CERTInext Sandbox Notes

CERTInext Sandbox Notes

The quick pick guide

Need

Product to choose

Sectigo Equivalent

Need

Product to choose

Sectigo Equivalent

One normal hostname, no SANs

InCommon OV SSL Certificate

 

Multiple hostnames / SANs

InCommon OV SSL Certificate UCC

 

One wildcard, such as *.dept.utexas.edu

InCommon OV SSL Certificate Wildcard

 

Wildcard plus additional SANs

InCommon OV SSL Certificate Wildcard UCC

 

Research grid / e-Science / IGTF use case

InCommon RSA IGTF Server or related IGTF product

 

“Just validate domain control, no org identity”

InCommon DV SSL Certificate UCC

 

EV / extended legal identity

InCommon EV SSL Certificate UCC, but usually not needed

 

SANs here is UCC, which is CERTInext/InCommon’s “multi-domain / SAN certificate” bucket.

DV, OV, EV

Term

Meaning

What gets validated

Typical use

Term

Meaning

What gets validated

Typical use

DV

Domain Validated

Control of the domain only

Basic TLS where organization identity in the cert is not important

OV

Organization Validated

Domain control plus organization identity

Public university services, institutional systems, most normal enterprise TLS

EV

Extended Validation

More intensive legal/entity validation

Rarely needed now; often finance/legal/high-assurance branding workflows

What the shape words mean

Term

Meaning

Example

Term

Meaning

Example

Single Domain

One FQDN

www.example.edu

UCC

Multi-domain / SAN certificate

www.example.edu, api.example.edu, login.example.edu

Wildcard

Covers one DNS label under a domain

*.example.edu covers a.example.edu, not a.b.example.edu

Wildcard UCC

Wildcard plus SANs

*.example.edu plus api.other.example.edu