Maintenance for DigiCert, GeoTrust, Thawte, RapdidSSL products on August 18th 2020
Due to a change in our backend for DigiCert, GeoTrust, Thawte and RapdidSSL products we will have a maintenance on August 18th 2020 from 09:00 CEST - 11:00 CEST
Management of DigiCert, GeoTrust, Thawte and RapdidSSL products will not be available during this timeframe. Commands will not be queued, but responded to with an error message.
Orders that have not been completed before the maintenance might be delayed and will be finished after the maintenance is over. We don't expect many certificates to be delayed.
For testing purposes the changes will be published in our OTE environment on Friday Morning July 17th.
Technical Changes for SAN certificates as of August 18th 2020 13:00 CEST
We're introducing changes by adding the possibility to specify a separate approver email address per SAN certificate.
These changes affect the commands AddCertificate, RenewCertificate, ModifyCertificate and ReissueCertificate.
The respective CA will send out approver emails to the addresses for the base domain and all SAN domains stated in the certificate order for email-validated certificates.
To give you control about which emails are used, we will allow you to specify them in the commands.
This is done by stating the newly introduced parameters APPROVEREMAIL[0-24] instead of just APPROVEREMAIL in AddCertificate, RenewCertificate and ModifyCertificate and with REISSUEEMAIL[0-24] instead of REISSUEEMAIL in ReissueCertificate commands.
Those email addresses must be in the same order as the DOMAIN[0-24] given in the AddCertificate , RenewCertificate, ModifyCertificate and ReissueCertificate Commands.
The domains and SAN domains including their order can be retrieved by issuing a StatusCertificate command. Within the response the domains are returned as property[crt san][0-24]= [DOMAIN].
For your convenience, we will also allow the use of APPROVEREMAIL0 (or REISSUEEMAIL0 for reissues) to be used in single-domain certificates, too.
Those are working as aliases for the existing parameters APPROVEREMAIL / REISSUEEMAIL.
This means that you can switch to APPROVEREMAIL0 / REISSUEEMAIL0 for all certificate commands that use APPROVEREMAIL / REISSUEEMAIL.
Please note that stating APPROVEREMAIL0 will overwrite APPROVEREMAIL if both are given, preferring newer syntax while allowing old syntax.
If invalid addresses are stated, the respective CA will send out emails to ALL applicable email addresses for each SAN, i.e. mails will be sent out per SAN domain using the following local parts: admin@, administrator@, hostmaster@, webmaster@ and postmaster@
If you choose to not include different email addresses for each SAN domain, or if invalid addresses are stated, the respective CA will send out emails to ALL applicable email addresses for each SAN, i.e. mails will be sent out per SAN domain using the following local parts: admin@, administrator@, hostmaster@, webmaster@ and postmaster@
You can choose to state or not state email addresses for any number of SAN domains. For example by stating APPROVEREMAIL[0-4] but leaving others empty, etc.