Validate domains on a pending DV TLS certificate using Persistent DNS TXT record
Use the Persistent DNS TXT record domain control validation (DCV) method to demonstrate control over the domains on a pending DV TLS certificate order. With DV TLS certificates, you select one domain control validation (DCV) method to validate all domains on the certificate. However, each domain on the certificate must have its own persistent DNS TXT record.
With this method, you create a persistent DNS TXT record for the domain and add the required persistent URI value. After you add the record and it's publicly available, DigiCert checks the domain's DNS TXT records for the required hostname and persistent URI. You leave the record and URI in place afterward. The same values are reused for future revalidations, making them faster and reducing manual DNS updates.
Atenção
Important: Don’t delete the persistent DNS TXT record after the domain is validated. Keep the record and its persistent URI in place so you can reuse it for future persistent DNS TXT domain validations.
Before you begin
Make sure you have access and permission to create or modify DNS TXT records for each domain on the certificate order.
Step 1: Select the Persistent DNS TXT Record DCV method
In CertCentral, go to the certificate's Order # details page.
For Enterprise, Partner, and Legacy retail accounts: In the left main menu, go to Certificates > Orders. On the Orders page, in the Order # column, select the certificate's order number link.
For CertCentral Subscription accounts: In the left main menu, go to My Digital Trust Products > Certificates. On the Certificates page, in the Order # column, select the certificate's order number link.
On the certificate’s Order # details page, in the Certificate status section, check whether the certificate is waiting for domain validation to be completed.
Under What do you need to do, select the Prove control over domains link.
In the Prove control over domain window, in the Domain control validation (DCV) method menu, select Persistent DNS TXT Record and then select Save.
Step 2: Copy your persistent URI
In the Prove control over domain window, go to 3. Add the DigiCert-provided persistent URI.
For DV certificates, CertCentral only supports the Account URI.
The Account URI lets you use the same persistent URI to validate any domain on the order and in your CertCentral account
Under Your persistent URI, select Copy. Add it to the persistent DNS TXT record in the next step.
Step 3: Create a persistent DNS TXT record for each domain
Repeat this process for each domain on the certificate.
Go to your DNS provider's website and create a new DNS record for your domain.
For provider-specific instructions, refer to your DNS provider’s documentation for creating or updating DNS TXT records.
In the record Type field, or its equivalent, select TXT.
In the Host field, sometimes labeled Name or Hostname, enter
_validation-persist.Some DNS providers automatically append your domain name. Others may require the complete hostname, for example:
_validation-persist.example.comIn the Value field, sometimes labeled Content or TXT value, enter the persistent URI value you copied from CertCentral.
Example:
digicert.com; accounturi=https://digicert.com/account/{{your_persistent_uri_value}}Select a Time-to-Live (TTL) value or use your DNS provider's default TTL value.
Save the persistent TXT record.
Step 4: Check the DNS TXT records in CertCentral
In CertCentral, return to the certificate’s Order # details page.
For Enterprise, Partner, and Legacy retail accounts: In the left main menu, go to Certificates > Orders. On the Orders page, in the Order # column, select the certificate's order number link.
For CertCentral Subscription accounts: In the left main menu, go to My Digital Trust Products > Certificates. On the Certificates page, in the Order # column, select the certificate's order number link.
In the Certificate status section, under What do you need to do, select the Prove control over domains link.
In the Prove control over domain window, go to 5. Complete domain validation and select Check record.
What's next
You've validated the domain.
Atenção
Important: You're done, but don't delete the persistent DNS TXT record now that the domain is validated. Keep the record and its persistent URI value in place so DigiCert can reuse it for future revalidations.
Troubleshoot Persistent DNS TXT domain validation issues
If validation doesn't complete, confirm that the DNS TXT record is publicly resolvable and contains the exact persistent TXT value displayed in CertCentral.
Issue | What to check |
|---|---|
TXT record created on the wrong hostname | Confirm the hostname value matches the domain being validated. |
Hostname value was omitted or misspelled | Confirm the hostname uses the following format: Some DNS providers automatically append your domain name. Others may require the complete hostname. |
Persistent URI was copied incorrectly or modified | Copy the exact persistent URI from CertCentral without changing it. |
Extra characters added to the record value | The TXT value field must contain exactly what is shown in CertCentral with nothing added or removed. |
DNS propagation incomplete | Allow time for DNS propagation before checking the record. |