Skip to main content

With DigiCert

DigiCert issues commercial DV SSL certificates with manual or automatic domain validation.


Prerequisites

  • Access with ADMIN or OPERATOR role
  • An active DigiCert account with available balance or plan
  • The DigiCert API Key on hand
  • For automatic DNS validation: an AWS integration with Route 53 configured

Step 1 — Configure the DigiCert integration

  1. Go to Integrations in the sidebar menu
  2. Find the DigiCert card and click + Configure
  3. Fill in the fields:
    • Name — e.g.: digicert-production
    • API Key — key generated in the DigiCert dashboard
  4. Click Save changes
Where to find the API Key
In the DigiCert dashboard, go to **Account → Account Access → API Keys** and generate a key with certificate issuance permissions.

Step 2 — CSR Step 2: CA and Configuration

  1. Under Certificate Authority, select DigiCert (DV SSL with existing integration)
  2. Fill in the fields:
FieldDescription
DigiCert IntegrationSelect the integration registered in Step 1
OrganizationOrganization registered in your DigiCert account
DV ProductDV product available in the account — only Domain Validation products are shown
Technical ContactTechnical contact registered with DigiCert
Organization ContactOrganization contact registered with DigiCert
Locality (L)City
State (ST)State or province
Country (C)2-letter country code, e.g.: BR
Order ValidityOrder validity in Years or Days
NotesOptional notes
  1. Choose the Domain Control Validation (DCV) method:
MethodWhen to use
Email ValidationSends a validation email to the domain owner
DNS CNAME TokenYou add a CNAME record to the DNS zone manually
HTTP CSR HashYou upload a hash file to the web server
DNS Auto-Validation (Route 53) — ManualYou have Route 53 integration but create the record manually
DNS Auto-Validation (Route 53) — AutomaticThe CLM creates and manages the DNS records automatically

Step 3 — Track the validation

For manual methods (DNS CNAME, HTTP, Email):

The validation screen displays the DCV token in two ready-to-copy formats:

  • DNS TXT — TXT record to add to the DNS zone
  • DNS CNAME — alternative CNAME record accepted by DigiCert

The domain status appears as Pending until DigiCert confirms it. Click Force validation to trigger an immediate check.

The DCV token has an expiration time shown on the screen. Complete the validation before it expires.

For DNS Auto-Validation (Route 53) — Automatic:

The CLM creates the DNS records automatically. Track the progress in real time — no manual action is required.


Cancel a request

If you need to cancel before issuance, click Reject request on the validation screen. The request will be canceled with DigiCert as well.