Add a domain, authorize the domain for certificates, and use HTTP practical demonstration as the validation method

Demonstrate control over your domain with HTTP practical demonstration

Before you begin

Validation Note: Before you can prevalidate a domain for TLS/SSL validation, you must first submit its organization for prevalidation. Additionally, if you want the domain to be used for OV, EV, and/or Private SSL certificates, you must submit its organization for those matching validation types.

Demonstrate control over your domain by hosting a .txt file containing a randomly generated token value at a predetermined location on your website. Once the file is created and placed on your site, DigiCert visits the specified URL to confirm the presence of your verification token. Make sure to avoid some of the more Common mistakes: HTTP practical demonstration DCV method.

Step I: Add and authorize a domain for TLS/SSL certificate

  1. In your CertCentral account, in the left main menu, go to Certificates > Domains.

  2. On the Domains page, click New Domain.

  3. On the New Domain page, under Domain Details, enter the following domain information:

    1. Domain Name
      In the box, enter the domain name the certificates will secure.
    2. Organization
      In the dropdown, select the organization you want to assign the domain to.
  4. Under Validate This Domain For, check the validation types for which the domain must be validated.

    • OV/EV Domain Validation
      Allows you to order OV and EV SSL/TLS certificates for this domain, such as Standard SSL, Secure Site SSL, and Secure Site Pro EV SSL.
    • Private SSL Domain Validation
      Allows you to order private SSL certificates for this domain, such as Private SSL and Private Multi-Domain SSL.
  5. Under Domain Control Validation (DCV) Method, select HTTP Practical Demonstration.

Note: The default DCV method is Verification Email.

  1. When you are finished, click Submit for Validation.

Step II: Use HTTP practical demonstration to demonstrate control over the domain

Create Your .txt File:

  1. Create your .txt file:

    1. Under User Actions, in the Your unique verification token box, copy your verification token.
      To copy the value to your clipboard, single click in the text field.
      Note: The unique verification token expires after thirty days. To generate a new token, click the Generate New Token link.
    2. Open a text editor (such as Notepad) and paste in Your unique verification token.
    3. In Your HTTP token URL, the string after pki-validation/ is the name of your .txt file.
      For example, if Your HTTP token URL is, then, your file name is c7e2ff0c848e4707594066cc860.txt
    4. Save the .txt file under this name (for example, c7e2ff0c848e4707594066cc860.txt).
  1. Create the .well-known/pki-validation/ directory:

    Create the .well-known/pki-validation/ directory on your site and place your .txt file in it.

Note: On Windows-based servers, the .well-known folder must be created via command line (mkdir .well-known).

  1. Verify the HTTP token

    1. In your CertCentral account, in the left main menu, go to Certificates > Domains.
    2. On the Domains page, in the Domain Name column, click domain link.
    3. On the domain information page (e.g.,, at the bottom of the page, click Check HTTP Token.

Troubleshooting tips

Verify the URL matches exactly, making sure that the URL for your web page matches the DigiCert provided URL.

  • http://YourDomain/.well-known/pki-validation/[filename].txt

Where YourDomain matches the domain that you are validating, and [filename].txt matches the unique hash provided by DigiCert under Your HTTP token URL (for example, c7e2ff0c848e4707594066cc860.txt).

If you are missing a period, a number, or a letter, validation cannot be completed.