Planning and Deploying a Multi-Domain SSL Certificate

Planning and Deploying a Multi-Domain SSL Certificate

Zane Lucas

A Multi-Domain SSL Certificate, also offered under the Unified Communications Certificate (UCC) name, secures several names on one SSL Certificate. Getting the most from it is mostly a matter of planning the names before you order and managing them sensibly afterward.

This guide walks through that practical side : scoping the names, mapping the primary name and the Subject Alternative Name (SAN) entries, validating each name, installing once, and adding names later. Learn About Multi-Domain SSL Certificates 🔗

Inventory the Names First

Start by listing every name that needs protection, including the root domain, the www host, and any subdomains and separate domains in use. A name left off the list will not be covered, so a thorough sweep at this stage avoids a gap later.

Group the names so you can see the pattern. A long list of subdomains under one domain may point toward a Wildcard SSL Certificate instead, while a spread of separate domains is exactly what a Multi-Domain SSL Certificate is for. Learn About Wildcard SSL Certificates 🔗

Map the Primary Name and the Subject Alternative Name (SAN) Entries

One name is the primary name and sits in the Common Name (CN) field. Every other name becomes an entry in the Subject Alternative Name (SAN) field, and the SSL Certificate is valid for all of them equally.

The choice of primary name is mostly administrative, so pick the main public domain for clarity. Learn About the Subject Alternative Name (SAN) Field 🔗

Generate One Certificate Signing Request (CSR)

A Multi-Domain SSL Certificate uses a single Certificate Signing Request (CSR) generated for the primary name. The additional names are supplied during the order rather than placed inside the Certificate Signing Request (CSR) itself.

Generate the Certificate Signing Request (CSR) on the server where the SSL Certificate will live, and keep the matching Private Key safe. Learn About Certificate Signing Requests (CSR) 🔗

Validate Every Name

Each name on the SSL Certificate must pass Domain Control Validation (DCV) before the Certificate Authority (CA) issues it. Domain Validation (DV) confirms control of each name, while Organization Validation (OV) and Extended Validation (EV) add checks of the business behind them.

Plan for this : you need a way to complete validation for every name, whether by file, Domain Name System (DNS) record, or e-mail. A single unvalidated name will hold up the whole SSL Certificate. Learn About SSL Certificate Validation 🔗

Install Once, Cover Everything

Once issued, the SSL Certificate is installed a single time on the server that answers for the names, and it then secures every listed name from that one installation. This is the core saving in day-to-day work compared with juggling separate SSL Certificates.

Where the names are served by different systems, the same SSL Certificate and its Private Key are installed on each, since all the names share one SSL Certificate. Learn About SSL Certificate Installation 🔗

Add Names and Keep Coverage Current

To cover a new name after issuance, order an additional Subject Alternative Name (SAN) for the existing SSL Certificate, and Trustico® adds it. The cost is pro-rated to the validity left on your license, so the new name shares the same expiry date.

Keep one record of every name and one reminder for the shared expiry date, since a single lapse would affect all of them at once. A reissue stays available without charge for a Private Key change or to claim validity from a multi-year license. Compare the Trustico® Multi-Domain Range 🔗

Back to Blog

Most Popular Questions

Frequently asked questions covering how to plan, order, validate, install, and maintain a Multi-Domain SSL Certificate, also offered under the Unified Communications Certificate (UCC) name.

How Should Someone Plan a Multi-Domain SSL Certificate?

Start by listing every name that needs protection, including the root domain, the www host, subdomains, and separate domains. A name left off the list will not be covered, so a thorough inventory avoids a gap later.

How Does the Primary Name Relate to Subject Alternative Name (SAN) Entries?

One name is the primary name and sits in the Common Name (CN) field, and every other name becomes a Subject Alternative Name (SAN) entry. The SSL Certificate is valid for all of them equally.

How Many Certificate Signing Requests (CSR) Does the Order Need?

A Multi-Domain SSL Certificate uses one Certificate Signing Request (CSR) generated for the primary name. The additional names are supplied during the order rather than placed in the Certificate Signing Request (CSR) itself.

How Does Each Name Become Validated?

Every name must pass Domain Control Validation (DCV) before the Certificate Authority (CA) issues the SSL Certificate. You need a way to validate each name by file, Domain Name System (DNS) record, or e-mail, and one unvalidated name holds up the whole SSL Certificate.

How Does Someone Install a Multi-Domain SSL Certificate?

The issued SSL Certificate is installed once on the server that answers for the names and secures every listed name from that installation. Where names are served by different systems, the same SSL Certificate and Private Key are installed on each.

How Can Someone Add a Name Later?

To cover a new name, order an additional Subject Alternative Name (SAN) for the existing SSL Certificate, and Trustico® adds it. The cost is pro-rated to the validity left on the license, so the new name shares the same expiry date.

Should Someone Choose Multi-Domain or Wildcard?

A spread of separate domains suits a Multi-Domain SSL Certificate, while many subdomains of one domain may suit a Wildcard SSL Certificate. Grouping the names during planning makes the right choice clear.

Which Validation Levels Are Available?

A Multi-Domain SSL Certificate is offered at the Domain Validation (DV), Organization Validation (OV), and Extended Validation (EV) levels. Domain Validation (DV) confirms control of each name, while Organization Validation (OV) and Extended Validation (EV) add checks of the business.

How Does the Unified Communications Certificate (UCC) Name Relate Here?

Unified Communications Certificate (UCC) and Multi-Domain SSL Certificate are two names for the same product. Both list several names in the Subject Alternative Name (SAN) field.

How Should Someone Keep Coverage Current?

Keep one record of every name and one reminder for the shared expiry date, since a single lapse affects all names at once. A reissue stays free for a Private Key change or to claim validity from a multi-year license, and it keeps the same names.

Stay Updated - Our RSS Feed

There's never a reason to miss a post! Subscribe to our Atom/RSS feed and get instant notifications when we publish new articles about SSL Certificates, security updates, and news. Use your favorite RSS reader or news aggregator.

Subscribe via RSS/Atom