Skip to main content

SSL for domains

Find out everything you need to know about SSL certificates for domains at centron: single, multi and wildcard certificates, DV, OV and EV validation, and the full validation processes.

SSL Certificates for Domains

SSL certificates are an essential part of internet security, as they are used on web, email and application servers, as well as on many other platforms. Each SSL certificate is valid specifically for the domain(s) or SANs (Subject Alternative Names) for which it was issued.

Types of certificates

Our SSL certificates are flexible and tailored to your specific requirements:

  • Single certificate: Valid for a single domain. Example: the domain ‘domain.de’ with a Sectigo Positive SSL (DV).
  • Multi-domain certificate: Valid for multiple domains. The cost varies depending on the number of domains. These certificates can also be combined with wildcard certificates. Example: Domains ‘domain.de’, ‘domain.com’, ‘domain.eu’ with a Sectigo Positive SSL Multidomain (DV).
  • Wildcard certificate: Valid for a main domain and all associated subdomains. Example: ‘*.domain.de’ covers ‘domain.de’, ‘www.domain.de’, ‘test.domain.de’ etc., issued as a Sectigo PositiveSSL Wildcard (DV).

Types of validation

SSL certificates vary in terms of their validation methods:

  1. Domain-validated certificate (DV): This is the most basic and cost-effective option, in which only domain ownership is verified, usually via a confirmation email.
  2. Organisation-Validated Certificate (OV): In addition to email validation, this involves a telephone verification of the organisation, based on official registers.
  3. Extended Validation (EV) certificate: The highest level of authentication. In addition to the DV and OV validation steps, a detailed verification process is required, including the submission of specific identification documents.

Contents of an SSL certificate: Regardless of the type of validation, SSL certificates contain:

  • Domain name
  • Validity period
  • For OV/EV: Company name
  • For EV: Additional identification features such as the ‘green’ address bar in the browser

Areas of application:

  • DV certificates are suitable for intranets, small websites, forums, blogs and mail servers.
  • OV certificates are ideal for online shops and medium-sized corporate websites.
  • EV certificates offer the highest level of security and are suitable for platforms where customer trust is crucial.

With these versatile SSL certificate options, you can enhance the security and trustworthiness of your online presence.

Validation process

Depending on the type of certificate you have chosen, you will need to complete a varying number of steps to validate your SSL certificate.

Please note: None of these calls are made by centron GmbH; they are made by the service provider PSW Group on behalf of the certification authority Sectigo.

Domain validation | domain-validated SSL certificate (DV)

You can validate your domain either by email, hash or CNAME.

Our tip: If your domain is managed by centron and you manage it via the web panel, you can have your certificates issued fully automatically using CNAME validation. ccenter will take care of all the validation steps for you.

Email validation

You can choose from five different email addresses on your domain to which the certification authority will send an email. This email contains a validation code and a link which you must open in your browser to enter the code. Once this has been confirmed, your certificate will be available for download shortly afterwards.

The following email addresses are available (replace DOMAIN.DE with your own domain in each case):

Hash validation (HTTP/HTTPS hash)

You will be provided with a unique file name and hash value, which the file must contain, and which you must place in your domain’s web directory. The file must be stored under a specific file path so that the hash value can be accessed via a specified URL in the browser.
Path in the web directory: \.well-known\pki-validation\
You can upload the file using the File Manager (Windows hosting: Web Panel → Hosting Area menu → File Manager / Instructions for Linux hosting) or via FTP.
This validation type is not available for wildcard certificates.

Example of an HTTP hash:

URL at which the hash value must be accessible in the browser (default):

http://centronhosting.de/.well-known/pki-validation/ABCDEFGHIJKLMNOPQRSTUVWXYZ123456.txt

Hash value:

123456abc7890deFG1234HijKLMN567890123OpqRsTUvW1234xYz567890Abc13
comodoca.com
1a2b3c4567

You may need to create the folder locally on your PC first and then upload it, as it is not possible to create a folder with special characters at the start using standard methods.
Open PowerShell and enter the following command to navigate to your desktop:
cd ~\Desktop
Create a folder there called ‘.well-known’:
mkdir .well-known
You will find the newly created folder on your desktop. You can now upload this folder to the web server using a file manager or via FTP.

Path where the file must be stored (Windows hosting): Please note the home folder specified in the web panel (see the following article).

 centronhosting.de\web\.well-known\pki-validation\ABCDEFGHIJKLMNOPQRSTUVWXYZ123456.txt 

Path where the file must be stored (Linux hosting):

 httpdocs\.well-known\pki-validation\ABCDEFGHIJKLMNOPQRSTUVWXYZ123456.txt 

or

 centronhosting.de\.well-known\pki-validation\ABCDEFGHIJKLMNOPQRSTUVWXYZ123456.txt 

File contents:
Hash value

Once the hash value has been stored, you can test the call in your browser. The result should look like this:

CNAME validation

In this case, a CNAME DNS record must be defined. This record must be added to the DNS zone of the domain for which the SSL certificate is to be issued.

Here is an example of what such a CNAME record looks like:

_1234567890abcdefghijklmnopqrstuv.centronhosting.de
CNAME
abcdefghijklmnopqrstuv1234567xyz.cdefghijklmnopqrstuvwxy135792468.comodoca.com

This record must be added to the DNS zone as follows:

Name Domain (may need to be omitted or separated from the name by a full stop)TypeContent (in the web panel: IP)
_1234567890abcdefghijklmnopqrstuv centronhosting.deCNAMEabcdefghijklmnopqrstuv1234567xyz.cdefghijklmnopqrstuvwxy135792468.comodoca.com
    

This article will help you add a DNS record in Webpanel.

Organisation Validation | Organisation Validated SSL Certificate (OV)

For certain SSL certificates, organisation validation is carried out in addition to domain validation. The following requirements must be met for this:

  • Validation documents must be submitted to the PSW Group
  • Validation by telephone

Validation documents

  • the organisation specified is registered in a public Register

    • Public Register (for organisations in Germany; otherwise, similar to Register):
      • Commercial Register
      • Register of Associations
      • Register of Co-operatives
  • For companies not entered in the Commercial Register, a certificate may be issued in the name of an individual; the following is required for this:

    • An entry in the UPIK database
    • or a business registration, including a telephone call to the Trade Register Office
    • or a document confirming face-to-face validation, issued by a notary
  • Private individual

    • Entry in the UPIK database
    • or a document confirming face-to-face verification, issued by a notary

Validation by telephone

The telephone verification is carried out with the contact person specified when the SSL certificate was ordered. This person must also be contactable on the telephone number provided at the time of ordering. This telephone number cannot be changed. However, it is possible for the call to be answered on the number provided in the order and then forwarded to an extension, mobile number or similar.

For telephone validation, there must be a contact entry in one of the following databases:

Extended Validation | Extended Validation SSL Certificate (EV)

In addition to domain and company validation, Extended Validation includes the following requirements:

  • Confirmation of business activity
  • Confirmation of the business address
  • Verification of the employment status and authorisation of the main contact person
  • Sectigo SSL Subscriber Agreement (download here)
  • EV Certificate Request Form (download here)

Confirmation of business activity

The company has been in existence for more than three years and …

  • is registered in the commercial Register
  • or can provide evidence of business activity in the form of
    • a credit institution with which the company holds a bank Account
    • a legal letter from Sectigo, issued by a solicitor or notary from the country in which the organisation operates, including a telephone call to the solicitor or notary

Confirmation of business address

  • The address is a physical address (not a PO box)
  • The organisation’s address is listed as a valid business address in the commercial Register entry for the (subsidiary) company
  • or can be confirmed by one of the following authorities
    • Commercial Register (or equivalent government Register Register for company registration)
    • Dun & Bradstreet (D&B) report
    • Legal letter from Sectigo, issued by a solicitor or notary from the country in which the organisation operates, including a telephone call to the solicitor or notary

Verification of the contact person’s employment status and authorisation

  • The contact person specified in the order is employed by the company. Employment is verified as follows:

    • The contact person is listed as a shareholder, managing director or authorised signatory in one of the following documents
      • public Register (Commercial Register, Register of Associations or Register of Co-operatives)
      • Dun & Bradstreet (D&B) report
      • Confirmation of the main contact person’s employment status by the company’s HR department
      • Legal letter from Sectigo, issued by a solicitor or notary from the country in which the organisation operates, including a telephone call to the solicitor or notary
  • The contact person is authorised to manage an EV certificate on behalf of the company

  • The contact person has been authorised by their line manager to purchase an EV certificate on behalf of the company

    • Confirmation from the line manager is provided if they are listed in the Companies Register or if the HR department confirms their employment
    • Authorisation is also confirmed in the EV contract (Sectigo SSL Subscriber Agreement)
    • If the line manager does not hold the required position within the company, a line manager with an equivalent title or the HR department may provide the authorisation