Domain prevalidation: Bulk domain revalidation
Use the bulk domain revalidation feature to submit up to 25 domains simultaneously for revalidation. DigiCert recommends keeping your domain validations up to date for quicker certificate issuance.
Items to note about domain validation:
Per industry standards, a domain's validation is valid for 199 days (approximately six months).
If you order a certificate for a domain while the domain's revalidation is pending, we use the domain's current validation to issue the certificate until that validation has expired.
Submit domains for revalidation
Select the domains to revalidate
In the CertCentral main menu, go to Certificates > Domains.
On the Domains page, select the domains you want to revalidate.
Select the DCV method to revalidate your domains:
Revalidate using Persistent DNS TXT record
For this method, you’ll need to go to your DNS provider and create a persistent DNS TXT record for each domain selected. In the Hostname field, enter _validation-per sist. Then, in the Value field, enter the persistent DNS TXT value (also called the persistent URI).
注記
Important: Don’t delete the Persistent DNS TXT record
Don’t delete the persistent DNS TXT record after the domain is validated. The Persistent DNS TXT URIs don’t expire. Keep the record and its persistent URI in place so DigiCert can reuse it for future persistent DNS TXT domain validations.
In the Submit domains for revalidation menu, select Revalidation by Persistent DNS TXT record.
On the Submit domains for revalidation by Persistent DNS TXT method page, review the selected domains.
Select Submit domains for validation.
Expand Show URIs and verify domains submitted for revalidation to see the domains and their persistent URIs—either account-wide or unique.
Under Instructions, select one of the following options:
Use my account-wide URI for all domains
Select this option if you want to use the same persistent DNS TXT value for all the domains.
Use a unique URI for each domain
Select this option if you want to use a unique persistent DNS TXT value for each domain.
Copy the persistent URIs.
If you're using the account-wide URI, you only need to copy the persistent DNS TXT value for one domain, since the value is the same for all domains in your CertCentral account.
注記
Note: To get a copy of the account-wide URI after you leave this page, open a domain's details page for a domain using the persistent DNS TXT DCV method.
If you're using unique URIs, create a document and record each domain along with its corresponding unique persistent DNS TXT value.
警告
Caution: After leaving this page, the only way to get the unique persistent URI for each domain is to manually open each domain's details page and copy it.
When ready, select Go to Domains page.
Revalidate using DNS TXT record
For this method, you’ll need to go to your DNS provider and create a TXT record for each domain selected. Add a DigiCert-generated random value to the domain's DNS as a TXT record.
In the Submit domains for revalidation menu, select Revalidation by DNS TXT record.
On the Submit domains for revalidation by DNS TXT method page, review the selected domains.
Select Submit domains for validation.
Under Next steps, take note of the date that the unique verification tokens will expire.
Expand Show tokens and verify domains submitted for revalidation to see the domains and the unique verification token generated for each one.
Copy the unique token for each domain.
Manually copy the unique verification tokens and save them. If you prefer, create your own document and record each domain along with its corresponding unique verification token.
Or download the CSV file with all the unique verification tokens. DigiCert recommends downloading a CSV file that contains all the information in the table under Show tokens and verify domains submitted for revalidation. To download the CSV file, under Next steps, select Download CSV.
警告
Caution: After leaving this page, the only way to get the DigiCert-generated random value for a domain is to manually open each domain's details page and copy it.
When ready, select Go to Domains page.
Revalidate using DNS CNAME record
For this method, you’ll need to go to your DNS provider and create a CNAME record for each domain selected. In the Hostname field, enter _dnsauth. Then, add [random_value].dcv.digicert.com in the target host field to point the CNAME record to dcv.digicert.com.
In the Submit domains for revalidation menu, select Revalidation by DNS CNAME record.
On the Submit domains for revalidation by DNS CNAME method page, review the selected domains.
Select Submit domains for validation.
Under Next steps, take note of the date that the unique verification tokens will expire.
Expand Show tokens and verify domains submitted for revalidation to see the domains and the unique verification token generated for each one.
Copy the unique token for each domain.
Manually copy the unique verification tokens and save them. If you prefer, create your own document and record each domain along with its corresponding unique verification token.
Or download the CSV file with all the unique verification tokens. DigiCert recommends downloading a CSV file that contains all the information in the table under Show tokens and verify domains submitted for revalidation. To download the CSV file, under Next steps, select Download CSV.
警告
Caution: After leaving this page, the only way to get the DigiCert-generated random value for a domain is to manually open each domain's details page and copy it.
When ready, select Go to Domains page.
Revalidate using email
For this method, DigiCert sends an authorization email to one or more of the following contacts for each domain selected, and the recipient must follow the instructions to complete validation:
Email to constructed email addresses
Email to DNS TXT record contact
Email to DNS CAA record contact
In the Submit domains for revalidation menu, select Revalidation by email.
On the Submit multiple domains for validation page, in the Select language for email-based verification menu, select language for the DCV emails.
Select Next.
On the Addresses to receive DCV email page, select the email address or addresses you want CertCentral to send the DCV email to for each domain.
Select Submit for validation.
On the Domains submitted for revalidation page, under Instructions, take note of the date that the emails will be valid until.
Select Done to return to the Domains page.
What's next
Use the selected DCV method to complete domain validation and demonstrate control over your domains. See Validate domains before or during certificate orders.
References: