Description

This document is intended for SSL Certificates with validation types on domains. The described guide is an alternative solution for validating controls on a domain.

If you do not have access to update your registered domain and cannot verify the domain via email, you can use the File Auth method. This is used as an alternative in obtaining an SSL Certificate with the DV validation type.

The File Auth method in Domain Control is a method intended to verify a domain by accessing the hash file that has been uploaded to the website that will be installed with SSL. The way to do this is by accessing “HTTP” or what is called HTTP-Based DCV.

HTTP-Based DCV

This method requires the hash file originating from the Certificate Signing Request (CSR) to be accessed via http or port 80. Then the Certificate Authority will check the contents of the file. This stage is carried out to ensure that the contents of the file have met validation against domain controls.

To be able to validate domain controls via File Auth, follow these instructions:

After generating CSR from the server that you will install with SSL Certificates and have submitted the CSR when generating the certificate, you can request a hash file of the CSR that has been created by the Certificate Authority through us. Please contact us if you need a hash file when you need verification with File Auth.

We will send you a Hash File, in the form of a simple plain-text *.txt file. You must upload this file to the root folder of your webserver so that it can be accessed via HTTP access.

Example:

When you order an SSL Certificate from Komodo, and a CSR that has been created using the domain name www.yourdomain.com, and the MD5 hash of your CSR is 8593532A8FA01E6CEBA0B7C85E510D0F and the hash for the SHA-1 of your CSR is F18B0E3C464CCFE58209272A97ADC0E8C4233BF9, then the contents of your Auth DCV file will be:

F18B0E3C464CCFE58209272A97ADC0E8C4233BF9

comodoca.com

With file name 8593532A8FA01E6CEBA0B7C85E510D0F.txt,

Please upload the file to the root folder of your webserver so that it can be accessed via http or port 80 with the following URL:

http://www.domainanda.com/8593532A8FA01E6CEBA0B7C85E510D0F.txt

When it can be accessed, the Certificate Authority will check and search for the file and ensure that the information contained in the file matches the information from the CSR that you previously submitted.

Then the verification process for your domain control has been completed and your certificate will immediately be ACTIVE.

Informasi Tambahan

You can also create a hash file from your CSR, using the following Online CSR Decoder tool:

https://secure.comodo.com/utilities/decodeCSR.html

We recommend not to do the SHOW EMPTY FIELDS checklist and do a checklist on the SHOW CSR HASHES field before entering the CSR code and before clicking the DECODE button.

Further Questions  ?

If you have further questions regarding the need for the verification process, please click Here.