Skip to main content

Metodi di convalida del controllo del dominio (DCV)

Metodi DCV supportati per la convalida dei domini sugli ordini di certificato DV TLS/SSL

Prima che DigiCert possa emettere un certificato, è necessario dimostrare di avere il controllo sui domini e su eventuali SAN (nomi alternativi del soggetto) nell'ordine. Questo processo viene chiamato convalida del controllo del dominio (DCV).

I certificati DV non supportano la pre-convalida di dominio. Pertanto, ogni qualvolta ordini un certificato DV, devi dimostrare il controllo sui domini nel tuo ordine. Dopo aver effettuato l’ordine, devi completare la convalida dominio prima che DigiCert possa emettere un certificato DV.

Acronyms in this article: domain validation (DV), Transport Security Layer (TLS), Certificate Authorities (CAs) Domain Name System (DNS), text (TXT), Conical Name (CNAME), Certificate Authority Authorization (CAA), Hypertext Transfer Protocol (HTTP)

How the process works when validating domains on a pending DV certificate order

When you order a DV certificate, you’re required to select a DCV method to validate the domains on the certificate. When done, CertCentral takes you to the certificate's pending Order details page. From this page, you can use the selected DCV method to demonstrate control over the domains. You can always switch validation methods if needed.

With DV certificate orders, you can use just one DCV method to validate the domains on the pending order. Consider the following limitations when adding domains, wildcard domains, and IP addresses to DV certificates:

  • If you have an IP address on the certificate, you must use the HTTP Practical Demonstration DCV method to validate it.

  • If you have a wildcard domain on the certificate, you can’t use the HTTP Practical Demonstration DCV method to validate it.

DigiCert recommends that you don’t include wildcard domains and IP addresses on the same DV certificate.

DV certificates don’t support domain validation reuse

A DV certificate's domain validation is valid long enough to issue the certificate. DV domain validation isn’t reusable for reissues or renewals. Each time you order a DV certificate, you must demonstrate control over the domains on the order before DigiCert can issue it.

Convalida DNS TXT

Con questo metodo di convalida, aggiungi un valore casuale generato da DigiCert (fornito per il dominio nel tuo account CertCentral) al DNS del dominio come record TXT. Quando DigiCert effettua una ricerca per i record DNS TXT associati al dominio, possiamo trovare un record in cui il valore del record include il valore casuale DigiCert.