OV Certificate Download
2.7 Certificate Issuance
Once all Order Actions (Steps 1-4) are marked Completed, the CA processes and issues the certificate. This typically happens within minutes of the final verification step being approved, but may take up to 1-5 business days depending on CA processing.

All Steps 1-4: Completed (green): All required actions are done - the CA has everything it needs.
Step 5 Certificate Download: Certificate Issued (green): The certificate has been generated and is ready to download.
Certificate Status: Certificate Generated (green): Confirmed - your certificate exists and is waiting for you.
Order Status: Order Accepted (orange): The order is still in the 'Accepted' state; it moves to 'Order Fulfilled' after download.
2.8 Certificate Download
There are three ways to download your issued certificate: via the email notification, via the emSign Subscriber Portal, or directly from CERTInext.
2.8a Download Notification Email

The Organization Representative receives an email with the subject: 'ORDER #[ID] - Your Certificate is ready for download'.
The email contains Order ID, Ordered Date, Product & Validity, and the Identifier (domain). It includes an orange 'Download Certificate' button and an alternative URL to paste into a browser.
Action
Click the 'Download Certificate' button in the email. This opens the emSign Subscriber download page.
2.8b emSign Subscriber Portal - Certificate Download Page

The download confirmation page shows:
A green tick with: 'Thanks for completing the necessary steps.'
'Your certificate has been issued and ready for download. To continue further, please click Download Certificate.'
Order ID, Product & Validity, and Domain Name details.
Orange 'Download Certificate' button.
2.8c Step 5 - Expanded Download Panel in Order Actions
Expanding Step 5 in the Order Actions list reveals the following download instructions and options:
Step 5 Expanded - Text on Screen
Your certificate has been issued and ready for download.
An email containing certificate download instructions has been sent to your email ID.
In case you have not received an email, please click Resend Email to resend the email.
Your certificate is based on the CSR submitted by you. Please ensure to import / use the certificate against the same key-pair, from where the CSR was generated.
Please follow the necessary instructions in your download notification email to download your certificate.
Resend Email: Re-sends the download notification email to the Organization Representative's email address. Use this if the original email was not received.
Download Certificate: Initiates the certificate download directly from the portal, bypassing the email.
Important
Your certificate is generated from the CSR you submitted.
You MUST install and use the certificate on the same server and with the same private key that was used to generate the CSR.
If you generate a new key pair, you must re-issue the certificate with a new CSR.
2.8d Selecting the Download Format

When initiating a download from CERTInext, a 'Select the Format to download' dialog appears with four options:
DER encoded binary X.509 (.CER): Binary format of the certificate. Compact and widely supported by Windows systems and Java keystores. Choose this for Windows Server (IIS) or Java-based servers. Double-click the downloaded file to view/install in Windows Certificate Manager.
Base-64 encoded X.509 (.CER): Text-based (PEM) format of the certificate, saved with the .CER extension. Readable in a text editor. Choose this for most Linux/Unix-based servers (Apache, Nginx), or when your server software requests a .CER file.
Base-64 encoded X.509 (.CRT): Identical content to the Base-64 .CER above but saved with the .CRT file extension. Choose this when your server software (e.g., Apache, Nginx) expects a .crt file extension.
Zip: A ZIP archive containing the certificate along with any intermediate/chain certificates. Recommended for most installations. Choose Zip if you are unsure, or if your server requires the full certificate chain. Extract the ZIP and follow your server's installation guide for the certificate and chain files.
Note - Which Format to Choose
If in doubt, choose Zip - it includes all necessary certificate files (end-entity certificate + intermediate certificates/chain).
Your web server administrator will know how to handle the extracted files.
For quick Windows inspection, choose DER or Base-64 .CER.
Choose the one applicable to your scenario based on the above description
Action
Select your preferred format and click Download.
Save the file(s) to a secure location.
Follow your web server platform's documentation to install the certificate.
Last updated
