EPAG Domainservices GmbH
Professionally
managing your domains

Home

Language:   

+49 228 3296840info@epag.de

 SSL FAQs
 The most important questions about SSL certificates
Here you will find answers to frequently asked questions. In case we did not answer your question below, please feel free to contact our SSL support team by e-mail.
 What is a CSR and what does it need to contain?
The abbreviation CSR is short for “Certificate Signing Request”. The CSR is a sequence of text characters which will be generated by your SSL software for the certificate hostname. Only after a CSR has been supplied, the Certificate Authority (e. g. Thawte or VeriSign) will be able to generate your certificate.
The CSR must contain the following information:
  • Country (= C)
  • State (= ST)
  • Locality (= L)
  • Organisational name (= O)
  • Organisational unit (= OU)
  • Common name (= CN)
Indicating your e-mail address within the CSR is optional.
Important notices for generating the CSR:
  • Please do not enter a challenge password or an optional company name when generating the CSR. The Certificate Authority will not accept a CSR with these two additional fields.
  • Please make sure that no umlauts (e.g. ä, ö, ü) were used in the CSR.
  • Please make sure that you have installed the newest version of OpenSSL when you generate a CSR. When using older versions of OpenSSL, it might be possible that CSRs are generated with only light decryption. Those CSRs will not be accepted by the Certificate Authority. This affects mostly Debian or Ubuntu distributions.
Along with the SSL certificate order, the CSR needs to be submitted in a specific format. Please see the following example that shows a valid CSR for “example.com”:

-----BEGIN CERTIFICATE REQUEST-----
MIIBvzCCASgCAQAwfzELMAkGA1UEBhMCREUxDDAKBgNVBAgTA05SVzENMAsGA1UE
BxMEQm9ubjEZMBcGA1UEChMQRXhhbXBsZS5jb20gSW5jLjEUMBIGA1UEAxMLZXhh
bXBsZS5jb20xIjAgBgkqhkiG9w0BCQEWE2V4YW1wbGVAZXhhbXBsZS5jb20wgZ8w
DQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAMOTp1J6/RJ6n3b7q+VBnzZCScQJGJyr
caLtVUpTxztO94jMRUlHYFzE9qoE17k3E+BwNf/k5Oq3RHvZjn7HkbLPWKDElkNz
TbhrVM1pV1QiSitVHURy9JhdS9V7FKm5loZczkjatnBq+1pKBgh8OPXBdA99V3Ma
BGmWsZ/1x4nxAgMBAAGgADANBgkqhkiG9w0BAQUFAAOBgQBDqhJ2qL3zcY8AIauO
hjiKgHciy/Y9jgNedDGD3uw2G7XUBUcewP7Q82Ra9SccIE5kyVeO1u81UAKjmQfH
1ywUkuSbib01ZFNCeoa+GmMJkEq9UbSl0rkcP8Qrh9gme+3zu8Ag0VsBn0+2GgrE
Q0lolzzvT/k0HuLRiu4QR1Fs+g==
-----END CERTIFICATE REQUEST-----

The private key requires a minimum length of 1024 bits. Please note that when ordering “extended validation” certificates, a mandatory minimum length of 2048 bit is required for the private key.
More information on how to generate a CSR on your server is available at www.thawte.com:
Thawte-Help for generating CSR
Information for VeriSign certificates is available at www.verisign.com:
VeriSign-Help for generating CSR

 What is the difference between the administrative and technical contact?
The administrative contact is the person who will hold the certificate. This person is as well the administrative domain contact in the public Whois database and will usually also be the authorizing person who confirms the certificate order. EPAG will not contact the administrative contact if all contact details have been submitted in due order.
The technical contact is the person who will receive technical information related to the certificate order. The technical contact is as well the person who will be contacted at first by Thawte or EPAG for questions.
In addition to the technical contact, a contact person for EPAG is required. To specify this contact, simply use the “E-mail address (contact person)” field on the second ordering screen to insert the e-mail address of the person which EPAG shall contact to process the order and send the invoice. This contact person will not be contacted by the Certificate Authority.

 What has to be considered regarding the e-mail address of the authorizing person?
The e-mail address provided for the authorizing person should be active and also visible in the public Whois database. If the e-mail address is for some reason not visible or different to the one shown in the public Whois record, then you should make sure that one of the following predefinded e-mail addresses are active and monitored:
  • admin@yourdomain
  • administrator@yourdomain
  • hostmaster@yourdomain
  • root@yourdomain
  • webmaster@yourdomain
  • postmaster@yourdomain
When choosing one of those predefined e-mail addresses, Thawte, VeriSign or RapidSSL can be sure that the contact person of this domain is authorized. The e-mail required to approve the certificate will be sent to this person for checking and confirming the application.

 How will I receive the certificate after it is issued?
After a certificate has been successfully issued by Thawte, VeriSign or RapidSSL, it will be sent via e-mail to the technical contact, and a copy will be sent to the administrative contact. The certificate will be contained within the e-mail in plain text format within the e-mail.
More information about how to install a certificate is available at www.thawte.com:
How to install a Thawte certificate
Help for VeriSign certificates can be found at www.verisign.com:
How to install a VeriSign certificate

 How will I get the VeriSign Secured Seal respectively the Thawte Trusted Site Seal?
After receiving a successfully issued certificate from Thawte, VeriSign or RapidSSL, you can show in the secure area on your website a so called Seal to indicate to your customers that this website is trustworthly. You may retrieve your Site Seal through the following links:
Please note that you need to renew the Seal after you have renewed your certificate.

 Is it possible to renew a certificate - purchased anywhere else - with EPAG?
Yes, it is possible to renew Thawte or VeriSign certificates with EPAG, even if the certificate has originally been purchased through another Thawte or VeriSign partner.
To renew a certificate, we only need the Certificate Signing Request (CSR) of your current certificate. Please note that if a Microsoft product is used, a new CSR might be required for renewing your certificate.

 When can I start renewing a certificate?
You may renew a Thawte certificate starting 90 days before it expires. From the day of expiration, it is still possible to renew the certificate within 90 days.
Please be aware that a renewal may take several days, and make sure to initiate the process early enough. In some cases, altered information will again be subject to comprehensive verification.

 Is a Wildcard certificate valid for subdomains of a subdomain?
In general, the Wildcard Certificate is valid only for the subdomains of the “main” domain like [server1.domain.de] and [server2.domain.de]. That implies that it is impossible to include subdomains of a subdomain into the certificate signature, such as [mail1.server1.domain.de], [mail1.server2.domain.de] and [mail2.server2.domain.de].
A Wildcard certificate is not valid for the actual 2nd level domain [domain.de].

 Is it possible to install the same certificate on more than one server? What is a licence?
A certificate may generally be installed only on one physical server. If you have several subdomains included in a Wildcard Certificate spread out over different physical servers, you will need additional licences. The licence guarantees that you have the right to install a copy of the Wildcard Certificate on another server. Additional licenses are available for all certificate types except the Code Signing Certificate.
Please contact us directly to find out about pricing for additional licences.

 What is a reissue? Is there a cost associated with it?
A reissue is needed if you wish to change information in an existing certificate. For example, you might decide to change the server software and for that reason are unable to use the current certificate any longer. Within the validity period of a certificate, reissues through Thawte and VeriSign are free of charge. RapidSSL does not offer free reissues!
If a reissue is necessary, please tell us the reason and which details you wish to change.

 What is important for the e-mail addresses for RapidSSL certificates?
Please make sure when ordering a RapidSSL Certificate to submit only predefinded e-mail addresses with the application. Otherwise, certificate provision might fail or will experience considerable delays.
  • admin@yourdomain
  • administrator@yourdomain
  • hostmaster@yourdomain
  • root@yourdomain
  • webmaster@yourdomain
  • postmaster@yourdomain

 Which are the differences between the VeriSign Trust Seal and SSL certificates?
There is no SSL data encryption but only the check and confirmation of the Trust Seal owner's identity. Additionally every 24 hours a malware check is taken. More than that websites protected by the Trust Seal are highlighted in the results of the most popular search engines. If you ask for personal data on your website, you will also need a SSL certificate.

 Which data do I need for the order of a VeriSign Trust Seal?
  • URL of website where you wish to implement the Trust Seal
  • common data of the Trust seal owner, administrative and technical contact