With DigiCert
DigiCert issues commercial DV SSL certificates with manual or automatic domain validation.
Prerequisites
- Access with ADMIN or OPERATOR role
- An active DigiCert account with available balance or plan
- The DigiCert API Key on hand
- For automatic DNS validation: an AWS integration with Route 53 configured
Step 1 — Configure the DigiCert integration
- Go to Integrations in the sidebar menu
- Find the DigiCert card and click + Configure
- Fill in the fields:
- Name — e.g.:
digicert-production - API Key — key generated in the DigiCert dashboard
- Name — e.g.:
- Click Save changes
Where to find the API Key
In the DigiCert dashboard, go to **Account → Account Access → API Keys** and generate a key with certificate issuance permissions.
Step 2 — CSR Step 2: CA and Configuration
- Under Certificate Authority, select DigiCert (DV SSL with existing integration)
- Fill in the fields:
| Field | Description |
|---|---|
| DigiCert Integration | Select the integration registered in Step 1 |
| Organization | Organization registered in your DigiCert account |
| DV Product | DV product available in the account — only Domain Validation products are shown |
| Technical Contact | Technical contact registered with DigiCert |
| Organization Contact | Organization contact registered with DigiCert |
| Locality (L) | City |
| State (ST) | State or province |
| Country (C) | 2-letter country code, e.g.: BR |
| Order Validity | Order validity in Years or Days |
| Notes | Optional notes |
- Choose the Domain Control Validation (DCV) method:
| Method | When to use |
|---|---|
| Email Validation | Sends a validation email to the domain owner |
| DNS CNAME Token | You add a CNAME record to the DNS zone manually |
| HTTP CSR Hash | You upload a hash file to the web server |
| DNS Auto-Validation (Route 53) — Manual | You have Route 53 integration but create the record manually |
| DNS Auto-Validation (Route 53) — Automatic | The CLM creates and manages the DNS records automatically |
Step 3 — Track the validation
For manual methods (DNS CNAME, HTTP, Email):
The validation screen displays the DCV token in two ready-to-copy formats:
- DNS TXT — TXT record to add to the DNS zone
- DNS CNAME — alternative CNAME record accepted by DigiCert
The domain status appears as Pending until DigiCert confirms it. Click Force validation to trigger an immediate check.
The DCV token has an expiration time shown on the screen. Complete the validation before it expires.
For DNS Auto-Validation (Route 53) — Automatic:
The CLM creates the DNS records automatically. Track the progress in real time — no manual action is required.
Cancel a request
If you need to cancel before issuance, click Reject request on the validation screen. The request will be canceled with DigiCert as well.