📄️ What is Phone Verification
Phone verification generally refers to enterprise verification, which is usually conducted using the phone number or email address registered on a CA-recognized third-party platform. Its main purpose is to confirm the real existence of the applying enterprise, ensure that the person contacted is indeed an employee of the applying enterprise, and prevent unauthorized use of enterprise information.
📄️ How to Check If DNS Resolution Is Configured Successfully
This article mainly introduces how to check if DNS resolution is configured successfully. You can check the resolution result by using a DNS lookup tool, and it includes sample screenshots of successful and failed resolution. For cases where the displayed record value is inconsistent with the verification value, troubleshooting ideas are also provided to help you resolve DNS resolution issues quickly.
📄️ Can I apply for a certificate for a Chinese domain name?
Racent SSL fully supports certificate requests for Chinese domain names, providing application guides for all types of DV/OV/EV SSL certificates for Chinese domain names and browser compatibility instructions
📄️ What Documents Are Required to Apply for a Certificate
Detailed explanation of the required documents and differences between DV and OV SSL certificate applications: DV only requires Domain Control Validation (DCV), while OV requires real-name information such as enterprise organization name, address, and contact person, with document submission specifications and review key points included.
📄️ How to apply for an SSL certificate when the public IP cannot open ports?
For the difficulty of applying for an SSL certificate when ports 80/443 cannot be opened on the public IP, Racent provides two solutions: CFCA port-free validation and intranet certificates, supporting direct IP signing and private network encryption requirements.
📄️ Is it required that the subject bound to a certificate matches the subject bound to the domain name?
Most certificates do not require consistency, and you can choose according to your own needs. Only CFCA certificates require consistency. If they are inconsistent, you need to provide proof that the subject applying for the certificate and the subject bound to the domain name have an affiliate or parent-subsidiary relationship.
📄️ How long does it usually take to issue an OV certificate
As long as the customer can successfully complete the verification process, an OV certificate is generally issued within two to three days.
📄️ What procedures are required for OV certificate organization validation
OV certificate organization validation generally uses phone (email) verification; for some brands of certificates (such as CFCA, sslTrus domestic root), validation can be completed via stamped application forms.
📄️ If I selected email validation when submitting the application, can I change to another validation method?
You can change to another validation method. Click the details of the corresponding domain name in the backend, and you can switch to DNS validation/file validation. If you need to change the email address used for email validation, please contact us. (IP certificates only support file validation, and wildcard certificates do not support file validation)
📄️ How long does it take to issue a certificate after submitting a certificate request
If the CSR was generated when you submitted the certificate request on our platform, you can re-download the private key from the order. However, if the CSR was generated externally, you will need to submit a new certificate request or reissue the certificate.
📄️ How to Add DNS Records and Verify DNS Resolution
This article explains in detail how to add DNS resolution records on a domain management platform, including step-by-step instructions for configuring host records, record values, and record types. It also provides multiple methods and recommended tools to verify whether DNS resolution has taken effect. You will learn how to add DNS resolution records (A/CNAME/MX records) with hands-on guidance, quickly check the resolution status using online tools, and resolve common issues that cause DNS resolution not to take effect.
📄️ Can I apply for a certificate if the domain name has no ICP filing?
A clear answer to the feasibility of applying for an SSL certificate for a domain name without ICP filing: DV certificates can be obtained quickly via DNS or file verification without ICP filing, with additional requirements for OV/EV certificates explained.
📄️ Why is the certificate not issued even after validation is completed
There are two reasons why an SSL certificate has not been issued: Certificate synchronization is required; you may need to wait for the issuance process. Please refer to "How long does it take to issue a certificate after submitting a request" for issuance time reference. The relevant SSL certificate validation has not been completed, so you need to confirm whether the validation has been fully completed.
📄️ Can I apply for a certificate with a public IP address
You can apply for an SSL certificate for a public IP address! Brands such as sslTrus, Sectigo, and Digicert require port 80 or 443 to be open for file validation. CFCA certificates have no port restrictions and are suitable for special network environments. Learn about the port requirements and solutions for public IP certificate issuance from different brands.
📄️ Is there a required order for OV certificate validation?
When validating an OV SSL certificate, is there a mandatory order for Domain Control Validation and organization validation? For sslTrus domestic root OV certificates, organization validation generally needs to be completed first before the DCV value is issued.
📄️ How Long Are Record Values Valid When Applying for Certificates
How long do I need to keep DNS record values when applying for an SSL certificate? Sectigo/Positive/sslTrus records are permanently valid, CFCA requires 360 hours, and Digicert/Thawte/Rapid/Globalsign require 30 days. Detailed explanation of DNS validation validity periods for each brand.
📄️ Reasons for the Discontinuation of Sectigo AAA Root Certificate Issuance
Sectigo's "AAA Certificate Services" root certificate ceased issuance on April 15, 2025, due to new Mozilla/Chrome regulations (root certificate validity period ≤ 15 years). Certificates issued by its subordinate CAs are no longer trusted in new versions of Chrome and Firefox. Check policy impacts and solutions.
📄️ Will the main domain of a GeoTrust multi-domain certificate come with a free www entry?
When applying for a GeoTrust multi-domain certificate, entering a main domain (such as domain.com) will grant the corresponding www main domain (www.domain.com) for free, which does not occupy an additional domain slot. Other subdomains must be added manually. View detailed coverage rules for multi-domain certificates.
📄️ Which brands' multi-domain certificates include the www domain for the primary domain at no extra cost
Currently, only GeoTrust Flex multi-domain certificates include the www primary domain (www.domain.com) when you fill in the primary domain (e.g. domain.com), which does not consume your domain slot. All other brands (such as Sectigo/Digicert/Comodo, etc.) require you to manually add the www domain.
📄️ Possible Reasons for File Validation Failure
Key reasons for SSL certificate file validation failure: 1) Incorrect file path (file not placed in /.well-known/pki-validation/); 2) Port restrictions (non-CFCA certificates require port 80/443); 3) Missing validation for multiple domains; 4) Wildcard certificates do not support file validation; 5) Server blocking the .well-known directory; 6) Firewall interception on overseas servers. Step-by-step troubleshooting guide included.
📄️ How often does a CA perform certificate polling checks?
There is no fixed schedule for a CA's polling checks of DNS records, but historical data reveals the core window periods: first check (3-5 minutes), second check (20-30 minutes), and subsequent checks (<1 hour). Configuring globally effective DNS records immediately is the key to ensuring second-level certificate issuance, with an authoritative configuration guide attached.
📄️ Is it abnormal if a certificate is not issued for a long time? What should I do?
For unissued certificates, first troubleshoot the DNS configuration: confirm that the TXT record value/host name is correct and has taken effect globally. Manual validation triggering is supported, and please note the differences in record validity periods across CAs (permanent for Sectigo / 30 days for DigiCert / 15 days for CFCA). Global propagation detection tools and emergency handling channels are provided.
📄️ 锐安信 SSL OV Certificate Application: How to Verify Without Contact Information on Third-Party Platforms
When applying for a 锐安信 SSL OV certificate, if no contact information is registered on third-party platforms, you can verify using the official website contact information on Qichacha/Aiqicha, or the phone number registered in bidding information. Learn about alternative methods for enterprise information verification for OV certificates.
📄️ Requirements for DigiCert OV certificate official website contact information verification
When applying for a DigiCert OV certificate, you can use the contact information on the official website for verification, but the website must meet the following requirements: 1. It appears on the first page of Baidu/Google search results for the company name; 2. The organization name in the website title or footer copyright is exactly the same as the organization name applying for the certificate; 3. The contact information page is a normal web page (not a login page).
📄️ How to Unblock Overseas Incoming Calls
Provides specific operation steps for China Mobile, China Unicom and China Telecom to unblock overseas incoming calls, including contacting customer service, configuring settings via WeChat official accounts and using SMS commands, to help users resume receiving calls from international regions as well as Hong Kong, Macao and Taiwan.
📄️ Alternative Validation for sslTrus/Sectigo Certificates Without Valid Contact Information
If no valid contact is available when applying for sslTrus or Sectigo certificates, you can update your registered information via Qichacha/Aiqicha/114best, or use lawyer letter validation (which requires signature from a registered lawyer; the CA will verify the lawyer's qualifications).
📄️ Alternative verification for Digicert/Geotrust certificates when no contact information is available
If no valid contact information is available when applying for Digicert and Geotrust certificates, you can update the registration information via Qichacha/Baidu Maps/114 directory assistance, or provide a water/electricity/gas/phone bill from the past three months (which must show the company name, address and phone number) for verification.
📄️ Difference Between sslTrus EV and OV Certificate Validation Processes
sslTrus EV and OV certificates cover the same validation items (Domain Control Validation (DCV) + agreement email + organization validation) and follow consistent validation methods, but OV certificates are issued directly upon completion of validation, while EV certificates require a secondary review (1-2 business days) after initial validation is completed.
📄️ Validation Process Differences Between Digicert EV and OV Certificates
The validation content for Digicert EV and OV certificates is the same (Domain Control Validation (DCV) + organization validation), but EV organization validation only supports verification via phone number (sources such as Qichacha, Baidu Maps, 114 directory assistance), and does not support contact information from email or official websites. You need to process the approve email after validation.
📄️ Reissue Rapid DV certificates with EKU
Rapid DV certificates support reissuance with EKU (Extended Key Usage) configuration, which can be specified as needed during reissuance.
📄️ Sectigo OV Validation Supports Temporary Modification of Official Website Contact Information
Sectigo organization validation supports temporary modification of the contact information on your official website to complete company information verification. You can restore the original contact information as needed after the validation is passed.
📄️ CSR and DN Consistency Requirements for CFCA Certificate Retrieval
When retrieving a CFCA certificate, the CSR information must be completely consistent with the issued certificate DN, otherwise the retrieval will fail. If the initial CSR is inconsistent with the issued DN information, you need to regenerate the CSR based on the issued DN before retrieving the certificate.
📄️ Which certificate brands support Attorney Letter validation
Sectigo, sslTrus, and GlobalSign brands support Attorney Letter validation. When choosing the Attorney Letter method, you must use the attorney letter template provided by the CA, and templates provided by customers themselves are not supported.
📄️ DNS validation record types supported by SSL certificate brands
Sectigo and sslTrus support CNAME and TXT records for Domain Control Validation. DigiCert and GeoTrust support only TXT records. GlobalSign supports only TXT records. CFCA supports only TXT records.
📄️ Can I apply for a CFCA certificate without being the domain owner
You may apply for a CFCA certificate without being the domain owner, but the applying organization must be a subordinate unit or directly affiliated unit of the domain owner; otherwise, only the domain owner is eligible to apply.
📄️ What should I do if I cannot affix the official seal on the application form when applying for a CFCA certificate
If you cannot affix the official seal on the application form when applying for a CFCA certificate, you may skip submitting the sealed application form and instead use the contact information registered on third-party platforms recognized by the CA, such as Qichacha, for verification
📄️ What other Taiwan enterprise verification platforms does Sectigo support besides Dun & Bradstreet
Besides Dun & Bradstreet, Sectigo's Taiwan enterprise verification platforms also support the Business Basic Information/Import/Export Business Registration System, Commercial and Industrial Registration Public Information Inquiry Service, and Chinese Yellow Pages Online Directory (Taiwan organizations).
📄️ What are the Domain Control Validation rules for multi-domain certificates
For multi-domain certificates, if they include domains under the same primary domain, only one validation is required for that primary domain; if all domains are different, each domain must be validated separately.
📄️ Can bidding documents be used to complete organization validation?
During the organization validation process for SSL certificates, in addition to the contact information registered on third-party platforms recognized by the CA, certificates from some brands can also be validated using the phone number listed on bidding documents.
📄️ Will an organization name change affect issued certificates?
After a certificate is issued, if the name of the organization that applied for the certificate changes, it will not affect the already issued certificate, which will continue to display the original organization name.
📄️ Does WoTrus Super Fast Guomi SSL Certificate Support Adding New Domains via Reissuance
Does WoTrus Super Fast Guomi SSL Certificate support adding new domains through reissuance after issuance?
📄️ What to do if CAA records on the domain prevent SSL certificate issuance during application
What to do when CAA records on the domain prevent certificate issuance
📄️ What to do if the organization name exceeds 64 characters when applying for an enterprise-level certificate
What should I do if the organization name exceeds 64 characters when applying for an enterprise-level certificate?
📄️ Does an S/MIME email certificate order support binding to multiple accounts?
Does an S/MIME email certificate order support binding to multiple accounts?
📄️ What materials are required for individuals to apply for a Sectigo OV SSL certificate?
What materials are required for individuals to apply for a Sectigo OV SSL certificate?
📄️ Does WoSign Guomi SSL Certificate Support Issuance for Intranet IPs and Domain Names
Does WoSign Guomi SSL certificate support issuance for intranet IPs and domain names?
📄️ What are DigiCert's email sender addresses?
What are DigiCert's email sender addresses?
📄️ What methods are available to distinguish the DN number from the first year when submitting a new application for a CFCA Guomi (SM cryptography) certificate in the second year
What methods are available to distinguish the DN number from the first year when submitting a new application for a CFCA Guomi (SM cryptography) certificate in the second year
📄️ When should I get a new certificate for an expiring certificate?
When should I obtain a new certificate if my applied certificate is about to expire but its total validity period has not yet ended?
📄️ How to obtain a new certificate when the current certificate is about to expire
If the currently applied certificate is about to expire but the total validity period of the certificate has not yet ended, how can I obtain a new certificate?