Is it abnormal if a certificate is not issued for a long time? What should I do?
Failure to issue a certificate in a timely manner may indicate an abnormality, and the most common cause is failed DNS validation. Please troubleshoot as follows:
-
Check DNS configuration immediately (top priority!)
- Confirm that the value of the required resolution record (such as TXT) and the host record are completely correct.
- Confirm that the record has taken effect globally (you can use the online DNS check tool).
-
Manually trigger validation
- Log in to the console and locate the certificate order.
- Click the "Validate" button.
-
Pay attention to the record validity period
- Sectigo/sslTrus/PositiveSSL: Records are valid long-term.
- DigiCert/GeoTrust/RapidSSL/Thawte/GlobalSign: Records are valid for approximately 30 days.
- CFCA: Records are valid for 15 days. Reconfiguration is required upon expiration.