For the complete documentation index, see llms.txt. This page is also available as Markdown.

Ordering EV Certificate - Draft

What Is an EV Certificate?

An Extended Validation (EV) SSL/TLS certificate provides the highest level of identity assurance available for websites. It encrypts all data flowing between a visitor’s browser and your server and prominently displays your organization’s verified identity to visitors.

Unlike Domain Validation (DV) or Organization Validation (OV) certificates, EV certificates require the Certificate Authority (CA) to perform rigorous, multi-step verification of your organization’s legal existence, physical address, operational status, and the authority of the individuals signing and approving the certificate request. This process is governed by strict CA/Browser Forum EV Guidelines.

EV certificates require two authorized individuals from your organization: a Contract Signer (who signs the legal Subscriber Agreement) and a Certificate Approver (who formally authorizes certificate issuance). These can be the same person if they hold the appropriate authority.

The issuance timeline is typically 1–5 business days because the CA must complete full Extended Validation. Once issued, your certificate provides the strongest available browser trust indicators.

1.3 The Two EV Product Variants - At a Glance

CERTInext offers two variants of the EV certificate, each designed for a different hosting scenario:

Feature

Description

EV SSL Certificate

Secures a single primary domain (e.g., yourcompany.com + optionally www.yourcompany.com). Ideal for organizations that need the highest trust level on one website.

EV SSL Certificate UCC

Secures multiple domain names (up to 4 included, expandable) under one certificate. Ideal for organizations with several websites or portals that all require EV-level trust.

Extra Domain Cost (UCC)

EV SSL Certificate: N/A | EV SSL Certificate UCC: $126 per domain beyond 4

DCV Verifications

EV SSL Certificate: 1 | EV SSL Certificate UCC: One per domain

Interim DV Certificate

EV SSL Certificate: Not applicable | EV SSL Certificate UCC: Issued automatically after DCV; precedes the full EV certificate

Phase 2 Order Actions

EV SSL Certificate: 7 actions | EV SSL Certificate UCC: 8 actions (includes Interim DV Certificate action)

Wildcard Domains

Not supported on EV certificates (CA/Browser Forum policy)

Choosing the Right EV Product

Use EV SSL Certificate if you need the highest identity assurance on exactly one domain.

Use EV SSL Certificate UCC if you need EV-level trust across multiple distinct domains (e.g., companyportal.com + companyshop.com + companyintranet.com).

Note: Wildcard domains (*.domain.com) are NOT permitted on EV certificates under CA/Browser Forum rules.

1.4 Prerequisites - Before You Begin

Have the following ready before starting an application:

Field / Option

What It Is

What To Do

CERTInext account

Log in at your organization’s CERTInext portal URL. Your administrator provides login credentials.

Log in before starting. Confirm you have permission to place certificate orders.

Certificate Signing Request (CSR)

A CSR is a block of encrypted text generated on your web server. It contains your public key and basic organizational details. Generate it using your web server software (e.g., OpenSSL, IIS, cPanel) before starting.

Generate using a minimum 2048-bit RSA or 256-bit ECDSA key. Ensure the domain in the CSR matches the domain you will enter in Step 5.

Domain name(s) to secure

Know the exact domain(s) you want the certificate to protect. For EV SSL UCC, list all domains upfront.

Confirm you own and control the domain(s). The CA will verify domain ownership during validation.

Organization details

Full legal organization name, registered address, country, state/province, locality, and postal code -exactly as they appear in official government or business registration records.

Gather from official company registration documents. Mismatches with registry data are the most common cause of EV validation delays.

DUNS Number or Company Registration Number

A 9-digit DUNS number (from Dun & Bradstreet) or local government-issued company registration number. Used for EV organization identity verification.

Find your DUNS number at dnb.com. If your organization doesn’t have one, DUNS registration is free for businesses.

Contract Signer

An authorized individual (e.g., Director, VP, IT Director) with legal authority to sign the Subscriber Agreement on behalf of your organization.

Identify this person before starting. They will receive a signing link by email. Can be the same person as the Certificate Approver.

Certificate Approver

An authorized individual (e.g., CISO, IT Director) with authority to approve EV certificate issuance for your organization.

Identify this person before starting. They will receive an approval link by email. Can be the same person as the Contract Signer.

Account credit or payment method

Sufficient account credit balance or a payment card for the Pay Online option.

Confirm balance or have a payment card ready before proceeding to Step 8.

Access to DNS provider (for DCV)

After payment you must prove domain ownership via DNS. You or your IT/domain administrator will need to create a DNS TXT record at your domain’s DNS provider.

Coordinate with your DNS administrator in advance. For EV SSL UCC, each domain requires its own TXT record.

PHASE 1: Applying for the Certificate in CERTInext

This phase covers the eight-step application wizard inside CERTInext. Click New Certificate in the left navigation panel of CERTInext to begin. You will see a progress bar on the left side showing all eight steps. Steps with a tick mark are completed. You can click Back at any step to return and edit without losing later data.

Step 1 - Choose Product & Validity

This is the first screen you see after clicking New Certificate. You select which EV product to purchase and for how long.

1a. Common Fields (both products)

Field / Option

What It Is

What To Do

Group

Your organization account name in CERTInext. Pre-assigned and cannot be changed here.

No action needed -confirm this is your correct account.

CA Source

The Certificate Authority that will issue the certificate. emsign (eMudhra’s trusted CA) is pre-selected.

Leave as emsign unless your administrator has configured an alternative.

Certificate Type

The category of certificate. SSL/TLS Certificates is pre-selected.

Leave as SSL/TLS Certificates.

Product

The specific EV certificate product you wish to purchase.

Click the dropdown and select the desired EV product: ‘EV SSL Certificate’ for single domain, or ‘EV SSL Certificate UCC’ for multi-domain. See Section 1.3 for guidance.

Subscription For

The validity period: 1 Year, 2 Years, or 3 Years.

Select the appropriate validity period. Note: EV certificates cannot exceed 1 year under CA/Browser Forum rules, but multi-year subscriptions provide continuous coverage through automatic renewal.

Cost

The price for the selected product and validity period (in USD). Auto-calculated.

Review before clicking Next. EV SSL Certificate = $173 for 1 year.

1b. Product-Specific Fields

Product Difference - No. of Domains field

The ‘No. of Domains’ dropdown appears ONLY for EV SSL Certificate UCC. It is not present for EV SSL Certificate.

Field / Option

What It Is

What To Do

No. of Domains (UCC only)

Sets how many domains the certificate will cover. The default and minimum included in the base price is ‘Upto 4’.

Leave at ‘Upto 4’ if you need four or fewer domains. Additional domains beyond 4 can be added in Step 5

Extra SAN note (UCC only)

A note displayed beneath the Cost field informing you of the per-domain cost for SANs beyond the included base.

Note this cost before proceeding. Each extra domain added in Step 5 increases the Grand Total accordingly.

1c. Certificate Features Panel

A blue information panel at the bottom of the screen describes what all EV SSL/TLS certificates include:

• Secures Single, Multiple Domains & Sub Domains

• Domain & Extended Organization Validation

• Average Issuance Timeframe: 1–5 Business Days

• Unlimited Server Licenses

• Strongest SHA2 & ECC Encryption

• Major Browser & Mobile Device Compatibility

• Priority Support

• Automatic Renewal Reminders and Early Renewal Options

IMPORTANT

• EV certificates take 1–5 business days to issue due to rigorous identity verification by the CA. Plan ahead if you have a launch deadline.

• EV certificates cannot exceed 1 year of validity per CA/Browser Forum rules.

After reviewing all fields and the cost, click Next to proceed to Step 2.

Step 2 - Certificate Signing Request (CSR)

A Certificate Signing Request (CSR) is a file you generate on your web server before applying for the certificate. It contains your domain name, organization details, and your public key. The CA uses your CSR to generate your certificate.

IMPORTANT NOTE displayed on screen

The public key and signature algorithm from your CSR are used for certificate generation. Subject details such as Organization, Country, and State are pre-filled from your CSR for convenience but can be edited. The values you submit in the form will be the final values in the issued certificate.

Field / Option

What It Is

What To Do

Skip CSR

An option to bypass CSR submission at this stage if you do not yet have one prepared. The CSR will then need to be provided before the certificate can be issued.

Only use Skip CSR if specifically instructed by your administrator. In most cases, have your CSR ready before starting the application.

Upload CSR (Choose File button)

Upload a CSR file (.csr or .pem) directly from your computer.

Click Choose File, navigate to your saved CSR file, and select it. The CSR text will be loaded automatically.

Paste CSR (text area)

An alternative to file upload -paste the raw CSR text directly into this box.

Copy the full CSR text from your server (including the -----BEGIN CERTIFICATE REQUEST----- and -----END CERTIFICATE REQUEST----- lines) and paste it into this field.

CSR Format - What It Looks Like

A valid CSR begins with: -----BEGIN CERTIFICATE REQUEST-----

Followed by several lines of base64-encoded text.

Ends with: -----END CERTIFICATE REQUEST-----

Ensure you copy the entire block including the BEGIN and END lines.

Key Size Requirement

Your CSR must be generated using a minimum 2048-bit RSA key or 256-bit ECDSA key. Never share your private key -only the CSR (public portion) should be uploaded. Ensure the domain in your CSR matches the domain you will enter in Step 5.

After uploading or pasting your CSR, click Next to proceed to Step 3.

Step 3 - Organization Information

This step collects the legal details of your organization. For EV certificates, these details are verified against official government business registries and must match exactly. They will appear in your issued certificate, visible to your website visitors.

Entering Your Organization Details

Enter the legal details of your organization exactly as they appear in official government records and business registries. These details are used for Extended Validation.

Field / Option

What It Is

What To Do

Organization Name *

The full legal name of your registered business or institution.

Enter your organization’s exact legal name as registered with the government (e.g., “ABC Corporation Inc.”). Do not use abbreviations.

Organization Unit

The department or division within your organization responsible for this certificate (optional).

Enter a department name (e.g., “Information Technology”, “Web Services”), or leave blank.

Business Category *

The legal classification of your organization.

Select the option that best matches: Private Organization (most companies), Government Entity, Business Entity, or Non-Commercial Entity.

Street Address 1 *

The first line of your organization’s official registered address.

Enter the building number and street name of your registered office.

Street Address 2 *

The second line of your organization’s address.

Enter the suite, floor, or additional address detail (e.g., “Suite 400”, “Time Square Building”).

Country *

The country where your organization is legally registered.

Select from the dropdown. Defaults to United States of America (USA).

State / Province *

The state or province of your registered address.

Select from the dropdown list.

Locality *

The city or town of your registered address.

Enter the city name.

Postal Code *

The ZIP code or postal code of your registered address.

Enter your 5-digit ZIP code or full postal code.

IMPORTANT

• All organization information must match your official legal registration documents exactly -including capitalization and punctuation.

• Use your registered office address, not a P.O. Box or mailing address.

• Discrepancies between entered information and registry data are the most common cause of EV validation delays or rejections.

• For EV certificates, the Organization Name is verified against official business registries and will appear in your certificate.

Pre-validated Organizations

If your organization has been previously validated by the CA, it may appear at the top of the selection list. Selecting it will pre-fill all fields and may allow the CA to skip re-validation, speeding up issuance significantly. New organizations require full Extended Validation.

After entering all organization details and confirming accuracy, click Next to proceed to Step 4.

Step 4 - Organization Representative Information

This step identifies the person who will act as the certificate subscriber -the individual within your organization who is formally requesting this certificate. They will receive a consent email during the verification phase (Phase 2, Action 2).

Field / Option

What It Is

What To Do

Choose User (New / Existing)

Toggle between creating a new user profile or selecting an existing one from your account. New: enter details manually. Existing: select from a pre-existing list.

If this is your first certificate order or the representative is not yet in the system, choose New. Otherwise, choose Existing and select the appropriate user.

Name *

Full name of the organization representative.

Enter the person’s legal first and last name. Do not use nicknames or abbreviations.

Email ID *

The work email address of the representative. A verification consent email will be sent here during Phase 2.

Enter a valid, monitored organizational email address. Must be a work email -not a personal email (Gmail, Yahoo, etc.). Do not use a shared or unmonitored mailbox. The consent link is individual and time-sensitive.

Mobile Number

The representative’s mobile/phone number (optional).

Select the country dial code from the dropdown, then enter the number.

Certificate Download Delegation (Optional)

Use this section if a different person (other than the Organization Representative) should receive notifications when the certificate is ready to download -for example, your web server administrator.

Field / Option

What It Is

What To Do

Contact name (Delegation)

Name of the person delegated to download the certificate.

Enter only if using Certificate Download Delegation.

Email ID (Delegation)

Email address of the delegated downloader.

Enter only if using Certificate Download Delegation. This person will receive the download notification email.

IMPORTANT

• Use official organizational email addresses only. Personal emails are not acceptable for EV certificates.

• The Organization Representative’s email will receive the certificate requester consent email. Ensure this person is available to respond promptly.

• The consent email is addressed to the individual -it should not be forwarded.

After completing the representative’s details, click Next to proceed to Step 5.

Step 5 - Certificate Information

This step shows a summary of your organization’s details (auto-filled, read-only) and collects the domain name(s) the certificate will protect, along with your company registration number.

5a. Organization Summary (Read-Only - All Products)

The top portion of this screen displays the organization details you confirmed in Step 3. These fields are informational only. If any detail is incorrect, click Back to return to Step 3 and correct it before proceeding.

Field

Value shown (example)

Organization Name

Your organization’s legal name (e.g., ABC Corporation Inc.)

Organization Unit

Department name or blank if not specified

Business Category

Private Organization / Government Entity / Business Entity / Non-Commercial Entity

Street Address 1

Registered street address

Street Address 2

Additional address details or blank

Country

Country of registration (e.g., United States of America (USA))

State / Province

State or province (e.g., New York)

Locality

City (e.g., New York)

Postal Code

ZIP/postal code (e.g., 11697)

5b. Domain Name Fields - Differences by Product

▶ Product Difference - Domain Fields

The domain entry section below the organization summary is the key difference between the two EV products. Read the sub-section for your chosen product carefully.

EV SSL Certificate - Single Domain

Field / Option

What It Is

What To Do

Automatically secure ‘www’ variant of websites

A checkbox that, when ticked, instructs the system to also secure the www.yourdomain.com version of your domain automatically, at no extra cost.

Tick this box if your website is accessed both with and without ‘www’ (which is the case for most websites). Leave unticked only if your domain is exclusively accessed without www.

Domain Name *

The single fully-qualified domain name (FQDN) the certificate will protect (e.g., yourcompany.com).

Type the domain name exactly as it should appear in the certificate. Do not include ‘http://’ or ‘https://’. Example: yourcompany.com or portal.yourcompany.com

Company DUNS / Company Registration Number *

A 9-digit DUNS number (Dun & Bradstreet) or local government-issued company registration number. Used for EV organization identity verification.

Enter your 9-digit DUNS number. If you do not have a DUNS number, enter your local government-issued company registration/incorporation number. Find your DUNS at dnb.com -registration is free for businesses.

EV SSL Certificate UCC - Multiple Domains

Field / Option

What It Is

What To Do

Automatically secure ‘www’ variant of websites

Tick to also secure the www variant of the PRIMARY domain automatically.

Tick if applicable for your primary domain. Note: this applies to the primary domain ONLY. Additional domain names do not automatically include their www variant.

Domain Name *

The primary (main) domain name the certificate will protect (domain #1 of your total).

Enter your primary domain name (e.g., yourcompany.com). Do not include ‘https://’ or ‘www.’.

Additional Domain Names *

A multi-entry field where you add all extra domain names beyond the primary domain (domains #2, #3, #4, etc.). Each domain appears as a removable tag.

Click inside the input box and type each additional domain, pressing Enter or clicking the ‘+’ button after each one. You can also click ‘Import additional domain’ to paste or upload a list in bulk. Click ‘x’ on any domain tag to remove it.

Import additional domain (button)

Allows bulk import of multiple domain names at once instead of adding them one by one.

Click to open an import dialog. Paste a list of domain names (one per line) and confirm.

Clear (button)

Removes all entries from the Additional Domain Names list.

Use only if you want to start the domain list from scratch.

Company DUNS / Company Registration Number *

A 9-digit DUNS number or local company registration number.

Enter your DUNS number or company registration number. Same as EV SSL Certificate.

IMPORTANT

• List ALL domains you need secured in a single order. Adding domains post-issuance requires a reissue of the certificate.

• Wildcard domains (e.g., *.yoursite.com) are NOT supported on EV certificates per CA/Browser Forum policy.

• IP addresses cannot be added as SANs for EV certificates.

• The www variant auto-secure option applies to the PRIMARY domain only.

• The total domain count (primary + additional) must not exceed your purchased ‘No. of Domains’ without paying the extra SAN fee ($126 per domain).

After entering all domain name(s) and the registration number, click Next to proceed to Step 6.

Step 6 - Authorized Signatory Information

This step is unique to EV certificates. EV certificates require two specifically authorized individuals from your organization: a Contract Signer (who signs the legal Subscriber Agreement) and a Certificate Approver (who authorizes certificate issuance). These can be the same person if they hold appropriate authority.

6a. Contract Signer Information

The Contract Signer is the individual with authority to enter into legal agreements on behalf of your organization (e.g., Director, VP, authorized officer). They will receive and must electronically sign the eMudhra emSign Subscriber Agreement.

Field / Option

What It Is

What To Do

Same as Organization Representative (checkbox)

Copies the Organization Representative’s details from Step 4 into this section.

Check this box if the same person from Step 4 is also your Contract Signer. The fields will auto-fill.

Choose User *

‘New’ or ‘Existing’ contact.

Select ‘New’ to enter new details, or ‘Existing’ to pick from saved contacts.

Name *

Full legal name of the Contract Signer.

Enter their full name exactly as it appears on official documents.

Email ID *

Work email of the Contract Signer. The Subscriber Agreement signing link will be sent here.

Enter a valid organizational work email. The agreement link is sent to this address. The Subscriber Agreement is a legally binding document -ensure this email reaches the correct authorized person.

Telephone

Contact phone number (optional).

Select country code and enter the full telephone number.

6b. Certificate Approver Information

The Certificate Approver is the individual who gives final authorization for the EV certificate to be issued (e.g., CISO, IT Director, delegated manager). This is an EV-specific requirement under CA/Browser Forum guidelines.

Field / Option

What It Is

What To Do

Same as Contract Signer (checkbox)

Copies the Contract Signer’s details into the Certificate Approver section.

Check this if the same person is both Contract Signer and Certificate Approver (common in smaller organizations).

Choose User *

‘New’ or ‘Existing’ contact.

Select ‘New’ to enter new details, or ‘Existing’ to pick from saved contacts.

Name *

Full legal name of the Certificate Approver.

Enter their full name.

Email ID *

Work email of the Approver. The EV Certificate Request Approval link will be sent here.

Enter a valid organizational work email. Ensure the Approver is available and watching their email.

Telephone

Contact phone number (optional).

Select country code and enter the full number.

IMPORTANT

• The Contract Signer must have legal authority to bind your organization to contractual agreements (e.g., Director, VP, authorized officer).

• The Certificate Approver must have authority to authorize security certificate issuance (e.g., CISO, IT Director, or delegated manager).

• Both roles can be fulfilled by the same person if they hold appropriate authority.

• Do not use external consultants or vendors in these roles.

After completing the authorized signatory details, click Next to proceed to Step 7.

Step 7 - Additional Information (Optional)

This step is the same for both EV products. All fields are optional but some, such as auto-renewal, are pre-configured with sensible defaults.

Field / Option

What It Is

What To Do

Tags

Custom labels you can attach to this order for internal tracking and reporting within CERTInext (e.g., ‘Production’, ‘Project-Alpha’, ‘2026-Q2’).

Click ‘+ Add Tag’, type your tag text, and press Enter. Add multiple tags as needed. Tags are for your internal use only and do not appear on the certificate.

Order Remarks

A free-text notes field for any special instructions or internal references related to this order.

Type any notes relevant to your team or to support if you need to raise a query. This text is visible to the CA and CERTInext administrators.

Technical Point of Contact Information

Checkbox -expands to collect the name, email, and phone number of the technical person responsible for managing this certificate (e.g., the system administrator who will install it).

Tick and fill in only if the technical contact is different from the Organization Representative entered in Step 4. Useful for larger organizations.

KYC Documents

Checkbox -expands to allow you to upload Know Your Customer (KYC) verification documents (e.g., company registration certificate, utility bill, government ID).

Tick and upload documents if the CA requests them or if you want to proactively provide them to speed up the EV verification process.

Additional email recipients

Checkbox -expands to add extra email addresses that should receive certificate-related notifications.

Tick and add email addresses if others in your organization (e.g., a manager, security team) should also receive order status updates and the download notification.

Auto-renew certificates until coverage

Checkbox (ticked by default) -instructs CERTInext to automatically initiate certificate renewal before expiry.

Leave ticked (recommended). Only untick if you want to manage renewals manually. Without auto-renewal, your certificate may expire without notice, causing browsers to show security warnings.

Set renew criteria - Before [N] days of certificate expiry

Configures how many days before expiry the auto-renewal process begins. Default is 15 days.

Click the dropdown to adjust the lead time (e.g., 30 days gives more time for any renewal complications). 15 days is the standard minimum recommended.

Review and adjust any optional settings, then click Next to proceed to the Order Summary.

Step 8 - Order Summary & Payment

The final step before payment. Review everything carefully. A ‘Payment Pending’ badge appears in the top-right corner.

8a. Product Information Panel

Field / Option

What It Is

What To Do

Certificate Type

The category of certificate (SSL/TLS Certificates).

Verify this matches your intended purchase.

Product Name

The specific EV product selected (e.g., EV SSL Certificate or EV SSL Certificate UCC).

Confirm this is the correct product variant.

Validity Period

The subscription duration selected in Step 1 (e.g., 1 Year).

Confirm the correct duration.

Domain Count

The total number of domains the certificate will cover.

For EV SSL Certificate: 1. For EV SSL Certificate UCC: reflects the total number of domains entered in Step 5.

Product Difference - Order Summary for EV SSL Certificate UCC

The Order Summary in Step 8 shows all the following for UCC:

Domain Count: 4 (or your selected number)

domain name: [primary domain]

additional domain names: [all additional domains listed, comma-separated]

Grand Total: $417 (for up to 4 domains, 1 year). Additional SANs beyond 4 = $126 per domain.

8b. Certificate Information Panel

A summary of all organization details and domain name(s) entered across previous steps. Scroll through to verify all values are correct.

8c. Payment Information Panel

Field / Option

What It Is

What To Do

Current Balance

Your organization’s current pre-paid credit balance in USD.

Verify you have sufficient balance if paying by credit. If the balance is less than the Grand Total, use Pay Online instead.

Certificate Price (upto 4) (UCC only)

The base certificate price covering the included number of domains (up to 4).

Informational -auto-calculated.

Additional SAN Cost (UCC only)

The additional cost for any domains beyond the included base quantity. Format shown: ‘$[rate] per [count]’.

Informational. Verify this matches the number of extra domains you added in Step 5.

Grand Total

The final total amount in USD payable for this order.

Verify this matches your expectation before proceeding to payment. EV SSL Certificate = $173 (1 year). EV SSL Certificate UCC = $417 (up to 4 domains, 1 year).

Subscriber Agreement checkbox

A mandatory checkbox confirming you have read and agreed to eMudhra emSign’s Subscriber Agreement.

You MUST tick this checkbox before payment. Click the ‘Subscriber Agreement’ hyperlink to read the full terms if you have not done so.

8d. Payment Buttons

Button

Action

Save and Exit

Saves your application as a draft and exits the wizard. You can return to complete payment later from the Orders list.

Pay Online

Opens a payment gateway to pay the Grand Total using a credit/debit card or other supported online payment method.

Use Credit

Deducts the Grand Total from your organization’s pre-paid credit balance in CERTInext immediately. Order is submitted upon confirmation.

IMPORTANT

• Review ALL information carefully before payment. Once payment is made, changes to domain name or key organization details require a certificate reissue.

• Ensure your domain name and organization name are correct -these appear in the certificate and are visible to your website visitors.

Tick the Subscriber Agreement checkbox, then click either Pay Online or Use Credit to submit your order. After successful payment, you will be taken to the Order View page.

PHASE 2: Post-Submission - What Happens After You Pay

After payment, your order enters a multi-step verification and issuance workflow. For EV certificates, the CA must verify your identity, organization, domain ownership, and organizational authority before issuing the certificate. Most steps require action from you or your authorized signatories.

Two portals are involved

1. CERTInext (certinext.io) -where you placed your order. Use it to track order status.

2. emSign Subscriber Portal -where you and your authorized signatories complete all verification steps.

The emSign portal link is sent to you in the order confirmation email and is also accessible via CERTInext > Certificates > Orders > your order > Track Order Status.

2.1 CERTInext Order View - Immediately After Payment

You are automatically redirected to the Order View page in CERTInext. Bookmark or note the Order ID displayed at the top -you will need it if you contact support.

Field

Meaning

Order ID

Unique reference number for your certificate order. Keep this safe.

Ordered Date

Date and time the order was placed.

Product

The EV certificate product ordered.

Group

Your organization account name.

CA Source

Certificate Authority: emSign.

Certificate Price

Total amount charged for this order (USD).

Order Status

‘Order Accepted’ (orange badge) -the order has been received and accepted for processing.

Certificate Status

‘Pending for Approver’ (orange badge) -the certificate is awaiting verification and issuance steps.

Note - Subscription Dates

Subscription Start Date and Subscription End Date will be blank at this stage. They are populated once the certificate is issued and the subscription becomes Active.

2.2 Order Confirmation Email

Within minutes of payment, the Organization Representative receives an email notification confirming the order was placed successfully.

Email Field

Content

Subject

ORDER #[Order ID] -Your Order is Successful

Order ID

Your unique order reference number

Ordered Date

Date and time (UTC)

Product & Validity

Product name and subscription period

Identifier

The primary domain name secured by this certificate

Subscription Per

e.g., 1 Year(s)

Track Order button

Orange button linking to the emSign Subscriber Portal for your order

Click ‘Track Order’ to open the emSign Subscriber Portal where you will complete the remaining verification actions. You can also access this portal via the link in subsequent notification emails.

Tracking Order Status in CERTInext

In CERTInext, navigate to Certificates > Orders and click your order to view its full details.

Click the three-dot menu (top-right of the order) to open the “Track Order Status” popup. This popup shows a unique Order Status Tracking URL.

“Open URL”: Opens the emSign Subscriber Portal in your browser.

“Share URL”: Sends the tracking link via email to the Organization Representative.

2.3 emSign Subscriber Portal - Order Actions Overview

The emSign Subscriber Portal is the central place where all post-payment verification steps are tracked and completed. Access it via the “Track Order” link in your confirmation email.

The portal displays:

• Request Information: Certificate Requester, Contract Signer, and Certificate Approver details

• Order Details panel (right side): Date, Order ID, Product, Domain, Order Status, Certificate Status

• Order Actions: A numbered list of all verification steps required for certificate issuance

The Order Actions

▶ Product Difference - Number of Order Actions by Product

EV SSL Certificate has 7 Order Actions.

EV SSL Certificate UCC has 8 Order Actions (adds Action 7: Interim DV Certificate).

Action

Name and Description

Action 1. Submit CSR

Confirms your CSR was accepted. Auto-completed if you submitted a CSR in Step 2. Only pending if you selected “Skip CSR”.

Action 2. Certificate Requester Verification

The Organization Representative confirms they authorized this certificate request. A consent email is sent to their email address.

Action 3. Subscriber Agreement

The Contract Signer electronically signs the emSign Subscriber Agreement -the legal contract between your organization and the CA.

Action 4. EV Certificate Request Approval

The Certificate Approver gives formal institutional authorization for EV certificate issuance. Mandatory for all EV certificates.

Action 5. Organization Verification

The CA verifies that your organization is a real, legally registered entity. May be automatic or require a Verified Professional Letter (VPL).

Action 6. Domain Verification (DCV)

You prove to the CA that your organization controls the domain(s) on the certificate. Required before certificate issuance.

Action 7 (UCC only). Interim DV Certificate

EV SSL Certificate UCC only: a temporary DV-level certificate is automatically issued after domain verification, while EV organization checks are finalized.

Action 7 (EV SSL) / Action 8 (EV SSL UCC). Certificate Download

Available once all other steps are complete. The CA issues your certificate and it becomes available for download.

Action Status Colors

Green = Completed. Orange = Awaiting Customer Action (you must do something).

‘Issuance Pending’ (orange) on the final certificate action means the CA is still processing -no action needed yet.

Certificate Status in the right panel shows the overall progress: ‘Pending for Approver’ → ‘Approved’ → ‘Certificate Generated’.

Use the Resync button (circular arrow icon) next to any action to refresh its status or resend notification emails.

2.4 Action 1: Submit CSR

If you uploaded or pasted your CSR in Step 2 of the application, this action is automatically marked Completed. No action is needed.

If you selected “Skip CSR” during application, this step shows as pending. You must submit your CSR here before the certificate can be issued.

• Click the “+” to expand Action 1.

• Paste or upload your CSR in the provided field.

• Click Submit.

2.5 Action 2: Certificate Requester Verification

The Organization Representative (Certificate Requester from Step 4) must confirm they authorized this certificate request. This is a consent step required for all EV SSL certificates.

The Organization Representative receives an email with the subject: ‘ORDER #[ID] -Certificate Requester consent required for SSL EV request’.

• Click the orange “Click here to provide consent” button in the email.

• Review the Order Details and Organization Details on the page.

• Read the consent statement: “Accepting this consent means that you confirm your certificate request.”

• Click “Approve” to confirm, or “Reject” to decline.

• A confirmation popup appears: “Are you sure you want to accept the consent?” -Click “Yes”.

Success: “Thank you for completing the pending actions. This would help us to speed up the certificate issuance process.”

• Click “Proceed for Verification” to return to the full Order Actions list.

IMPORTANT

• The consent email may land in the spam/junk folder. Check there if not received within 15 minutes.

• If the consent link has expired, use the Resync button (circular arrow) next to Action 2 in the portal to send a new consent email.

• The consent email is addressed to the individual -it should not be forwarded.

2.6 Action 3: Subscriber Agreement

The Contract Signer (from Step 6) must electronically sign the eMudhra emSign Subscriber Agreement -the legal contract between your organization and the Certificate Authority.

2.6a Agreement Email

The Contract Signer receives an email with the subject: ‘ORDER #[ID] -Sign Subscriber Agreement for EV SSL Request’.

• Click the orange “Agreement Link” button in the email.

2.6b emSign Subscriber Portal - Subscriber Agreement Page

• Review the full Subscriber Agreement document (10 pages) displayed on screen.

• On the right panel, complete the Accept Agreement form:

◦ Your Name: Pre-filled with the Contract Signer’s name. Verify it is correct.

◦ Place: Enter the city/location where you are signing (e.g., “New York”).

◦ Email ID: Pre-filled and masked for privacy. Verify the masked email is correct.

◦ Check box: “I am the authorized person to sign this agreement.”

◦ Check box: “I agree to all the terms & conditions of this agreement.”

◦ Click “Accept Agreement” (both checkboxes must be ticked first).

Success: “Thank you for providing your consent and completing the Subscriber Agreement step successfully.”

IMPORTANT

• Read the Subscriber Agreement carefully -it is a legally binding document.

• The Place field should reflect your actual current location, not your company’s registered address.

• Both checkboxes are mandatory. The “Accept Agreement” button remains inactive until both are checked.

• Once signed, the agreement cannot be revoked without cancelling the order.

2.7 Action 4: EV Certificate Request Approval

The Certificate Approver (from Step 6) must give final authorization for the EV certificate issuance. This step is mandatory for all EV certificates under CA/Browser Forum rules.

2.7a Approval Email

The Certificate Approver receives an email with the subject: ‘ORDER #[ID] -Approve SSL EV Certificate request’.

• Click the orange “Approve EV Certificate request” button in the email.

2.7b emSign Subscriber Portal - EV Certificate Approval Page

• Review Order Details (Order ID, Date, Ordered By, Domain, Certificate Requester Name/Email).

• Review Organization Details (Organization Name, Domain).

• Under “Approve SSL EV request”, click the orange “Approve” button (or “Reject” if there is an issue).

• A confirmation popup asks: “Are you sure you want to approve the SSL EV certificate request?” -Click “Yes”.

Success: “Thank you for approving the SSL EV certificate request successfully.”

IMPORTANT

• The Approver’s action is a formal institutional authorization. Ensure the Approver reviews the domain and organization details before approving.

• If the Approver has not received the email, use the Resync button next to Action 4 in the portal.

2.8 Action 5: Organization Verification

The CA verifies that your organization is a real, legally registered entity. This is the most detailed verification step for EV certificates. The CA first attempts automatic verification using public business registries.

2.8a Automatic Verification

If the CA can verify your organization automatically through public business registries, this step completes without any action from you -it will simply move to “Completed”. Only if automatic verification cannot confirm your organization will a Verified Professional Letter (VPL) be requested.

2.8b Verified Professional Letter (VPL)

If automatic verification fails, the CA will request a Verified Professional Letter.

Step A -Email requesting VPL:

• Subject: ORDER #[ID] -Submit Verified Professional Letter for SSL EV request

• The email explains that the CA could not verify your organization through public sources and requests a VPL.

• Click the orange “Submit Verified Professional Letter” button.

Step B -VPL Upload Form in emSign Portal:

The VPL is an official letter on your organization’s letterhead (or from a legal authority) that establishes your organization’s identity. It should confirm: Legal name, DBA name (if applicable), Physical address, Contract Signer authority, and Certificate Approver authority.

Field / Option

What It Is

What To Do

Organization Name

Auto-filled with your organization’s name. Read-only.

No action needed. Verify it displays your correct organization name.

Document Source *

Describes the origin or type of the letter.

Enter a brief description of the document source (e.g., “Company Official Letterhead”, “Notarized Business Registration Document”).

Document (PDF only) *

The actual VPL file to upload. Platform accepts PDF files only.

Click “Choose File”, select your VPL PDF file, and confirm the upload. Ensure the file is not password-protected.

Document Description *

A brief description of what the document contains.

Enter a short description (e.g., “Professional letter verifying ABC Inc legal registration and authorized signatories”).

Issuer Name *

Full name of the person who prepared or signed this letter.

Enter the full name of the attorney, notary, company officer, or authorized professional who issued the letter.

Issuer Email ID *

Email address of the person who issued the letter.

Enter a valid work email address for the Issuer. The CA validation agent may contact them to verify the letter.

Issuer Contact No. *

Phone number of the Issuer.

Select the country code and enter the full phone number. The CA may call to verify the letter.

• Click “Submit For Verification” to submit the VPL.

Success: “Thank you for submitting the Legal Option Letter for [organization] successfully.”

2.8c Organization Authentication Code

After the VPL is reviewed, the CA sends an Organization Authentication Code to the email address publicly listed for your organization (from public registries such as WHOIS or business databases).

Two emails are sent simultaneously:

• An email to the publicly listed organizational contact containing the 6-digit Authentication Code.

• An email to the Organization Representative containing a Verification Link to the emSign portal where the code must be entered.

Step C -Entering the Authentication Code:

• Click the link in the Verification Link email.

• On the emSign portal page, enter:

◦ Organization Authentication Code: Enter the 6-digit code received by the public registry contact.

◦ Designation: Enter your job title at the organization (e.g., “IT Manager”, “Systems Administrator”).

• Click “Submit”.

Success: “Thank you for submitting the organization authentication code for [organization] and completing the verification successfully.”

IMPORTANT

• The authentication code is sent to the publicly listed organizational contact -not necessarily to you. Coordinate internally with whoever receives that email to obtain the code.

• The code expires in 24 hours. If it expires, use the Resync button next to Action 5 in the portal to trigger a new code.

• Your Designation must reflect your actual role at the organization.

2.9 Action 6: Domain Control Validation (DCV)

Domain Control Validation is the process by which you prove to the Certificate Authority that you genuinely control each domain on your certificate. This is mandatory for ALL SSL/TLS certificates before issuance.

2.9a Domain List

When you expand Action 6 (Domain Verification), you see:

• ‘Total Domains: [N]’ -the count of domains requiring verification.

• Each domain listed with a status icon (orange warning = pending, green = verified) and a ‘Verify’ button.

• For EV SSL Certificate: 1 domain to verify.

• For EV SSL Certificate UCC: one entry per domain -you must verify each domain individually.

▶ Product Difference - Multiple DCV for EV SSL Certificate UCC

EV SSL Certificate UCC requires domain verification for EVERY domain listed on the certificate.

Total Domains: Shows the total count (e.g., “Total Domains: 4”).

Each domain is listed individually with its own status icon, “CAA” button, and “Verify” button.

DCV must be initiated and completed for each domain separately by clicking “Verify” next to each one.

If the authorized domain name (base domain) ownership is proven, all sub-domains that have the same base domain name will be proven automatically (e.g., proving xyz.com automatically proves blog.xyz.com). Note: the reverse is NOT allowed.

Click the ‘Verify’ button next to a domain. A modal dialog appears.

Technical Note

The DCV modal includes a note: “This is technical in nature. If you are not the right person, please contact your IT / Domain administrator.” If you do not manage your DNS records yourself, forward the TXT record details (Host and Value) to your DNS administrator and ask them to create the record.

Field / Option

What It Is

What To Do

DCV Method dropdown

The method used to prove domain ownership. ‘DNS TXT Record (Most Preferred)’ is the recommended and pre-selected method.

Leave as ‘DNS TXT Record (Most Preferred)’ unless your DNS provider does not support TXT records.

Record Type

The type of DNS record to create: TXT.

Always TXT for this method.

Host

The hostname for the DNS TXT record. This is the domain name itself (Copy button available).

Copy this value exactly. Log in to your DNS provider’s management panel, navigate to DNS settings for this domain, and use this as the Host/Name field when creating the TXT record.

Value

The unique verification token that must be entered as the TXT record’s value (Copy button available).

Copy this token exactly. Enter it as the Value/Content of the new TXT record at your DNS provider. Do not add any extra spaces or characters. For UCC: each domain gets its own unique Host and Value -do not reuse values between domains.

Verify Now button

Triggers the CA’s system to check your DNS for the TXT record.

ONLY click Verify Now after you have saved the DNS TXT record at your DNS provider AND allowed sufficient time for DNS propagation (15–30 minutes minimum, up to 48 hours).

Close button

Closes the modal without verifying.

Click Close if you need to set up the DNS record first and return to verify later.

InCommon Note - DNS Propagation

After creating the DNS TXT record at your DNS provider, changes may take anywhere from a few minutes to 48 hours to propagate globally (depending on your DNS TTL settings). It is best practice to wait at least 15–30 minutes before clicking ‘Verify Now’. If verification fails, wait longer and try again. Do not delete the TXT record until verification succeeds.

2.9c Domain Verification Success

After successful verification, a success popup appears: “Thank you for proving the domain ownership for [domain]. Domain Verification is completed successfully.”

Click OK to dismiss. The domain’s status icon turns green.

For EV SSL Certificate UCC: repeat the Verify process for each remaining domain until all show green / Completed.

2.10 Action 7: Interim DV Certificate (EV SSL Certificate UCC Only)

▶ Product Difference - Action 7 is unique to EV SSL Certificate UCC

This action does NOT appear for the standard EV SSL Certificate.

No action is required from you. Once all domain verifications (Action 6) are complete, the system automatically processes and issues the Interim DV Certificate.

Monitor this step’s status in the portal. It will move from “Issuance Pending” to “Completed” automatically.

An Interim Domain Validated (DV) Certificate is a temporary, basic certificate issued once domain verification is complete, before the full EV organization validation is finalized. It provides DV-level HTTPS coverage for your domains while the CA completes the Extended Validation checks (organization verification, approver confirmation, etc.).

[SCREENSHOT: emSign Portal -Interim DV Certificate (Action 7) -Issuance Pending]

What happens next:

• Once the Interim DV Certificate is issued, you may optionally install it on your server for immediate basic HTTPS coverage.

• The full EV Certificate (Action 8) will be issued after all remaining EV-specific verifications are approved.

• When the full EV Certificate is issued, replace the Interim DV Certificate on your server with the EV certificate.

IMPORTANT

• The Interim DV Certificate is NOT the final EV Certificate. Do not consider your EV order complete until the full EV Certificate (Action 8) is issued.

• The EV Certificate provides the highest browser trust indicators. The Interim DV Certificate does not.

• Replace the Interim DV Certificate with the full EV Certificate promptly once it is issued.

2.11 Certificate Issuance & Download

Once all Order Actions are marked Completed, the CA processes and issues the certificate. This typically happens automatically within minutes to a few hours of the final action being completed. No action is required from you at this stage.

2.11a Download Notification Email

The Organization Representative receives an email with the subject: ‘ORDER #[ID] -Your Certificate is ready for download’.

[SCREENSHOT: Email -Certificate Ready: ‘ORDER #[ID] -Your Certificate is ready for download’]

• The email contains Order ID, Ordered Date, Product & Validity, and the Identifier (domain).

• It includes an orange “Download Certificate” button linking to the emSign Subscriber download page.

• Click the “Download Certificate” button in the email. This opens the emSign Subscriber download page.

2.11b emSign Subscriber Portal - Certificate Download Page

[SCREENSHOT: emSign -Certificate download page showing Order ID, Product, Domain Name and Download Certificate button]

The download confirmation page shows:

• A green tick with: “Thanks for completing the necessary steps.”

• “Your certificate has been issued and ready for download. To continue further, please click Download Certificate.”

• Order ID, Product & Validity, and Domain Name details.

• Orange “Download Certificate” button.

2.11c Certificate Download in Order Actions

Expanding the final Certificate Download action in the Order Actions list reveals the following:

[SCREENSHOT: emSign Subscriber Portal -Certificate Download (expanded panel with Resend Email and Download Certificate buttons)]

Text shown in expanded panel

Your certificate has been issued and ready for download. An email containing certificate download instructions has been sent to your email ID. In case you have not received an email, please click Resend Email to resend the email. Your certificate is based on the CSR submitted by you. Please ensure to import / use the certificate against the same key-pair, from where the CSR was generated.

Button

Action

Resend Email

Re-sends the download notification email to the Organization Representative’s email address. Use this if the original email was not received.

Download Certificate

Initiates the certificate download directly from the portal, bypassing the email.

IMPORTANT

• CRITICAL: Your certificate MUST be installed with the matching private key. If you have lost your private key, you will need to generate a new CSR and request a reissue.

• After installation, verify your certificate using SSL Labs (ssllabs.com/ssltest) to confirm it is correctly installed and trusted by major browsers.

• EV certificates display the organization’s name in the browser address bar -confirm this appears correctly after installation.

• For EV SSL Certificate UCC: the issued certificate file contains Subject Alternative Name (SAN) entries for ALL your domains. You install ONE certificate file that covers all domains simultaneously.

2.11d Selecting the Download Format

When initiating a download from CERTInext, a ‘Select the Format to download’ dialog appears with four options:

Field / Option

What It Is

What To Do

DER encoded binary X.509 (.CER)

Binary format of the certificate. Compact and widely supported by Windows systems and Java keystores.

Choose this for Windows Server (IIS) or Java-based servers.

Base-64 encoded X.509 (.CER)

Text-based (PEM) format of the certificate, saved with the .CER extension. Readable in a text editor.

Choose this for most Linux/Unix-based servers (Apache, Nginx), or when your server software requests a .CER file.

Base-64 encoded X.509 (.CRT)

Identical content to the Base-64 .CER above but saved with the .CRT file extension.

Choose this when your server software (e.g., Apache, Nginx) expects a .crt file extension.

Zip

A ZIP archive containing the certificate along with any intermediate/chain certificates. Recommended for most installations.

Choose Zip if you are unsure, or if your server requires the full certificate chain. Extract the ZIP and follow your server’s installation guide.

Which Format to Choose

If in doubt, choose Zip -it includes all necessary certificate files (end-entity certificate + intermediate certificates/chain). Your web server administrator will know how to handle the extracted files. For quick Windows inspection, choose DER or Base-64 .CER.

2.12 CERTInext Order View - Final State

After the certificate is downloaded, the Order View in CERTInext updates to its final state. Navigate to Certificates > Orders and click your order to view this screen.

[SCREENSHOT: CERTInext Order View -Final state (Order Fulfilled / Certificate Downloaded status)]

Field

Final Value

Order Status

Order Fulfilled (green)

Certificate Status

Certificate Downloaded (green)

Subscription Status

Active (green)

Subscription Start Date

Date the certificate was issued

Subscription End Date

Expiry date (Start Date + validity period, e.g., 1 year)

2.12a Order Action Menu (⋯ Button)

In the top-right corner of the Order View, a three-dot menu icon (⋯) provides additional actions depending on the certificate type.

[SCREENSHOT: CERTInext Order View -Action menu open (⋯ button, showing available options)]

Action

Available For

Download Invoice

All products

Track Order

All products

Download Certificate

All products

Reissue Certificate

All products

Add / Remove SANs

EV SSL Certificate UCC only

Revoke Certificate

All products

Reissue vs. Revoke

Reissue creates a replacement certificate (useful when you change your server or CSR). The old certificate is revoked as part of reissuance.

Revoke permanently deactivates the certificate without replacement -only use Revoke if you are decommissioning the service or the key has been compromised and you will not replace it.

Last updated