The Trustico® tracking system is where an SSL Certificate license is managed after an order is placed. Each SSL Certificate is issued from that license, and the tracking system is where issuance, reissue, validation and downloads are handled for the life of the license.
Where Each Product Is Managed
Every traditional SSL Certificate license is managed in the tracking system. The ordering and billing systems hold your purchase and invoice records, however they do not provide reissue, validation, or SSL Certificate downloads.
Certificate as a Service (CaaS) products work differently again. They are managed entirely by your own Automatic Certificate Management Environment (ACME) client and are not available within the tracking system.
Traditional SSL Certificate Tracking and Management
Trustico® provides two separate tools. The tracking system covers traditional SSL Certificate licenses, while Certificate as a Service (CaaS) subscriptions are managed through their own credentials.
Access requires the reference number associated with the Certificate Authority (CA). That reference proves your right to the SSL Certificate license, so the tracking system cannot be entered without it.
Warning : Failure to retain your Certificate Authority (CA) Reference will result in the inability to manage your SSL Certificate and may result in forfeiture. Store this credential securely as Trustico® cannot recover it on your behalf.
Keeping that reference somewhere retrievable is the single most important step you can take after ordering.
What the Tracking System Provides
The tracking system is used on an order-by-order basis. Once your Certificate Authority (CA) Reference is entered, the current status of that license is displayed along with the actions available to you.
Reissue is the action used most often. An SSL Certificate can be reissued at any point during the license period at no additional cost, which is necessary whenever a shorter validity period ends before the license does. Learn About SSL Certificate Reissue 🔗
Validation status is also shown, so you can see whether the Certificate Authority (CA) is waiting on anything from you. Where a fresh Domain Control Validation (DCV) is required, the tracking system is where it is completed.
Issued SSL Certificates are downloaded here, together with the Intermediate Certificates needed for the chain to validate correctly once installed. Learn About Intermediate Certificates 🔗
Validation and the CA portal
Validation is carried out by the Certificate Authority (CA) rather than by Trustico®. The CA portal is the validation manager the Certificate Authority (CA) provides for that purpose, and it is reached from a button within the tracking system once you have logged in.
Within the CA portal you can upload documents, supply telephone numbers, and view the list of outstanding requirements for your order. It shows exactly what remains before the SSL Certificate can be issued.
Every order requires Domain Control Validation (DCV) to confirm control of the domain. An Organization Validation (OV) or Extended Validation (EV) order requires the organization validation process to be completed in addition to that.
Customers ordering an Organization Validation (OV) or Extended Validation (EV) SSL Certificate license are advised to visit the CA portal to review those requirements and any outstanding steps. Trustico® is unable to intervene in the validation process, since it takes place entirely with the Certificate Authority (CA).
E-Mails covering validation status are always sent, so progress can be followed without logging in, although the CA portal remains the authoritative view. Learn About The Validation Procedure 🔗
Programmatic Access Through the Application Programming Interface (API)
The functions available within the tracking system can also be accessed programmatically. Anything that can be viewed or managed against an SSL Certificate license through the tracking system directly is available through the Application Programming Interface (API), which suits customers and partners handling a number of licenses.
Documentation is reached by logging into the tracking system and scrolling to the foot of the page, where a link to a worked example is provided.
The example is generated against the order you are logged into, so the requests and responses shown relate to your own SSL Certificate license rather than to generic placeholder values. That makes the documentation considerably quicker to follow.
Application Programming Interface (API) access requires a key, which is issued on request. The same documentation page explains how to make that request.
License Dates and SSL Certificate Dates
Two separate dates are displayed for every order, and confusing them is a common cause of unexpected expiry. Your license validity is the total period purchased. Your SSL Certificate validity belongs to the SSL Certificate currently issued from that license.
A website stops being protected on the SSL Certificate expiration date, not on the license expiration date. Where the license runs longer, a reissue is required to continue coverage through the remainder of the term.
The tracking system displays the license validity alongside the validity details of the last SSL Certificate issued from that license.
Setting Expiry Reminders
Downloadable calendar files are provided for both the SSL Certificate expiry date and the license expiry date. Adding both to your own calendar takes a moment and removes any reliance on memory.
This matters more than it used to, because shorter validity periods leave far less margin if a date passes unnoticed. Learn About Managing Short Validity Periods 🔗
Important : Customers and partners are responsible for monitoring the expiry dates of installed SSL Certificates. Where several SSL Certificates are in use, dedicated SSL Certificate monitoring software is advisable so that installed SSL Certificates are detected and alerts are raised before a reissue is due.
Responsibility for keeping an SSL Certificate current sits with the certificate owner, or with the server administrator acting on their behalf.
Keeping Your Own Records
Your Certificate Authority (CA) Reference is what you need to keep. It works in the same way as a serial number supplied with any other product, and it becomes difficult to locate two years later if it was never recorded.
An SSL Certificate license can produce many SSL Certificates over its lifetime, since you may download and reissue as often as you wish. That was not always the case, because a license once produced a single SSL Certificate that simply ran to its expiry date.
What that means in practice is that only you know where each SSL Certificate has been installed and how many installations exist. Recording those installations, and the date each one stops working, is what keeps a website from going unprotected unexpectedly.
The license expiry date matters just as much, because once the license expires no further reissue is possible and a new license is required.
Locating Your Certificate Authority (CA) Reference
Your Certificate Authority (CA) Reference is issued by the Certificate Authority (CA) when the order is submitted, and is normally different from your Trustico® order number. It is the identifier that ties any request back to the original SSL Certificate license.
It appears in the automated e-mails sent during ordering, including the shipment notification where it is shown as the tracking number. Orders containing multiple products generate several such notifications, one for each SSL Certificate license.
It is also recorded against the order in your account ordering and billing history, and it is added to your invoice a few minutes after payment is processed. Viewing the invoice is often the quickest route to it.
Customers who ordered through the current Trustico® website can also find it within their account, by logging in with the e-mail address used to place the order. Each traditional SSL Certificate product is listed there with its license dates and its Certificate Authority (CA) Reference.
Note : In the legacy system this identifier was called the Supplier Order Number. Older documentation referring to a Supplier Order Number is referring to the same credential now known as your Certificate Authority (CA) Reference.
Where the reference cannot be located in any of those places, the comparison between the two numbers explains what to look for. Learn About Reference and Order Number 🔗
When Your Details Are Not Accepted
Where a reference is rejected, the usual cause is that the Trustico® order number has been entered instead of the Certificate Authority (CA) Reference. Checking the order confirmation e-mail for the correct identifier resolves most cases.
An order that has not yet reached the Certificate Authority (CA) will also return no result, since the reference is only created once the order has been submitted. Where neither explanation applies, the support team can assist. Learn About Trustico® Support 🔗
Certificate as a Service (CaaS) Management
Certificate as a Service (CaaS) subscriptions are not managed through the tracking system. Configuring your Automatic Certificate Management Environment (ACME) client requires your unique External Account Binding (EAB) credentials instead.
These credentials are delivered on ordering and remain available through the portal for a limited period afterward.
Important : Record your External Account Binding (EAB) credentials immediately upon receipt. After seven days, these credentials are no longer available through the portal and cannot be regenerated.
Store them securely, since they are needed again whenever an additional Automatic Certificate Management Environment (ACME) client is configured. Learn About Certificate as a Service (CaaS) 🔗