Ordering SMIME Certificates - Draft
What is an S/MIME Certificate?
An S/MIME certificate is a digital security credential that is attached to your email account. Once installed in your email application, it does two important things:
• Digitally signs your outgoing emails so recipients can verify that the email truly came from you (not an impersonator).
• Encrypts emails between you and other S/MIME users, so no one else can read them in transit.
What is CERTInext?
CERTInext is the certificate lifecycle management portal provided by eMudhra. It allows your organisation to request, manage, and download digital certificates from a trusted Certificate Authority (CA) called eSign.
What is a CSR?
A Certificate Signing Request (CSR) is a small encrypted file that you generate on your computer. It contains your public key and basic identity information. You upload it during the application so the CA can embed your public key inside your finished certificate. Think of it as an application form that your computer fills out automatically.
How Long Does the Process Take?
Stage
Typical Time
Filling the application form
5–10 minutes
Order acceptance (automatic)
Immediate
Email verification (you must act)
Within 24 hours of receiving the email
Certificate issuance after verification
Minutes
Certificate download
Instant
⚠ WARNING: The email verification link expires in 24 hours. Make sure to complete email verification promptly after you receive it. If it expires, you can request a resend from the order tracking page.
PHASE 1 - APPLYING FOR THE CERTIFICATE IN CERTInext
This phase covers everything you do inside the CERTInext portal — from selecting your product to making payment. There are six steps.
STEP 1 - Choose Product & Validity
This is the first screen you see after clicking New Certificate in the CERTInext portal. You choose which type of certificate you want and for how long.

Field Reference
Field / Element
What It Is
What To Do
Group
The name of your organisation as registered in CERTInext. This is set by your administrator and cannot be changed here.
This field is auto-filled. No action needed.
CA Source *
The Certificate Authority that will issue your certificate. 'eSign' is eMudhra's own trusted CA.
Select 'eSign' from the dropdown.
Certificate Type *
The category of certificate you are applying for.
Select 'S/MIME Certificates' from the dropdown.
Product *
The specific S/MIME product variant and its validity period.
Select 'eSign - SMIME - Simple MV-S 1 Year' (or the product your administrator has approved) from the dropdown.
Cost
The price of the selected product in USD, as charged to your organisation's credit balance.
This updates automatically when you select a product. No action needed. Verify the amount before proceeding.
Product Info Box
A summary of what S/MIME certificates provide: email validation, digital signing, end-to-end encryption, message integrity, sender identity assertion, and automatic renewal reminders.
Read this to confirm S/MIME is the certificate type you need.
ℹ NOTE: Fields marked with an asterisk (*) are mandatory. You cannot proceed to the next step without filling them in.
💡 TIP: If you do not see the product you need in the dropdown, contact your CERTInext administrator — they control which products are available to your group.
What to Do
1. Click New Certificate in the left sidebar (or top menu) to begin.
2. Confirm that Group shows your correct organisation name.
3. Set CA Source to emSign or any CA.
4. Set Certificate Type to S/MIME Certificates.
5. Select the correct Product from the dropdown. The cost will appear automatically.
6. Review the feature list in the blue information box to confirm your selection.
7. Click Next to proceed to Step 2.
STEP 2 - Certificate Signing Request (CSR)
A CSR contains the public key and identity information needed to create your certificate. On this screen you either provide your own CSR (if your IT team generated one) or allow the system to generate the key pair for you.

Important Note About the CSR
ℹ NOTE: The public key and signature algorithm from your CSR are used for certificate generation. Subject details such as Organisation, Country, and State are pre-filled from your CSR for convenience - but you can edit them. The values you submit in this form will be the final values in the issued certificate.
Field Reference
Field / Element
What It Is
What To Do
Key Generation *
Specifies who generates the cryptographic key pair (public and private keys).
Select 'Requester' if your IT team or you will generate the CSR. If you are unsure, check with your administrator.
Skip CSR
A checkbox that, when ticked, bypasses the CSR upload and lets the system generate the key pair on your behalf.
Tick this checkbox ONLY if instructed by your administrator and you do not have a CSR file. Leave unticked if you have a CSR.
Upload CSR
Allows you to upload a CSR file directly from your computer.
Click 'Choose File', navigate to your CSR file (usually a .csr or .pem file), and select it. You can use this OR the Paste CSR field below — not both.
Paste CSR
A text area where you can paste the contents of your CSR directly.
Open your CSR file in any text editor (e.g. Notepad), select all the text (Ctrl+A), copy it (Ctrl+C), and paste it here (Ctrl+V). The text should begin with '-----BEGIN CERTIFICATE REQUEST-----' and end with '-----END CERTIFICATE REQUEST-----'.
⚠ WARNING: Never share your private key with anyone — including CERTInext support. Only the CSR (which contains the public key) is submitted here. Your private key must remain on your computer.
ℹ NOTE: If you are using a CSR generated by your IT department, they will provide you with the CSR file or text to paste here.
What to Do
1. Set Key Generation to 'Requester' (default).
2. Choose one of the two options:
- Option A (Upload): Click 'Choose File' and select your .csr or .pem file.
- Option B (Paste): Open your CSR file in a text editor, copy the full text, and paste it into the 'Paste CSR' box.
3. If you do not have a CSR, tick 'Skip CSR' and the portal will generate one for you.
4. Click Next.
STEP 3 - Requestor Information
This screen captures details about the person making the request. All important notifications (including the email verification link) are sent to the Requestor Email ID entered here.

Field Reference
Field / Element
What It Is
What To Do
Name *
The full name of the person requesting the certificate.
Enter your full name as it should appear on the order record.
Requestor Email ID *
The email address of the person submitting this request. This is where order confirmations and the email verification link will be sent.
Enter the work email address of the requestor. Ensure this inbox is actively monitored — critical emails will arrive here.
Mobile Number
A contact phone number for the requestor, including the country code.
Select your country code from the dropdown (e.g., +1 for United States, +91 for India) and enter your mobile number. This is used for support contact purposes.
Contact Name (Delegation)
The name of a colleague who is authorised to download the certificate on your behalf (optional).
Leave blank if you will download the certificate yourself. Enter the delegate's name only if someone else will handle the download.
Email ID (Delegation)
The email address of the download delegate (optional).
Leave blank if you will download the certificate yourself. Enter the delegate's email if you filled in Contact Name above.
ℹ NOTE: The Certificate Download Delegation section is optional. Use it only when the person applying for the certificate is different from the person who will install it.
⚠ WARNING: Double-check the Requestor Email ID before clicking Next. An incorrect email address will result in verification emails going to the wrong inbox, blocking your certificate from being issued.
What to Do
1. Enter your full name in the Name field.
2. Enter the requestor's active work email address in Requestor Email ID.
3. Select your country code and enter your mobile number.
4. If a different person will download the certificate, fill in Contact Name and Email ID under Certificate Download Delegation.
5. Click Next.
STEP 4 - Certificate Information
This screen specifies the email address that will be secured by the S/MIME certificate. This is the most important field - it defines which email account the certificate will protect.

Field Reference
Field / Element
What It Is
What To Do
Use Pre-Verified Domains
A checkbox that, when ticked, populates the Email ID field from a list of domains that your organisation has already verified with the CA.
Tick this if your IT administrator has already verified your email domain in CERTInext. Otherwise, leave it unticked and type the email address manually.
Email ID *
The email address that this S/MIME certificate will be issued for. This becomes the identity bound to the certificate — i.e., the email account that will be digitally signed and encrypted.
Enter the full email address of the mailbox this certificate is meant for (e.g., yourname@yourcompany.com). This may be pre-filled from the CSR — verify it is correct.
⚠ WARNING: The Email ID entered here is permanently embedded in the certificate. If you enter the wrong email address, the certificate will be issued for the wrong mailbox and a new order will be required.
ℹ NOTE: If the Email ID is already populated from your CSR, review it carefully to make sure it matches the mailbox you intend to secure.
What to Do
1. If your domain is pre-verified, tick 'Use Pre-Verified Domains' and select your email from the list.
2. If not, type the full email address directly into the Email ID field.
3. Double-check the email address - this cannot be changed after submission.
4. Click Next.
STEP 5 - Additional Information (Optional)
This step is entirely optional. It allows you to attach metadata and extra notification settings to the order. Filling it in makes it easier to find and manage the order later.

Field Reference
Field / Element
What It Is
What To Do
Tags
Searchable labels you can attach to this order for filtering or categorisation purposes (e.g., 'Finance', 'Remote-Staff', 'Pilot-Project').
Click '+ Add Tag' to add one or more tags. This is optional but recommended if your organisation uses tags to manage certificates.
Order Remarks
A free-text field for any internal notes about this certificate request.
Type any relevant notes (e.g., 'Replacement for expired cert', 'For contractor onboarding'). This is optional.
KYC Documents
A checkbox that, when ticked, allows you to upload identity/Know Your Customer documents required for higher-assurance certificate profiles.
Tick this and upload the required documents only if your certificate type requires KYC verification. For a Simple MV-S S/MIME certificate, this is generally not required.
Additional Email Recipients
A checkbox that, when ticked, reveals a field where you can enter extra email addresses to receive order status notifications.
Tick this and add email addresses if other people (e.g., your IT manager) should also receive notifications about this order.
💡 TIP: Adding Tags and Order Remarks is highly recommended for organisations with many users. It makes it much easier to search for and identify specific certificates later.
What to Do
1. Optionally add Tags by clicking '+ Add Tag'.
2 Optionally type notes in Order Remarks.
3. If required, tick KYC Documents and upload the relevant files.
4. If other people should receive notifications, tick Additional email recipients and enter their addresses.
5. Click Next to proceed to the Order Summary.
STEP 6 - Order Summary & Payment
This is the final step before submission. Review all the information you have entered. You must agree to the Subscriber Agreement and then choose a payment method.

Order Summary Sections Explained
Field / Element
What It Is
What To Do
Product Information
A summary showing the Certificate Type and Product Name you selected in Step 1.
Verify that Certificate Type shows 'S/MIME Certificates' and the Product Name matches what you selected.
Certificate Information
Displays the Email ID entered in Step 4 - the mailbox this certificate will secure.
Confirm this email address is correct.
Payment Notice
A message stating that clicking 'Use Credits' will deduct the cost from your organisation's credit balance in CERTInext.
Read this notice carefully before proceeding.
Current Balance
The total available credit balance of your organisation in USD at the time of ordering.
Ensure this is greater than or equal to the Grand Total. If the balance is insufficient, contact your administrator to top up credits.
Grand Total
The total amount that will be charged for this certificate order in USD.
Verify this matches the Cost shown in Step 1.
Subscriber Agreement checkbox
A mandatory acknowledgement that you have read and agreed to the eSign Subscriber Agreement.
You must tick this checkbox before any payment button becomes active. Click the 'Subscriber Agreement' hyperlink to read the terms.
Save and Exit
Saves your application as a draft without submitting it.
Use this if you need to pause and come back later.
Pay Online
Pays for the certificate using a debit/credit card or other online payment methods.
Use this option if you are paying directly rather than using pre-loaded credits.
Use Credits
Deducts the Grand Total from your organisation's pre-loaded credit balance.
This is the most common payment method in enterprise environments. Click this to submit and pay instantly using credits.
⚠ WARNING: Once you click 'Use Credits' or 'Pay Online' and the order is confirmed, it cannot be cancelled or refunded without contacting eMudhra support. Review all details carefully before paying.
ℹ NOTE: If the Subscriber Agreement checkbox is not ticked, the Pay Online and Use Credits buttons will remain greyed out. You must tick the checkbox first.
What to Do
1. Review the Product Information and Certificate Information sections carefully.
2. Note the Grand Total in USD and confirm your organisation has sufficient credits.
3. Click the 'Subscriber Agreement' link and read the terms.
4. Tick the checkbox to confirm you agree to the Subscriber Agreement.
5. Click 'Use Credits' to pay from your organisation balance, or 'Pay Online' to use a card.
6. Wait for the confirmation page to load - do not close or refresh the browser.
PHASE 2 - POST-SUBMISSION: WHAT HAPPENS AFTER YOU PAY
After payment, the process moves partly to your email inbox. You will receive notifications and must complete an email verification step before your certificate is issued. Below is the full sequence of what happens.
STEP 7 - Order Confirmation - View Your Order Details
Immediately after payment, CERTInext displays the View Order page. This is your official order record. Save or bookmark this page for future reference.

What You Will See
Field / Element
What It Is
What To Do
Order ID
A unique numeric identifier for your certificate order (e.g., 2287274899).
Note this number. You will need it when contacting support or tracking your order.
Ordered Date
The date and time when the order was placed (UTC).
Verify this is the correct date.
Product
The certificate product you ordered.
Confirm it matches your selection.
Group
Your organisation name in CERTInext.
For reference only.
CA Source
The Certificate Authority that will issue the certificate (eSign).
For reference only.
Certificate Price
The cost charged for this certificate in USD.
For reference only.
Order Status
The current processing status of your order.
Should show 'Order Accepted' immediately after payment. This confirms payment was received.
Certificate Status
The issuance stage of the certificate.
Will initially show 'Pending for Approver'. This means the CA is reviewing the order before issuing.
Certificate Requestor Information
Name, email, and mobile number of the person who placed the order.
Verify your details are correct.
Certificate Information
The secured email address bound to this certificate.
Verify the email address is correct.
CSR Information (CN, Key Size, Algorithm)
Technical details extracted from your submitted CSR: Common Name (CN), the key size in bits (e.g., 2048), and the key algorithm (e.g., RSA).
For reference. A key size of 2048-bit RSA is industry standard.
Ordered By (User / Role)
The CERTInext user account that placed the order and their role.
For audit and reference purposes.
Renewal Notifications
Indicates whether automatic renewal reminder emails are turned on.
If set to 'Yes', you will receive reminders before the certificate expires. Recommended to keep enabled.
Additional Email Recipients
Any extra email addresses you added in Step 5 to receive notifications.
Review to confirm the list is correct.
Tracking Your Order
On the View Order page, click the three-dot menu (⋮) in the top-right corner of the order detail panel, then select 'Track Order Status'. A modal window appears showing a public Order Status Tracking URL.

Field / Element
What It Is
What To Do
Order Status Tracking URL
A unique, shareable URL that shows the real-time status of this specific order without requiring a CERTInext login.
Copy this URL for your records. Click 'Open URL' to view it in a browser, or 'Share URL' to send it to the certificate requester.
Open URL button
Opens the tracking page directly in your browser.
Click to verify the tracking page is working.
Share URL button
Sends the tracking URL by email to the Requestor Email ID associated with this order.
Click if the requestor needs the URL to track progress themselves.
STEP 8 - Order Confirmation Email
Shortly after payment, an automated confirmation email is sent to the Requestor Email ID. This email is for your records only - no action is required.

What the Email Contains
Field / Element
What It Is
What To Do
Subject line
ORDER #[Order ID] - Your Order is Successful
Identify this email by its subject line.
Order ID
Your unique order number for reference.
Keep this for your records.
Ordered Date
The date and time the order was placed (UTC).
For your records.
Product & Validity
The certificate product name and validity period.
For your records.
Identifier
The email address that the certificate will secure.
Verify this is correct.
Track Order button
A link to the public order tracking page.
Click this at any time to check the current status of your order.
Support contact
eMudhra support email and phone number.
Use this if you need help with your order.
ℹ NOTE: This confirmation email does NOT require any action. Simply keep it for your records.
STEP 9 - Email Verification - Act Within 24 Hours
This is the most time-sensitive step. Shortly after the order confirmation email, you (or the certificate subject - the person whose email is being secured) will receive a second email asking you to verify the email address.

About This Email
Field / Element
What It Is
What To Do
Subject line
ORDER #[Order ID] - Email Verification Link
Look for this subject line in your inbox.
Verify Email button
A large orange button linking to the emSign subscriber portal to complete email verification.
Click this button to begin verification. You will be taken to the emSign portal.
Expiry warning
A notice that the verification link expires in 24 hours.
Act promptly. If you miss the 24-hour window, you will need to request a new verification email from the order tracking page.
Other Order Information
A summary of the order (Product, Validity, Identifier) for reference.
Verify the identifier (email address) is correct before clicking.
Direct URL alternative
If the button does not work, a plain URL is provided that you can copy and paste into a browser.
Use this as a backup if the button fails.
⚠ WARNING: This verification email is sent to the email address that is being secured by the certificate (the Certificate Information email, Step 4) — NOT necessarily to the Requestor Email ID. Make sure the owner of that mailbox checks their inbox promptly.
💡 TIP: Check your spam or junk folder if you do not see the verification email within a few minutes. Add no-reply@certinext.io to your safe senders list to avoid this in future.
STEP 10 - Accepting Email Verification on the emSign Portal
Clicking the 'Verify Email' button in the verification email opens the emSign Subscriber Portal. This is a separate portal from CERTInext. Here you confirm that you own and control the email address being secured.

What You Will See
Field / Element
What It Is
What To Do
Page header
The emSign branded Subscriber portal page.
This is the correct destination - it is part of eMudhra's infrastructure.
Order details box
Shows the Order ID, Date Ordered, Product & Validity, and Order Status.
Verify this matches your order.
Verification prompt
A message reading: 'Please accept to verify your email ID ([your email address]).'
Read this carefully to confirm the email address shown is the one you intended to secure.
Accept button
An orange button that, when clicked, confirms you own and consent to securing this email address.
Click Accept to proceed.
ℹ NOTE: Only the person who controls the email address being certified should click Accept. This step proves to the CA that the certificate owner consents to being issued a certificate for that address.
After Clicking Accept

✔ SUCCESS: You will see a green success message confirming: 'Thank you for verifying your email ID and completing the Email Verification step successfully.' Your Order ID, Product, and Validity are confirmed on this screen.
A 'Proceed for Verification' button appears. Click it to move to the full verification steps overview.
STEP 11 - Verification Steps Overview
After completing email verification, the emSign portal shows you a checklist of all the steps required before your certificate can be issued. This screen also serves as the main progress tracker.

Verification Steps Explained
#
Step
What It Means
Who Does It
1
Submit CSR
Your Certificate Signing Request has been received and validated by the CA.
Completed during application (Step 2)
2
Subscriber Agreement
You accepted the eSign Subscriber Agreement during payment (Step 6).
Completed during payment
3
Email Verification
You clicked Accept to verify ownership of the email address (Step 10).
You complete this (Step 9–10)
4
Certificate Download
The CA has issued the certificate and it is ready for you to download.
Automatic — CA issues; you download
Certificate Issued Message
Once all three prerequisite steps are complete, Step 4 (Certificate Download) will show the status 'Certificate Issued' in green. The page will display the following message:
✔ SUCCESS: 'Your certificate has been issued and ready for download. An email containing certificate download instructions has been sent to your email ID. Your certificate is based on the CSR submitted by you. Please ensure to import/use the certificate against the same key-pair from where the CSR was generated. Please follow the necessary instructions in your download notification email to download your certificate.'
ℹ NOTE: A 'Resend Email' button is available on this screen if you did not receive the download notification email. Click it to receive another copy.
STEP 12 - Certificate Ready for Download - Email Notification
After the CA issues your certificate, a third email is sent to the Requestor Email ID. This email contains the link to download your certificate file.

What the Email Contains
Field / Element
What It Is
What To Do
Subject line
ORDER #[Order ID] - Your Certificate is ready for download
Look for this subject line in your inbox.
Order ID
Your unique order number.
For your records.
Ordered Date
The date and time the order was placed (UTC).
For your records.
Product & Validity
The certificate product name and validity period.
For your records.
Identifier
The email address secured by this certificate.
Confirm this is correct.
Download Certificate button
An orange button linking directly to the certificate download page on the emSign portal.
Click this button to download your certificate.
Alternative URL
A plain-text download URL below the button that you can copy and paste into a browser.
Use this as a backup if the button does not work.
ℹ NOTE: The download link in this email may expire. If you receive this email, download your certificate promptly. If the link has expired, go to CERTInext, open your order, and use the tracking URL to find a fresh download link.
STEP 13 - Downloading Your Certificate
Clicking the Download Certificate button in the email takes you to the emSign Subscriber Portal download page. From here you can save your certificate file to your computer.

What You Will See
Field / Element
What It Is
What To Do
Success message
A green tick with the message: 'Thanks for completing the necessary steps. Your certificate has been issued and ready for download. To continue further, please click Download Certificate.'
This confirms the certificate is ready.
Order ID
Your unique order number.
For reference.
Product & Validity
The product name and validity period.
For reference.
Download Certificate button
An orange button that initiates the download of a ZIP archive containing your certificate.
Click this button to start the download.
The Downloaded File

Your browser's download manager will show a ZIP file named after your Order ID (e.g., 2287274899.zip). This archive typically contains:
• Your certificate file (.crt or .cer format)
• Any intermediate CA certificate files needed for the chain of trust
• A readme or instructions file (if provided by the CA)
⚠ WARNING: The certificate in this ZIP file must be imported against the same key-pair from which you originally generated the CSR. Do not import it with a different key. Contact your IT team if you are unsure how to import the certificate into your email application.
ℹ NOTE: On most computers, downloading a ZIP file causes it to appear in the Downloads folder. Right-click the ZIP file and select 'Extract All' (Windows) or double-click to unzip (Mac) before proceeding with import.
Last updated
