
with the expansion of website business, the number of subdomains continues to increase, and applying for SSL certificates for each subdomain alone is not only time-consuming and laborious, but also increases maintenance costs. The emergence of pan-domain SSL certificates solves this pain point. It can protect the main domain name and all sub-domains at the same level at one time, and greatly improve the efficiency of certificate management. This article will share the application operation skills of pan-domain SSL certificates in an all-round way from pre-preparation, certificate selection, application process to post-maintenance to help website managers successfully complete certificate deployment and build a strong website security defense line.
before officially launching the pan-domain SSL certificate application process, make sufficient preparations to avoid various problems in the application process and improve the application efficiency.
1 Confirm domain ownership and management
must first ensure that they have the complete ownership and management of the target main domain name, because the application for the pan-domain SSL certificate is based on the main domain name. You need to prepare the account information of the domain name registrar and the operation authority of the domain name resolution console. The subsequent verification process needs to complete the domain name attribution verification through the resolution operation.
2, sort out the scope of subdomains to be protected
sort out the same-level subdomains currently in use and planned to be used in the future in advance to clarify the coverage of the pan-domain SSL certificate. Although the pan-domain SSL certificate can cover all the same-level subdomains, planning in advance can help to verify the validity of the certificate more accurately in the future, while avoiding security bugs caused by factor domain omissions.
3, prepare corporate or personal verification materials
depending on the type of pan-domain SSL certificate selected, the required verification materials are also different. DV-type certificates only need to verify the ownership of the domain name, while OV-type and EV-type certificates need to provide qualification materials such as business licenses and organization code certificates. Individual applicants need to prepare identity materials such as ID cards. Sorting out in advance can speed up the review.
there are various types of pan-domain SSL certificates on the market, different types of certificates have obvious differences in verification level, security strength and applicable scenarios, and need to be reasonably selected according to their own needs.
1. Select the certificate type according to the verification level
pan-domain SSL certificate is mainly divided into three verification levels: DV, OV and EV. DV-type pan-domain SSL certificate verification process is the simplest, only need to verify domain name ownership, fast audit speed, suitable for personal blogs and small information websites; OV-type pan-domain SSL certificate needs to verify enterprise identity information, the certificate will display the enterprise name, suitable for small and medium-sized enterprises official website; EV-type pan-domain SSL certificate verification is the strictest, the browser address bar will display the green enterprise name, suitable for finance, e-commerce and other websites with extremely high security requirements.
2, choose the encryption algorithm according to the security requirements
different pan-domain SSL certificates adopt different encryption algorithms, the current mainstream encryption algorithms are RSA and ECC. The RSA algorithm has strong compatibility and can be adapted to most browsers and server environments; the ECC algorithm has higher encryption strength, and the certificate file is smaller, and the encryption and decryption speed is faster. It is suitable for websites with dual requirements for performance and security. You can choose according to your own server environment and the browser version of the client base.
complete the preliminary preparation and certificate selection, you can enter the formal application process of the pan-domain SSL certificate, and follow the standardized process to ensure the smooth passage of the application.
1, select a certificate service provider and submit an application
choose a regular pan-domain SSL certificate service provider, such as Symantec, Let's Encrypt, etc., enter the certificate application page of the service provider's official website, fill in the main domain name information, contact email, enterprise or personal identity information and other basic content, and upload the verification materials prepared in advance., submit the application and wait for the service provider to initially review.
2. Complete domain ownership verification
After theservice provider accepts the application, it will send the domain name verification instruction through the mail or console. The common verification methods are DNS resolution verification and file verification. DNS resolution verification needs to add the specified TXT record in the domain name resolution console, and file verification needs to upload the specified file to the root directory of the main domain name. After the verification, the service provider will enter the next step of review.
3, wait for the certificate review and download the certificate file
DV-type pan-domain SSL certificates can usually be reviewed within a few hours. OV and EV-type certificates take 1-3 working days. After the review is passed, the service provider will send the certificate file to the reserved mailbox, and it can also be downloaded directly from the service provider console. When downloading, pay attention to choosing the certificate file format that matches the server environment. For example, the format corresponding to different servers such as Apache, Nginx, IIS, etc. is different.
pan-domain SSL certificate application is completed and deployed, it is not once and for all, but also need to do a good job of daily maintenance to ensure that the certificate continues to be valid, providing stable encryption protection for the website.
1, set the certificate expiration reminder and timely renewal
pan-domain SSL certificate has a fixed valid period, usually 1-2 years. You need to set an expiration reminder in advance to avoid the interruption of HTTPS service on the website due to the expiration of the certificate. You can open the expiration email reminder in the service provider console, or you can configure the monitoring script on the server side to start the renewal process 30 days in advance. The renewal process is similar to the first application, but the review speed will be faster.
2. Regularly check the status of subdomains covered by the certificate
regularly check the HTTPS status of all subdomains covered by the pan-domain SSL certificate to ensure that each subdomain can display the encrypted logo normally. When adding a subdomain, there is no need to reapply for the pan-domain SSL certificate, just make sure that the sub-domain name resolution is normal, the certificate will automatically cover the new sub-domain at the same level, and check the encryption status in time after adding.
3, timely update certificate encryption algorithm and configuration
with the development of cyber security technology, the old encryption algorithm may be gradually eliminated, you need to pay attention to the security update notice issued by the service provider, timely update the encryption algorithm and server configuration of the pan-domain SSL certificate. At the same time, regularly check the SSL configuration of the server, close the insecure encryption suite, and improve the overall security level of the website.
To sum up, the application of pan-domain SSL certificate is a complete process from preparation to maintenance. In the early stage, the domain name and materials should be prepared, the appropriate certificate type should be selected according to the needs, and the application and deployment should be completed according to the standardized process. Later, the expiration renewal and status monitoring should be done. Through reasonable application and maintenance of pan-domain SSL certificates, it can provide unified encryption protection for all sub-domains of the website, and improve the security and user trust of the website.