SSL Certificate Tracking & Management

The Trustico® tracking system is where an SSL Certificate license is managed after an order is placed. Each SSL Certificate is issued from that license, and the tracking system is where issuance, reissue, validation and downloads are handled for the life of the license.

Where Each Product Is Managed

Every traditional SSL Certificate license is managed in the tracking system. The ordering and billing systems hold your purchase and invoice records, however they do not provide reissue, validation, or SSL Certificate downloads.

Certificate as a Service (CaaS) products work differently again. They are managed entirely by your own Automatic Certificate Management Environment (ACME) client and are not available within the tracking system.

Traditional SSL Certificate Tracking and Management

Trustico® provides two separate tools. The tracking system covers traditional SSL Certificate licenses, while Certificate as a Service (CaaS) subscriptions are managed through their own credentials.

Tracking & Management Locate Your Reference

Access requires the reference number associated with the Certificate Authority (CA). That reference proves your right to the SSL Certificate license, so the tracking system cannot be entered without it.

Warning : Failure to retain your Certificate Authority (CA) Reference will result in the inability to manage your SSL Certificate and may result in forfeiture. Store this credential securely as Trustico® cannot recover it on your behalf.

Keeping that reference somewhere retrievable is the single most important step you can take after ordering.

What the Tracking System Provides

The tracking system is used on an order-by-order basis. Once your Certificate Authority (CA) Reference is entered, the current status of that license is displayed along with the actions available to you.

Reissue is the action used most often. An SSL Certificate can be reissued at any point during the license period at no additional cost, which is necessary whenever a shorter validity period ends before the license does. Learn About SSL Certificate Reissue 🔗

Validation status is also shown, so you can see whether the Certificate Authority (CA) is waiting on anything from you. Where a fresh Domain Control Validation (DCV) is required, the tracking system is where it is completed.

Issued SSL Certificates are downloaded here, together with the Intermediate Certificates needed for the chain to validate correctly once installed. Learn About Intermediate Certificates 🔗

Validation and the CA portal

Validation is carried out by the Certificate Authority (CA) rather than by Trustico®. The CA portal is the validation manager the Certificate Authority (CA) provides for that purpose, and it is reached from a button within the tracking system once you have logged in.

Within the CA portal you can upload documents, supply telephone numbers, and view the list of outstanding requirements for your order. It shows exactly what remains before the SSL Certificate can be issued.

Every order requires Domain Control Validation (DCV) to confirm control of the domain. An Organization Validation (OV) or Extended Validation (EV) order requires the organization validation process to be completed in addition to that.

Customers ordering an Organization Validation (OV) or Extended Validation (EV) SSL Certificate license are advised to visit the CA portal to review those requirements and any outstanding steps. Trustico® is unable to intervene in the validation process, since it takes place entirely with the Certificate Authority (CA).

E-Mails covering validation status are always sent, so progress can be followed without logging in, although the CA portal remains the authoritative view. Learn About The Validation Procedure 🔗

Programmatic Access Through the Application Programming Interface (API)

The functions available within the tracking system can also be accessed programmatically. Anything that can be viewed or managed against an SSL Certificate license through the tracking system directly is available through the Application Programming Interface (API), which suits customers and partners handling a number of licenses.

Documentation is reached by logging into the tracking system and scrolling to the foot of the page, where a link to a worked example is provided.

The example is generated against the order you are logged into, so the requests and responses shown relate to your own SSL Certificate license rather than to generic placeholder values. That makes the documentation considerably quicker to follow.

Application Programming Interface (API) access requires a key, which is issued on request. The same documentation page explains how to make that request.

License Dates and SSL Certificate Dates

Two separate dates are displayed for every order, and confusing them is a common cause of unexpected expiry. Your license validity is the total period purchased. Your SSL Certificate validity belongs to the SSL Certificate currently issued from that license.

A website stops being protected on the SSL Certificate expiration date, not on the license expiration date. Where the license runs longer, a reissue is required to continue coverage through the remainder of the term.

The tracking system displays the license validity alongside the validity details of the last SSL Certificate issued from that license.

Setting Expiry Reminders

Downloadable calendar files are provided for both the SSL Certificate expiry date and the license expiry date. Adding both to your own calendar takes a moment and removes any reliance on memory.

This matters more than it used to, because shorter validity periods leave far less margin if a date passes unnoticed. Learn About Managing Short Validity Periods 🔗

Important : Customers and partners are responsible for monitoring the expiry dates of installed SSL Certificates. Where several SSL Certificates are in use, dedicated SSL Certificate monitoring software is advisable so that installed SSL Certificates are detected and alerts are raised before a reissue is due.

Responsibility for keeping an SSL Certificate current sits with the certificate owner, or with the server administrator acting on their behalf.

Keeping Your Own Records

Your Certificate Authority (CA) Reference is what you need to keep. It works in the same way as a serial number supplied with any other product, and it becomes difficult to locate two years later if it was never recorded.

An SSL Certificate license can produce many SSL Certificates over its lifetime, since you may download and reissue as often as you wish. That was not always the case, because a license once produced a single SSL Certificate that simply ran to its expiry date.

What that means in practice is that only you know where each SSL Certificate has been installed and how many installations exist. Recording those installations, and the date each one stops working, is what keeps a website from going unprotected unexpectedly.

The license expiry date matters just as much, because once the license expires no further reissue is possible and a new license is required.

Locating Your Certificate Authority (CA) Reference

Your Certificate Authority (CA) Reference is issued by the Certificate Authority (CA) when the order is submitted, and is normally different from your Trustico® order number. It is the identifier that ties any request back to the original SSL Certificate license.

It appears in the automated e-mails sent during ordering, including the shipment notification where it is shown as the tracking number. Orders containing multiple products generate several such notifications, one for each SSL Certificate license.

It is also recorded against the order in your account ordering and billing history, and it is added to your invoice a few minutes after payment is processed. Viewing the invoice is often the quickest route to it.

Customers who ordered through the current Trustico® website can also find it within their account, by logging in with the e-mail address used to place the order. Each traditional SSL Certificate product is listed there with its license dates and its Certificate Authority (CA) Reference.

Note : In the legacy system this identifier was called the Supplier Order Number. Older documentation referring to a Supplier Order Number is referring to the same credential now known as your Certificate Authority (CA) Reference.

Where the reference cannot be located in any of those places, the comparison between the two numbers explains what to look for. Learn About Reference and Order Number 🔗

When Your Details Are Not Accepted

Where a reference is rejected, the usual cause is that the Trustico® order number has been entered instead of the Certificate Authority (CA) Reference. Checking the order confirmation e-mail for the correct identifier resolves most cases.

An order that has not yet reached the Certificate Authority (CA) will also return no result, since the reference is only created once the order has been submitted. Where neither explanation applies, the support team can assist. Learn About Trustico® Support 🔗

Certificate as a Service (CaaS) Management

Certificate as a Service (CaaS) subscriptions are not managed through the tracking system. Configuring your Automatic Certificate Management Environment (ACME) client requires your unique External Account Binding (EAB) credentials instead.

Certificate as a Service Credentials

These credentials are delivered on ordering and remain available through the portal for a limited period afterward.

Important : Record your External Account Binding (EAB) credentials immediately upon receipt. After seven days, these credentials are no longer available through the portal and cannot be regenerated.

Store them securely, since they are needed again whenever an additional Automatic Certificate Management Environment (ACME) client is configured. Learn About Certificate as a Service (CaaS) 🔗

Most Popular Questions

Frequently asked questions covering how to manage an SSL Certificate license using the Certificate Authority (CA) Reference, the CA portal used for validation, which system manages each product type, programmatic access, expiry dates, and Certificate as a Service credentials.

Systems Used to Manage Each Product Type

Every traditional SSL Certificate license is managed in the tracking system rather than in the ordering or billing systems, which hold purchase and invoice records only. Certificate as a Service (CaaS) products are managed by your own Automatic Certificate Management Environment (ACME) client and are not available within the tracking system.

Tracking Your SSL Certificate License

Enter your Certificate Authority (CA) Reference in the tracking system to query the status of your SSL Certificate license directly with the Certificate Authority (CA). The reference is included in the automated e-mails sent during ordering and is normally different from your Trustico® order number.

Locating Your Certificate Authority (CA) Reference

The reference appears in the automated ordering e-mails, including the shipment notification where it is shown as the tracking number. It is also recorded in your account ordering and billing history, added to your invoice shortly after payment, and listed against each product within your account.

A Lost Certificate Authority (CA) Reference

Without the Certificate Authority (CA) Reference you will be unable to manage your SSL Certificate and may forfeit access to it entirely. Trustico® cannot recover this credential on your behalf, so store it securely as soon as it is received.

Capabilities of the SSL Certificate Tracking System

The tracking system manages an SSL Certificate license, providing issuance, reissue, validation status and SSL Certificate downloads, together with the Intermediate Certificates required for installation. It is used on an order-by-order basis.

Purpose of the CA portal

The CA portal is the validation manager provided by the Certificate Authority (CA), reached from a button within the tracking system. It is used to upload documents, supply telephone numbers, and view the outstanding requirements before an SSL Certificate can be issued.

Validation Requirements for Organization Validation and Extended Validation Orders

Every order requires Domain Control Validation (DCV) to confirm control of the domain. An Organization Validation (OV) or Extended Validation (EV) order additionally requires the organization validation process, and those customers are advised to visit the CA portal to review any outstanding steps. Trustico® cannot intervene in that process.

Programmatic Access to the Tracking System

Anything available within the tracking system can also be accessed through the Application Programming Interface (API). Documentation and a worked example generated against your own order are found at the foot of the page once you have logged into the tracking system, and access requires a key issued on request.

License Dates Compared With SSL Certificate Dates

License validity is the total period purchased. SSL Certificate validity belongs to the SSL Certificate currently issued from that license. A website stops being protected on the SSL Certificate expiration date, so a reissue is required where the license runs longer.

Calendar Reminders for Expiry Dates

Downloadable calendar files are provided for both the SSL Certificate expiry date and the license expiry date. Adding both to your own calendar is the simplest safeguard against a date passing unnoticed.

Availability of Your Certificate as a Service (CaaS) Credentials

External Account Binding (EAB) credentials are available through the portal for seven days after the order date. They cannot be regenerated afterward, so record them immediately upon receipt and store them securely for configuring further Automatic Certificate Management Environment (ACME) clients.

Ask Trustico® Assistant

For Instant Answers - Start Here When You Have a Question or Need Help

Formatting Domain Name System (DNS) Records and the Trailing Dot

Formatting Domain Name System (DNS) Records and...

Why some DNS records need a trailing dot and others do not, and how to enter SSL Certificate validation records correctly in zone files and hosting panels.

Formatting Domain Name System (DNS) Records and...

Why some DNS records need a trailing dot and others do not, and how to enter SSL Certificate validation records correctly in zone files and hosting panels.

Merkle Tree Certificates Explained

Merkle Tree Certificates Explained

The move toward post-quantum cryptography solves one problem and creates another. It protects encrypted traffic against future quantum computers, but the new signature algorithms are far larger than the ones...

Merkle Tree Certificates Explained

The move toward post-quantum cryptography solves one problem and creates another. It protects encrypted traffic against future quantum computers, but the new signature algorithms are far larger than the ones...

SSL Certificates and Front-of-Site Services Like Cloudflare

SSL Certificates and Front-of-Site Services Lik...

Learn how front-of-site services like Cloudflare affect which SSL Certificate visitors see and how to apply your purchased SSL Certificate to them.

SSL Certificates and Front-of-Site Services Lik...

Learn how front-of-site services like Cloudflare affect which SSL Certificate visitors see and how to apply your purchased SSL Certificate to them.

Understanding X9 Certificates and the Public Trust Model

Understanding X9 Certificates and the Public Tr...

Learn what X9 Certificates are, how X9 PKI differs from public browser trust, and why they are not a substitute for a publicly trusted SSL Certificate.

Understanding X9 Certificates and the Public Tr...

Learn what X9 Certificates are, how X9 PKI differs from public browser trust, and why they are not a substitute for a publicly trusted SSL Certificate.

Why Your SSL Certificate Type and Brand Matter by Industry

Why Your SSL Certificate Type and Brand Matter ...

Why the type and brand of SSL Certificate matter across regulated industries, who examines your validation standing, and what is at stake when they do.

Why Your SSL Certificate Type and Brand Matter ...

Why the type and brand of SSL Certificate matter across regulated industries, who examines your validation standing, and what is at stake when they do.

Revocation Status Errors on a Valid SSL Certificate

Revocation Status Errors on a Valid SSL Certifi...

A revocation status error such as RevocationStatusUnknown can appear on a valid SSL Certificate. Learn how to confirm it is not revoked and what to do next.

Revocation Status Errors on a Valid SSL Certifi...

A revocation status error such as RevocationStatusUnknown can appear on a valid SSL Certificate. Learn how to confirm it is not revoked and what to do next.

1 / 6