Skip to main content

Add and validate a domain for the domain validation service

Use the following procedure to add a domain to the validation service and complete DNS-based validation for it. Once added and configured, DigiCert​​®​​ Trust Lifecycle Manager can continuously validate the domain to ensure it's always ready for certificate issuance.

Wichtig

You must have access to add a CNAME record with the domain's authoritative DNS provider to complete this process.

  1. In the DigiCert​​®​​ Trust Lifecycle Manager menu, go to the Inventory > Domains page.

  2. Select Add domain.

  3. From the CertCentral connector list, select the connector associated with the CertCentral account you want to use for this domain.

  4. From the Organization list, select the organization associated with the selected CertCentral connector.

  5. In the Domain name field, enter the base domain or fully qualified domain name (FQDN) you want to add.

  6. Select Add & Continue. After you submit the domain, Trust Lifecycle Manager generates a unique CNAME record for DNS validation.

On the Set-up DNS Validation page, Trust Lifecycle Manager displays a unique CNAME record generated for the domain. Add this CNAME record to your DNS provider so that it points to DigiCert DNS for automated domain control validation. The record includes the following fields:

Field

Description

Record type

Type of DNS record used for validation (CNAME).

Host / Name

The subdomain label to create in your DNS zone.

Value / Target

The destination value the CNAME must point to.

To configure the CNAME record and start the validation check:

  1. Use the copy icons next to the Host / Name and Value / Target fields to copy the values to your clipboard. Configure these values in your DNS provider.

    Wichtig

    Trust Lifecycle Manager generates unique Host / Name and Value / Target values for each domain. Do not modify these values. Validation fails if you enter an incorrect value in your DNS provider.

  2. After configuring the DNS record in your DNS provider, select I've added this DNS record to start the validation check.

    The following outcomes can occur:

    • If the DNS record is configured correctly in your DNS provider, a confirmation message appears indicating that the DNS setup has been verified. You are then prompted to configure a validation policy.

    • If Trust Lifecycle Manager cannot find the DNS record, the DNS record not found message appears. Verify that the record was added correctly and allow time for DNS changes to propagate. The Check again option allows you to runs another DNS lookup to verify whether the required DNS record is available.

    • You can select Back to DNS instructions to return to the Set up DNS validation page and review the required DNS record details.

    • You can select Save and finish later to complete the DNS validation check later. Add the required DNS record to your DNS provider, and then return to Trust Lifecycle Manager to validate the domain again.

Configure a validation policy to specify how frequently Trust Lifecycle Manager automatically revalidates the domain.

  1. Select the validation interval. The available validation intervals are:

    • 7 days

    • 14 days

    • 30 days

    • Custom interval: Enter the number of days after which domain validation is automatically performed.

    • Manual: Domain validation is performed only when you manually trigger revalidation.

  2. Select Save policy. The added domain is ready for validation.

Anmerkung

If the validation policy is set to Manual, you must run validation manually to maintain the domain's successful status.

  1. On the confirmation page, select Validate now to immediately start domain validation.

  2. If you want to return to the Domain page, select Done. The new domain appears on the Domains page.

What's next

After validation completes successfully, the DNS configuration status shows Configured and Domain status changes to Validated.

If the initial validation cannot be completed, the Domain status remains in the Pending state indefinitely. Review the DNS record configuration, correct any issues in your DNS provider, and run validation again. To learn more, see: