Domain Control Validation (DCV) is a process in which the Certificate Authority (CA) verifies that you have control over the requested domain before issuing the SSL certificate. This verification occurs when you place a certificate order with a third-party CA. To perform DCV, the CA issues a challenge to verify domain ownership. The challenge format varies depending on the validation method selected by you during the certificate order process:
Once you complete the challenge, the CA verifies it. If the verification succeeds, the CA issues the SSL/TLS certificate. Key Manager Plus Cloud then fetches the certificate and adds it to the certificate inventory, where it can be managed and further deployed to the endpoint servers.
Key Manager Plus Cloud supports the following DCV methods:
For DNS-based DCV, the DNS details should be preconfigured. Refer to this document for detailed instructions.
Additional Detail
The CAs that supports the email-based DCV in Key Manager Plus Cloud are GoDaddy, The SSL Store, GlobalSign, and AWS-ACM.
In this method, the Certificate Authority sends a verification email to the approver email address specified during the certificate order request. The email contains instructions that should be followed to complete the validation process.
Additional Detail
For GoDaddy CA, the challenge IDs are mailed to the requester's email as well as the domain administrator's email.
After completing the steps in the email:
If the validation is successful, the CA issues the certificate. The certificate is then automatically fetched into the certificate inventory of Key Manager Plus Cloud.
From the inventory, you can deploy the certificate directly to endpoint servers such as a Certificate Store or IIS server.
Additional Detail
The CAs that supports the file or HTTPS-based DCV in Key Manager Plus Cloud are The SSL Store, GlobalSign, Let's Encrypt, Buypass Go SSL, and ZeroSSL.
When you choose file (HTTP/HTTPS)-based DCV, the certificate authority generates a challenge file at the time of order creation. To validate the domain, this file should be placed in the specified path on the domain server.
For Windows servers, this can be performed directly from the Key Manager Plus Cloud interface. Otherwise, you have to place the file on the specified path manually.
Follow these steps to place the file directly from the Key Manage Plus Cloud interface:
Additional Detail
The Key Manager Plus Cloud Agent should be installed on the Windows server before proceeding. Refer to this document for installation instructions.

Once the challenge file is deployed, verify the order status of the certificate under the respective CA in Key Manager Plus Cloud. If the validation is successful, the CA issues the certificate. The issued certificate is then automatically fetched into the SSL >> Certificates inventory, from where it can be managed or deployed to endpoint servers.
Additional Detail
For DigiCert CA, you should pre-validate your domains and organizations in the CertCentral portal before placing certificate orders from Key Manager Plus. Once pre-validation is complete, certificate issuance and renewals for those domains and organizations are straightforward. Refer to this document for detailed instructions.
Caution
Ensure that the Key Manager Plus Cloud Agent is installed on the Windows server before proceeding. Refer to this document for installation instructions.
When you choose DNS-based DCV, the CA provides a DNS challenge value and text record at the time of order creation. You should copy these records and manually add them to the domain server. For Windows servers, this verification process can also be carried out from Key Manager Plus Cloud by configuring the server details under Manage >> Deploy.
Additional Detail
For DigiCert CA, users can pre-validate organizations and domains in CertCentral to automate DNS challenge deployment. Refer to this document for detailed instructions.
To perform the DNS-based DCV, follow the steps below:

The DNS challenge values and text records are automatically created in the configured DNS servers. After the records are validated, check the certificate order status under the respective CA in Key Manager Plus Cloud. If validation succeeds, the CA issues the certificate, which is then fetched and stored in the SSL >> Certificates tab. From here, you can deploy the certificate directly to endpoint servers such as a Certificate Store or IIS server. Click here for more details on certificate deployment.
Additional Details