Skip to main content

Is it abnormal if a certificate is not issued for a long time? What should I do?

Failure to issue a certificate in a timely manner may indicate an abnormality, and the most common cause is failed DNS validation. Please troubleshoot as follows:

  1. Check DNS configuration immediately (top priority!)

    • Confirm that the value of the required resolution record (such as TXT) and the host record are completely correct.
    • Confirm that the record has taken effect globally (you can use the online DNS check tool).
  2. Manually trigger validation

    • Log in to the console and locate the certificate order.
    • Click the "Validate" button.
  3. Pay attention to the record validity period

    • Sectigo/sslTrus/PositiveSSL: Records are valid long-term.
    • DigiCert/GeoTrust/RapidSSL/Thawte/GlobalSign: Records are valid for approximately 30 days.
    • CFCA: Records are valid for 15 days. Reconfiguration is required upon expiration.