During domain control validation (DCV), DigiCert performs checks from multiple globallocations using our MPIC (Multi-Perspective Issuance Corroboration) agents. In somecases, these validation attempts fail or produce inconsistent results.
Stay up to date with your certificate activity by connecting your Slack Workspace DigiCert ONE’s Notification Center.
Depending on how your browser is configured, you may want to disable SSL v3 and enable TLS 1.0, TLS 1.1, and TLS 1.2.
After generating your code signing certificate, we recommend verifying that your certificate is installed in the browser’s Certificate Store.
You can use your DigiCert® Document Signing Certificate to add an invisible digital signature to a Word document, Excel workbook, and PowerPoint presentation.
You can use your DigiCert® Document Signing Certificate to add a visible digital signature inside a Word document or Excel workbook.
1. On the Windows server where your SSL Certificate is installed, download and save the DigiCert® Certificate Utility for Windows executable
To check the revocation status of an SSL Certificate, the client connects to the URLs and downloads the CA's CRLs.
1. On your Windows server or workstation, download and save the DigiCert® Certificate Utility for Windows executable
After installing your code signing certificate, you may need to export the certificate for use on a different computer, for signing code, etc.
2. From Acrobat home (on the left), select All tools
Though Wildcards are compatibile with Exchange, they can cause issues with POP3 and IMAP. For more information, see our page on Exchange 2007 Widlcard compatability.
In June 2011, ICANN approved the New Generic Top-Level Domain Program (gTLD), which allows organizations, individuals, and governments to apply for top-level namespaces.
The CSR is missing a NULL value in the OBJECT IDENTIFIER rsaEncryption (1 2 840 113549 1 1 1) field. To be compliant with RFC 3279, this field must contain a NULL value.
To update your Exchange 2007, Exchange 2010, or Exchange 2013 server, you will need to run the following commands from the Exchange Management Shell and replace the Server running the Client Access Role with your external domain name.
When generating a certificate from an online keypair in DigiCert® Software Trust Manager, users may encounter the status message “Error creating certificate.
Microsoft ended support for Exchange 2007 on April 11, 2017. It is recommended to upgrade.
Step 1: Copy the Certificate files to your server.
By disabling the CBC-mode ciphers, you are forced to rely on the RC4 stream cipher, which has its own biases (RC4-biases).
The reason that you are receiving this message is that the Intermediate Certificate was not included in the Certificate Chain.
DigiCert's Multi-Domain Certificates allow one certificate to be issued to multiple names
You can use a DigiCert Code Signing Certificate to sign your Mac OS software, tools, updates, utilities, and applications.
The following tutorial is meant to walk you through the process of generating your client authentication certificate and decrypting the SMPB batch file from DigiCert ONE IOT Manager.
When choosing your server type during the online order process, make sure to choose Java Tomcat to get the files in the most helpful format for command line installation.
To update the intermediate certificate on your Barracuda device, you will first download a copy of your existing DigiCert SSL Certificate
7. Click OK to save the file, making sure to verify that it is in the location you specified.
3. In the box labeled CA Bundle, paste the contents of the DigiCertCA.crt file that you downloaded in Step 1.
As of December 2012, Google's Gmail servers are configured not to connect to remote POP3 servers that have either no certificate or a self-signed certificate.
Microsoft ended support for Exchange 2007 on April 11, 2017. It is recommended to upgrade.
DigiCert Code Signing Certificates can be used to sign code, including Microsoft Authenticode, Microsoft Office VBA, Java, Adobe AIR, Apple's Mac OS, and Mozilla objects.
To sign your EV verification XML file, you must have an EV Code Signing Certificate with a SHA-2 signature algorithm.
Host headers can be used to host multiple secure websites on one IP address.
These issues are not specific to DigiCert® certificates—they are caused by the way wildcard characters are handled.
1. Open Keychain Access and select the certificate(s) you want to export.
Before DigiCert can issue your SSL/TLS certificate, you must prove control over the domains on the order.
When rekeying a Document Signing Certificate, DigiCert must generate a new initialization code.
To use an EV Code Signing Certificate with Mac OS X, you will need to have DigiCert preinstall the certificate to a token and ship it to you.
Before deleting any certificate, make sure that the certificate has expired or is not being used.
Step 1: Copy the Certificate files to your server. Download your DigiCert intermediate certificate.
These instructions were created using Nginx 1.6.2. Depending on which version of Nginx you are using, you may need to modify the instructions accordingly.
Create one record, which authorizes DigiCert to issue any of the DigiCert-owned certificate brands.
SNI is a transport layer security extension that enables you to use a virtual domain name or a hostname to identify the network endpoint.
If you are running Windows Server pre-2008, to enable OCSP stapling, upgrade to Windows Server 2008 or later.
After installing your code signing certificate or activating your EV code signing token, you can use the DigiCert® Certificate Utility for Windows to sign your code and winqual.exe file.
In Bluebeam Revu, open the PDF that you need to sign.
Windows automatically determines which intermediate certificates to send to clients based on which root certificates it finds in its root certificate authorities certificate store.
This page contains the DigiCert dedicated IP addresses for DigiCert Online Certificate Status Protocol (OCSP), Certificate Revocation List (CRL), and a few other DigiCert services.
Download the intermediate certificate and copy the file to the directory on your server where you will keep your certificate and key files.
OpenOffice and LibreOffice programs record the time the document is signed and the certificate validity period
In IIS 7, if you used host headers with an SSL Certificate, the same certificate had to be used for every secured site.
The DigiCert Certificate Utility® for Windows detects if an SSL Certificate installed on your Windows server has been revoked.
The DigiCert Certificate Utility® for Windows has a feature that lets you find out if an SSL Certificate installed on your Windows server has a matching private key.
The Query Server feature can be very helpful for testing your SSL Certificate installation for a certificate that's installed in your Local Area Network
In environments that require multiple SSL Certificates, the lack of friendly names can make managing your SSL certificates more difficult.
Older versions of Internet Explorer may not have the TLS protocol enabled by default.
Learn how to set up your DigiCert-provided hardware token for Document signing
Run the following command with Admin rights: sudo defaults write /Library/Preferences/com.apple.security.smartcard Legacy -bool true
This page provides instruction on how to export your Code Signing Certificate on Safari or Firefox in Mac.
Using host headers in combination with certificates that can cover more than one website, you can secure multiple sites on one IP.
Depending on which version of Apache you are using, you may need to modify these instructions accordingly.
If you used Safari or Chrome to install your Code Signing Certificate, the certificate should be located in the login keychain.
Older versions of Internet Explorer may not have the TLS protocol enabled by default.
This page provides instructions on how to configure Apache and Nginx for Perfect Forward Secrecy.
If you have more than one Code Signing Certificate on your computer, we recommend that you manually select which certificate to use for signing code.
This page provides instruction on how to disable the SSL V3 protocol.
To convert your certificates to a format that is usable by a Java-based server, you need to extract the certificates and keys from the .pfx file using OpenSSL.
S/MIME allows you to encrypt email content using the recipient's public key, so only the intended recipient with the matching private key can read the message.
The following article outlines the process of Jarsigner signing with a token on Linux.
Use these instructions to change your eToken password.
To run your applications on Adobe AIR or publish your Adobe Flash code on your Adobe Air applications, you must digitally sign them first.
Export your SSL/TLS certificate from one Microsoft server to import on another Microsoft server
If you already set up your code signing certificate and are ready to sign your Java .jar files, go to our Sign Java .jar files with jarsigner instructions below.
To run your applications on Adobe AIR, you must digitally sign them first.
These instructions are for signing Java .jar files with a code signing or EV code signing installed on a hardware token.
This article walks you through the steps to set up a Token on a Linux system and guides you on how to use the token once set up.
Download your intermediate certificate, then copy it to the directory on your server where you will keep your certificate and key files.
The first step when experiencing issues trying to get Apache started is to check your log file for an error that might point to the problem.
Use the DigiCert® Certificate Utility for Windows to repair your certificate installation and ensure it's installed correctly for use in IIS, Exchange, and other Windows server types.
In some instances, you may want to move a certificate from one server to another. You may also want to back up the certificate that you have installed. The best way to do this is to create a .pfx file.
There is a problem with the digital certificate. The VBA project could not be signed. The signature will be canceled.
The ‘/audit-log’ and ‘/signatures’ endpoints of the DigiCert® Software Trust Manager REST API both make provision for filtering the returned data (in CSV format) in the endpoint URL targeted by the GET request.
When signing Java files with jarsigner, using a DigiCert® Software Trust Manager certificate created with Java keytool, the “jar signed” success message may include a warning.
The token uses various passwords for authentication. If an Administrator Password is entered incorrectly 5 times, the eToken locks permanently.
During enrollments, users recieve a Service_Internal_Error A901
If you are having issues with DSS-Engine or DigiCert® Document Trust Manager please use the following phone numbers and email alias to contact support.
Error 12029 calling WINHTTP_CALLBACK_STATUS_REQUEST_ERROR, 'A connection with the server could not be established'.
When uploading your BIMI logo to CertCentral for a Verified Mark Certificate (VMC) order, you may encounter the following error message:
Scenario: Automation is behaving erratic when user tries to create profile or perform an automation task. Discovery notifications are not working even when enabled.
Automation profile disappears after it has been configured.
You might receive a “./start.sh: source: not found” error when activating a sensor on Linux machine.
When testing IOT Enrollment with EST using the client auth certificate generated in Account Manager, enrollments will fail.
To Timestamp a Java Applet with a DigiCert Code Signing Certificate for Sun Java using JDK 1.6.0, perform the following steps:
Digicert PKI Platform 8 ended support for TLS 1.0 and TLS 1.1 on August 30, 2021
When testing IOT Enrollment with EST using passcode, the enrollments fail.
End-users may not be able to launch the DigiCert PKI Client as the PKI Client console application is based on Microsoft HTML application (HTA).
If an invalid FASCN value is passed for an IDOD certificate request, PKI Web Services may return a generic A601 error.
In June 2022, DigiCert introduced the new cross root "DigiCert Trusted Root G4" to resolve compatibility issues with legacy timestamp clients.
Platform: CertCentral ACME Automation Error: Failed to update ACME account:405: Method Not Allowed
DigiCert sensors included a version of Apache Log4j identified in the Log4j zero-day exploit.
Microsoft deprecating AAD Graph in June of 2022. Making this graph option is no longer available.
DigiCert PKI Enterprise Gateway - Local Key Escrow and Recovery Service (LKMS) has been updated with the below changes:
1. Create an ACME Directory URL from CertCentral.
Enable code signer authentication. Once enabled, SafeNet pops up before you sign code and requires you to enter your password to verify you.
When enrolling for a certificate using MPKI Web Services, you receive the following error:
Gatekeeper certificate installation Steps requires the corresponding browser enabled in DigiCert Desktop Client application.
The token uses various passwords for authentication. If an Administrator Password or PUK is entered incorrectly 5 times, the eToken locks permanently.
When scanning a large IP address range scan results may be delayed due to varying factors, including but not limited to network speeds on your and ISP’s environments.
Background: Customers running the 64-bit version of Firefox are experiencing issues accessing the PKI Manager portal via PKI Client.
When Completing the Certificate Request in Internet Information Services (IIS) 7.0 Manager using a PKCS#7 file, the server may give the following error message:
The most common timestamping problems and the troubleshooting instructions are:
Sometimes certificates might be installed on your environment but not appear on the scan results.
The following error occurs when attempting to retrieve your certificate with a usb token: Product name: eToken PRO Java 72K OS755
CSR generation failed (User does not have access to action (config sync)). This is error is related to the role of a user managing the automation request.
When installing a certificate using Microsoft IIS 7 Manager, you may receive the following error message even though the certificate is installed:
The Adobe Approved Trust List (AATL) is used to distribute and maintain a list of trustworthy digital certificate issuers for Adobe Acrobat and Adobe Reader.
Log in to CertCentral and download the certificates from the order page by following these steps: 1. Log in to CertCentral
Error: "This certificate profile type requires that domain names be authenticated and assigned to this account." Requires you to contact PKI Support.
Using a timestamping service usually takes more time than the default digital signing process.
To sign code with a Code Signing Certificate for Microsoft Office and VBA, perform the following steps: 1. Open the document or template that contains the macros you want to sign
When attempting to create a Digital ID for digital signatures in Adobe Reader on Mac OS, Adobe Reader does not detect the inserted Safenet hardware token containing the certificate to be used.
If restarting Auto Enrollment service fails, this may happen if the service is unable to find the private key of the RA certificate that was generated on HSM.
How to install the necessary utilities to extract and view archived PKI Client logs files in zlib format for Windows, Mac OS and Linux.
Administrators and end users are missing their certificates after a recent update on their local system.
Exadata DB patching is done quarterly on all nodes.
When performing a local install of DigiCert One, the Ambassador service fails to install correctly.
You might get an access denied error when installing a sensor on a Windows machine. This is not a sensor issue but rather a Windows permissions one.
To resolve this issue, export the certificate from the original computer with Include all certificates in the certificate path option selected.
Discovery sensor does not pick up certificates installed on port 25.
During our maintenance window, any scheduled scans and their results will fail as data is being loaded and services go down.
This error occurs when the number of scans allowed in an account’s subscription has been exceeded.
When trying to replace Managed PKI Administrator ID, you may receive the following error message: Error 30ab - Valid or Pending ID exists
Sensor stops responding mid scan. It is usually because the network connection to the sensor has been interrupted or the sensor needs to be updated to the latest version.
Sometimes a scan will be complete, but only partially due to insufficient time allocated to the scan.
When users try to enroll and get an A901 error
The System and Administrator accounts do not have sufficient permissions or the Administrators group does not have ownership of the directory.
This issue occurs because Exchange Server 2010 uses Microsoft Windows HTTP Services (WinHTTP) to manage all HTTP and HTTPS traffic, and WinHTTP does not use the proxy settings that are configured for the Internet browser.
To disable automatic root certificates update on Microsoft Windows 7 or Microsoft Server 2008, perform the steps outlined below.
Please make the following changes to the security settings of the Microsoft Internet Explorer browser:
The OCSP protocol does not require the browser to spend time downloading and then searching a list for certificate information.
This page provides instructions on how to replace an Intermediate certificate and how to reissue and reinstall a SSL certificate when intermediate certificate error occurs.
OpenSSL is an open-source command line tool that is commonly used to generate private keys, create CSRs, install your SSL/TLS certificate, and identify certificate information.
Use Private TLS/SSL certificates to secure private and public domains and IP addresses.
This article details how to resolve issues experienced by using the DigiCert PKI Client to access the PKI Platform 8 administration portal called PKI Manager, using macOS Monterey machines running on either M1 or Intel-based chips.
.Onion is a top-level Internet domain used by anonymous websites on the Tor network accessibly only from the Tor anonymity browser.
To enable TLS 1.1 and/or TLS 1.2 protocols on web browsers, see the list below.
Download SafeNet Authentication Client for Windows XP, Vista, and 7. Download SafeNet Authentication Client 9.0 for Windows 8 and up.
To initialize or reset a SafeNet 5110FIPS USB Token Device password please follow the steps below:
The Distinguished Name is a set of values entered during enrollment and the creation of a Certificate Signing Request (CSR).