sent to your email ID. In case you have not received an email, please click Resend Email to resend the email. Your certificate is based on the CSR submitted by you. Please ensure to import / use the certificate against the same key-pair, from where the CSR was generated.
Button
Action
Resend Email
Re-sends the download notification email to the Organization Representative’s email address. Use this if the original email was not received.
Download Certificate
Initiates the certificate download directly from the portal, bypassing the email.
IMPORTANT
• CRITICAL: Your certificate MUST be installed with the matching private key. If you have lost your private key, you will need to generate a new CSR and request a reissue.
• After installation, verify your certificate using SSL Labs (ssllabs.com/ssltest) to confirm it is correctly installed and trusted by major browsers.
• EV certificates display the organization’s name in the browser address bar -confirm this appears correctly after installation.
• For EV SSL Certificate UCC: the issued certificate file contains Subject Alternative Name (SAN) entries for ALL your domains. You install ONE certificate file that covers all domains simultaneously.
2.11d Selecting the Download Format
When initiating a download from CERTInext, a ‘Select the Format to download’ dialog appears with four options:
Field / Option
What It Is
What To Do
DER encoded binary X.509 (.CER)
Binary format of the certificate. Compact and widely supported by Windows systems and Java keystores.
Choose this for Windows Server (IIS) or Java-based servers.
Base-64 encoded X.509 (.CER)
Text-based (PEM) format of the certificate, saved with the .CER extension. Readable in a text editor.
Choose this for most Linux/Unix-based servers (Apache, Nginx), or when your server software requests a .CER file.
Base-64 encoded X.509 (.CRT)
Identical content to the Base-64 .CER above but saved with the .CRT file extension.
Choose this when your server software (e.g., Apache, Nginx) expects a .crt file extension.
Zip
A ZIP archive containing the certificate along with any intermediate/chain certificates. Recommended for most installations.
Choose Zip if you are unsure, or if your server requires the full certificate chain. Extract the ZIP and follow your server’s installation guide.
Which Format to Choose
If in doubt, choose Zip -it includes all necessary certificate files (end-entity certificate + intermediate certificates/chain). Your web server administrator will know how to handle the extracted files. For quick Windows inspection, choose DER or Base-64 .CER.
2.12 CERTInext Order View - Final State
After the certificate is downloaded, the Order View in CERTInext updates to its final state. Navigate to Certificates > Orders and click your order to view this screen.
[SCREENSHOT: CERTInext Order View -Final state (Order Fulfilled / Certificate Downloaded status)]
Field
Final Value
Order Status
Order Fulfilled (green)
Certificate Status
Certificate Downloaded (green)
Subscription Status
Active (green)
Subscription Start Date
Date the certificate was issued
Subscription End Date
Expiry date (Start Date + validity period, e.g., 1 year)
2.12a Order Action Menu (⋯ Button)
In the top-right corner of the Order View, a three-dot menu icon (⋯) provides additional actions depending on the certificate type.
[SCREENSHOT: CERTInext Order View -Action menu open (⋯ button, showing available options)]
Action
Available For
Download Invoice
All products
Track Order
All products
Download Certificate
All products
Reissue Certificate
All products
Add / Remove SANs
EV SSL Certificate UCC only
Revoke Certificate
All products
Reissue vs. Revoke
Reissue creates a replacement certificate (useful when you change your server or CSR). The old certificate is revoked as part of reissuance.
Revoke permanently deactivates the certificate without replacement -only use Revoke if you are decommissioning the service or the key has been compromised and you will not replace it.
Last updated
