添加域、授权证书的域和使用 DNS CNAME 记录作为 DCV 方法
通过 DNS CNAME 记录证明对域的控制权
Use these instructions to add a domain to your CertCentral account and validate it using the DNS CNAME domain control validation (DCV) method. In the domain's DNS as a CNAME record, add _dnsauth in the hostname field. Then, add [random_value].dcv.digicert.com to the target host field, to point the random value and domain to DigiCert at dcv.digicert.com.
在开始之前
通过创建包含随机生成令牌的 DNS CNAME 记录来证明对域的控制权。CNAME 记录用于将令牌和域指向 DigiCert (dcv.digicert.com)。
To use the domain in OV, EV, or private TLS/SSL, or Secure Email certificates, you must submit the organization for validation. Learn how to submit an organization for validation.
When you have an organization, add a domain to the account and assign it to an organization.
Acronyms in this article: Domain Name System (DNS), Canonical Name (CNAME), organization validation (OV),
第 1 步:添加和授权用于 TLS/SSL 证书的域
In CertCentral, in the left main menu, go to Certificates > Domains.
For CertCentral Subscription accounts, in the left menu, go to Validation > Domains.
在域页面上,单击新域。
在新域页面的域详细信息下,输入域和组织信息。
域名
在框中输入证书要保护的域名。
组织
在下拉列表中,选择您要向其分配域的组织。
在域控制验证 (DCV) 方法下,选择 DNS CNAME 记录。
完成后,单击提交验证。
第 2 步:使用 DNS CNAME 记录证明对域的控制权
On the domain's page, in the Domain control validation (DCV) method section, under User actions, copy the random value from Your unique verification token.
The unique verification token expires in 30 days. To generate a new token, select the Generate New Token link.
Create your DNS CNAME record.
Go to your DNS provider’s site and create a new CNAME record.
For more detailed instructions for creating or updating a DNS TXT record, try the following resources:
Your DNS provider's documentation.
DigiCert knowledge base for articles like this one: Create a CNAME Record.
In the hostname field (or equivalent), enter
_dnsauth.In the record type field (or equivalent), select CNAME.
In the target host field (or equivalent), enter
[random_value].dcv.digicert.comto point the CNAME record to dcv.digicert.com.Select a Time-to-Live (TTL) value or use your DNS provider's default value.
Save the record.
重要
On October 28, 2025, DigiCert ended support for the
[random_value]prefix DNS CNAME record configuration. To learn more about this change, see the October 28 change log entry.验证 DNS CNAME 记录:
In CertCentral, in the left main menu, go to Certificates > Domains..
For CertCentral Subscription accounts, in the left menu, go to Validation > Domains.
在域页面的域名列中,单击域链接。
在域信息页面底部,单击检查 CNAME。