Each domain name on an SSL Certificate order is validated by one method, and that method can be changed at any time before the SSL Certificate is issued. You might switch because the original method is no longer convenient, because you have moved to a different server, or simply because another method is quicker for you.
Changing the method is done in the tracking system and takes only a few minutes. This page walks through the whole procedure for someone who has never done it before.
Reasons for Changing Your Method
The five methods all prove the same thing, that you control the domain name, so the one to use is simply the one that is easiest for you at the time. If you no longer have access to the mailbox behind an approver e-mail address, or you have moved your website to a server where placing a file is awkward, another method will suit you better.
A common reason is moving from a file based method to a Domain Name System (DNS) method, because the file methods carry extra conditions that the others do not. Choosing the method that matches where you have access is what keeps validation straightforward. Learn About The Validation Procedure 🔗
Preparation Before You Start
You need your Certificate Authority (CA) Reference, which is the nine to twelve digit number sent when your order reached the Certificate Authority (CA). This is not your Trustico® order number, and the order number will not grant access. Learn About Telling the Two Numbers Apart 🔗
You also need access to whichever method you intend to switch to, whether that is a mailbox, your Domain Name System (DNS) records, or the web server for the domain name. Having it ready before you begin means you can put the new record in place straight away.
Accessing the Tracking System
Access is granted for each license rather than through a general account, so there is nothing to set up in advance. On the first screen you provide your Certificate Authority (CA) Reference, the domain name covered by the SSL Certificate, and the brand of the product you ordered, which is chosen from a list. A human verification check appears on the same screen.
Note : The tracking system supports traditional SSL Certificates only. A Certificate as a Service (CaaS) product validates automatically through your own Automatic Certificate Management Environment (ACME) client, so there is no method to change by hand.
If a reference is rejected, the most common cause is that the order number was entered in place of the Certificate Authority (CA) Reference. A second screen may then ask for a short security code, which you enter to continue. Learn About The Tracking System 🔗
Opening Domain Control Validation
Once you are signed in, the dashboard shows the current state of the license. While an SSL Certificate is awaiting validation, the action you want is Complete Validation, which opens the Domain Control Validation (DCV) Status page.
That page lists every domain name on the license, each with the method it is currently set to use and its current status. This is where the method is changed.
Step 1 : Selecting Another Method
Five methods are offered for each domain name : Approver E-Mail Validation, HTTP File Validation, HTTPS File Validation, CNAME DNS Validation, and DNS TXT Validation. Choose the one you would like to switch to.
As soon as you pick a method that differs from the current one, the domain panel shows a New Method line confirming your choice. Nothing is changed yet, so you are free to look at what each method requires before you commit to it.
Where a license covers many domain names, a Domain Name System (DNS) or file based method is usually less work than approver e-mail, which has to be actioned for each address in turn. The standard methods also allow one configured domain name to be applied across the rest in a single step.
Approver E-Mail Validation
A list of pre-approved addresses at your domain name is shown, and you select one. A confirmation e-mail is sent to that address, and the recipient follows the instructions it contains. The mailbox must already exist and be able to receive e-mail, so create it first if it does not.
Approver e-mail is being phased out and is already unavailable on the newer Certificate as a Service (CaaS) products. Where you have a choice, one of the other methods is the better habit to build.
Domain Name System (DNS) Validation
The two Domain Name System (DNS) methods use either a CNAME record or a TXT record. For each, an Authorization Domain Placement choice is shown first : the Certificate Authority (CA) accepts the record at any of the listed domains, so pick the one whose Domain Name System (DNS) you control.
The record name and value are then displayed for you to add to your zone, and the Check Record Validity button confirms it is in place. These methods suit anyone who administers their own Domain Name System (DNS) records, and the TXT method is the one to use for a Wildcard SSL Certificate.
File Based Validation
The two file methods place a small file on your web server, reachable over either Hypertext Transfer Protocol (HTTP) on port 80 or Hypertext Transfer Protocol Secure (HTTPS) on port 443. The file URL and its exact content are shown for you to create.
Important : For the file methods, the file must be reachable at the root domain and at every subdomain the SSL Certificate secures. A file placed in one location alone will not validate the others, and the file methods cannot be used for a Wildcard SSL Certificate.
These methods suit anyone with straightforward access to the files served on the website, though they carry the condition above, which the Domain Name System (DNS) and approver e-mail methods do not.
Step 3 : Submitting Each Domain
With the new record or file in place, use Submit DCV Method for Viewed Domain to apply the change to the domain name currently being viewed. Where a license covers only one name, that is all there is to it.
For a license with several names, there is a quicker route. Once one domain name has been configured, a button above applies the same settings to all of the domain names at once, so you do not have to set each one by hand. It only covers domain names that have been configured, which is another reason the Domain Name System (DNS) and file methods suit large lists better than approver e-mail.
Confirming the Change
Give the Certificate Authority (CA) time to work. After you submit, it runs its own checks on your server every ten to fifteen minutes or so, rather than the moment you press the button, so a short wait is normal. Use Check Record Validity to confirm your own record while you wait, and Refresh Page to see the current status.
Important : Avoid resending approver e-mails, switching the method back and forth, or pressing Retry Validation Checks many times in quick succession. The Certificate Authority (CA) may respond by pausing its checks or reverting to its own schedule, which delays issuance rather than hastening it.
Where you have switched to a Domain Name System (DNS) method, also allow time for the change to propagate, since a cached earlier answer can delay the check. Leave the new record or file in place until the SSL Certificate has actually been issued. Learn About Allowing for Propagation 🔗
Organization and Extended Validation Requirements
Domain Control Validation (DCV) proves you control the domain name, but an Organization Validation (OV) or Extended Validation (EV) license also verifies your organization, and that part can carry additional requirements. These are handled by the Certificate Authority (CA) and are generally shown on its own validation portal.
The dashboard includes a CA Portal Direct Access button that takes you straight there, and the Certificate Authority (CA) usually sends the same details by e-mail. Completing those requirements is separate from choosing a Domain Control Validation (DCV) method, and both must be finished before the SSL Certificate is issued. Learn About Organization Validation Requirements 🔗
When Something Does Not Work
Validation that is submitted but does not complete usually points at your own setup rather than the Certificate Authority (CA). A record removed too early, a change that has not yet propagated, or a web server or Domain Name System (DNS) that restricts access by country or address range are the common causes.
The automated checks run from several locations around the world, and all of them must agree, so the new record or file needs to be reachable globally and left in place until issuance. Learn About The Automated Corroboration Checks 🔗
If the license shows as validated and the validation screens are no longer available, yet no SSL Certificate has been issued, the cause is usually elsewhere. Outstanding Organization Validation (OV) or Extended Validation (EV) requirements, or a Certification Authority Authorization (CAA) or Multi-Perspective Issuance Corroboration (MPIC) problem, are the usual reasons, and each is reviewed rather than resubmitted here. Learn About Certification Authority Authorization (CAA) Records 🔗
After the Method Completes
Once the new method completes, the remaining checks finish on their own and the SSL Certificate is issued, usually within minutes. You then return to the dashboard to download it. Learn About Reissuing Step by Step 🔗