Submitting a Test Certificate Application
Compared with official certificates, personal test certificates significantly lower the technical threshold and economic costs for enabling HTTPS in development and testing environments. In Huawei Cloud CCM, DigiCert provides three-month single-domain basic DV certificates as test certificates. Figure 1 shows the process from creating a test certificate to issuing it. After a test certificate is created, you need to apply for it. This section describes how to apply for a test certificate.
Prerequisites
You have created a test certificate and the certificate is in the Pending application state. For details about how to create a test certificate, see Creating a Test Certificate.
Constraints
- You can apply for a maximum of 20 test certificates under each account. In CCM, only one test certificate can be applied for at a time.
- Once you purchase a test certificate, it will be counted towards the quota even if you delete it after submitting the application or revoke it after it is issued.
- Your account and the IAM users created under your account share the test certificate quota. For example, if an account has applied for 20 test certificates, no test certificate quota is available for this account or the IAM users it creates.
- If your Huawei Cloud account has used up the quota of 20 test SSL certificates but you still want to apply for more SSL test certificates, purchase the DigiCert DV (basic) single-domain certificate package to increase your test certificate quota.
- One test SSL certificate can be used for only one single domain name.
- Test certificates cannot be used to protect IP addresses or wildcard domain names.
- By default, DNS verification is used to verify the domain ownership of a test certificate.
- The trust and security level of test certificates are low. They are recommended only for testing.
- For DigiCert DV (Basic) free certificates, no free technical support or installation guide is provided.
- A test certificate cannot be renewed. After a test certificate expires, it cannot be used anymore. If you still need an SSL certificate, create one in CCM.
Submitting a Test Certificate Application
After you create a test certificate, associate a domain name with the certificate, provide additional details, and then submit the application for approval.
- On the SSL Certificates page, click the tab. In the Operation column of the row containing the target test certificate, click Apply for Certificate.
- On the Apply for Certificate page, enter the domain name and applicant information. Figure 2 Entering application information
- Enter the domain name information.
Table 1 Domain name parameters Parameter
Description
Example Value
CSR
To obtain an SSL certificate, a Certificate Signing Request (CSR) file needs to be submitted to the CA for review. A CSR contains a public key and a distinguished name (DN). Typically, a CSR is generated by a web server. A pair of public and private keys is also created for encryption and decryption.
Options:- System generated CSR: The system automatically generates a certificate private key. Once the certificate is issued, you can download your certificate and private key on the certificate management page.
- Select an existing CSR: Select a CSR file that you have created in or uploaded to the CSRs tab. For details, see Creating a CSR and Uploading a CSR.
- Upload a CSR: You need to manually generate a CSR file and paste the content of the CSR file generated into the text box. For more details, see How Do I Make a CSR File?
System generated CSR
Domain Name
The domain name for which the certificate is used A test certificate can be used for only one single domain name.
For example, if your domain name is www.domain.com, enter www.domain.com in Domain Name. For details about the domain name reward rules, see Domain Name Types Supported in SCM.
To associate a Chinese domain name with a certificate, use encoding tool Punycode to encode the Chinese domain name and then enter the encoded data.
For example, if the encoded data is xn--siq1ht8k.com, set this parameter to xn--siq1ht8k.com.
www.domain.com
Domain Name Verification Method
- DNS: Add a resolution record to the domain name on the DNS platform hosting the domain name. For details about manual DNS verification, see Manual DNS Verification.
- File: Create the file in the specified root directory. For details about file verification, see Method 3: File Verification.
DNS
Key algorithms
DigiCert DV (Basic) and single-domain certificates support the following key algorithms: RSA_2048, RSA_3072, and RSA_4096. For details about the differences between key algorithms, see 3.c.
RSA_2048
- Enter the applicant information. For details, see Table 2.
Table 2 Authorization parameters Parameter
Description
Example Value
Applicant Details
- The CA will contact you through the applicant email address and phone number you provided to verify information.
- Personal information used as contact details is not included in the issued certificate.
-
(Optional) Technical Contact Information
The parameter is optional. You can skip it.
-
- Enter the domain name information.
- After confirming that the entered information is correct, read through the Cloud Certificate & Manager Statement, Privacy Statement, and the authorization statement, and check the box to agree to the disclaimer and statements
- Click Submit.
The system will submit your application to the CA. During the approval process, make sure that you can be reached by phone and that you regularly check for emails from the CA.
Follow-up Operations
The CA will handle your application within 2 to 3 working days and send a verification email to you.
Perform domain name verification as required. For more details, see Verifying Domain Name Ownership.
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot
