Setting Up a User-Managed SSL Certificate (SSL Premium)
Please use the “Print” function at the bottom of the page to create a PDF.
This article describes how to set up a IONOS SSL Premium certificate for use with a server product.
When you set up the SSL certificate in your IONOS account, you will receive your personal private key. The certificate is then requested from Sectigo and issued to the desired domain after successful validation.
Prerequisites
- Your package contains a not yet set up, user-managed SSL certificate of the type
Instant SSL EV (SSL Premium) - Your domain and the website you want to secure are in the same hosting package.
- Your domain is fully set up (status: Active).
How to set up the SSL certificate via your certificate management:
- Log in to your IONOS account.
Click Menu > Domain & SSL in the title bar.
The page listing all your domains is displayed.- Click on Manage in the section SSL certificates under Portfolio. The overview of your SSL certificates is displayed.
Search for the SSL certificate of type SSL Premium that has not yet been set up.
Click on Not set up yet in the corresponding row in the Domain column.
Select the desired domain you want to issue the certificate to or enter it in the input field.
The Set up SSL certificate page is displayed.Make sure the setting Use with my own server is selected as the intended use.
Check the details for your company and adjust them if necessary. Make sure that the details of your company or organisation and the administrative and technical contacts are correct, as the certification authority will attempt to contact them during the authentication process.
Please Note
Any change to the company name you make here will also be transmitted to the WHOIS database and is therefore publicly visible. Please always enter the telephone number in international format. The country code is marked with a preceding + (plus).
- Read and confirm the terms of use.
- Click on Set up SSL certificate.
Click on Download Private Key and save the key on your computer.
Please Note
Keep the private key in a safe place, as you cannot use the SSL certificate without a private key. For security reasons, the private key is neither stored by IONOS nor by the certification authority and therefore cannot be requested again. In the event of a loss, the SSL certificate must be reissued via the SSL administration (this generates a new key pair).
The SSL certificate is now requested from the certification authority. This verifies the identity of the applicant company as well as its ownership rights to the domain. After the final identity authentication, you can download the SSL certificate and install it on your server.
Note
As long as the company validation is being carried out by the certification authority, you can view the current status in your IONOS account at any time. To do this, simply click on the relevant certificate in the certificate list.
Stages of Validation - Briefly Explained
Validation by the certification body takes place in several steps:
- Company Authentication: The Certification Authority (Instant SSL EV) matches the company name, registration and security status of the company specified in the Certificate Signing Request with the appropriate registration authority of the country, state or (in some cases) the jurisdiction of the city. Public information is also looked up on the Internet.
- Domain Authentication: The certification authority checks whether the domain name in question is registered on the registered company name in a publicly accessible WHOIS database. If the domain name is not registered for the registered company name, alternative:
- A legally valid proof can be provided - proof of usage rights for the domain name can be provided, or additional documents can be provided. - Telephone Verification: As final identity authentication, the certification authority calls the company contact specified in the domain whois. The call can also be answered by another person in the company.
If the certification authority does not reach anyone, either a voice message will be left on the contact's answering machine or an email will be sent by Instant SSL EV with further instructions. This includes information on how to contact the certification body to complete the verification.