Hosted Certificate as a Service (CaaS) Issuance Tool

Certificate as a Service (CaaS) is built around automation. A client on your own server requests and reissues each SSL Certificate on its own, with no one involved. Some machines cannot run that client at all, and this tool exists for those.

It does the same job as an Automated Certificate Management Environment (ACME) client, except that Trustico® hosts it and runs it for you. You issue a real SSL Certificate from your existing Certificate as a Service (CaaS) license through four steps in a browser, with nothing to install and nothing to run on your own equipment.

What you receive is exactly what an automated client would have produced. Only the method differs.

Open The Issuance Tool

You supply your credentials, prove control of your domain names, and download the finished files. Explore Certificate as a Service 🔗

Intended Users

This tool is for customers holding a Certificate as a Service (CaaS) license who need an SSL Certificate for equipment where an Automated Certificate Management Environment (ACME) client cannot be installed or run.

The usual examples are equipment without shell access, and platforms where policy prevents new software being added.

Even then, the client does not have to run on that equipment. A separate machine can validate, obtain the SSL Certificate, and deliver it, which covers many cases where the target itself cannot. This tool suits the times when running a separate client is not practical either. Learn About Running Your Client Anywhere 🔗

It is also a straightforward way to see how Certificate as a Service (CaaS) works. Working through the four steps by hand shows plainly what an automated client does on your behalf.

Where a client can be run, it is still the better choice. Automation removes the manual work and keeps every file on your own equipment. Learn About Automated Client Options 🔗

On cPanel hosting, the Trustico® cPanel Plugin provides that same automation from inside the dashboard, without the command line. Explore the Trustico® cPanel Plugin 🔗

Recommended Usage

Trustico® recommends this tool for installations within a testing or development environment, or where an SSL Certificate is needed for development purposes.

The safest way to produce any private file or credential is to generate it directly on the server where it will be used, so that nothing sensitive is created or held anywhere else. This holds true whatever tooling you choose.

Assistance and Authorization

Customers already engage Trustico® to assist with the generation and installation of their SSL Certificates. This tool is an extension of that existing assistance, not a separate service.

Files of this kind are produced on request, and only where the customer holding the license has authorized Trustico® to do so. Anyone using the tool is asking Trustico® for help to have an SSL Certificate issued and put to full use.

Validation is always yours to complete. Proving control of a domain name is something only the domain holder can do, whichever route you take.

You are equally welcome to carry out every step yourself, within your own environment, without involving Trustico® or any other third party. Learn About Running Automation Yourself 🔗

You could also go further and build your own. Certificate as a Service (CaaS) runs on the open Automated Certificate Management Environment (ACME) standard, so nothing about this tool belongs to Trustico® alone.

A customer with the skills to do so is free to build an equivalent tool against the same service, using the same External Account Binding (EAB) credentials this tool uses. Treat what you see here as one worked example of what the standard allows, not the only path to it.

Requirements Before Starting

You need a current Certificate as a Service (CaaS) license. The tool issues against that existing entitlement and does not create a new one.

You also need the External Account Binding (EAB) credentials that belong to the license, namely a Key Identifier and an HMAC Key. These are the same credentials an automated client would use. Learn About External Account Binding (EAB) Credentials 🔗

Finally, you need a way to prove control of each domain name, which means the ability to publish a Domain Name System (DNS) record or to place a file on the website being secured. Learn About Obtaining Your Credentials 🔗

Four Steps

The tool works through four stages in order. Each one waits for you and does not move on by itself.

Selecting Your Service

Four services are offered : Trustico® Domain Validation, Trustico® Organization Validation, Sectigo® Domain Validation and Sectigo® Organization Validation.

Your choice must match the Certificate as a Service (CaaS) license you hold. The credentials you supply in the next step belong to one specific service.

Entering Domain Names and Credentials

This tool issues a single SSL Certificate covering up to 100 domain names, with wildcard entries supported alongside ordinary names. A Certificate as a Service (CaaS) license itself can secure more than that, from a few names to hundreds, through an automated client where a larger count is needed.

You also choose the key type here. RSA is available at 2048, 3072, 4096 and 8192 bits, and Elliptic Curve Cryptography (ECC) is available at P-256 and P-384. RSA at 2048 bits is the default and a sound choice for most installations.

Domain Control Verification

Every domain name on the SSL Certificate offers a Domain Name System (DNS) record or a file served over Hypertext Transfer Protocol (HTTP). You choose whichever you can put in place most easily.

Important : A wildcard entry offers the Domain Name System (DNS) record only. This restriction comes from Certificate Authority (CA) rules that Trustico® must follow, and applies wherever a wildcard is issued.

Publish the record or place the file, then ask the tool to check it when you are ready. You review the outcome at your own pace, and nothing runs in the background while you wait. Learn About The Validation Procedure 🔗

Downloading Your Files

Four files are produced : the SSL Certificate itself, the intermediate chain, the full chain, and the matching key file. Take them one at a time, or take all four together as an archive.

The intermediate chain must be supplied alongside the SSL Certificate. Browsers rely on the complete path to establish trust. Learn About Intermediate Certificates 🔗

Working Without Deadlines

Nothing in the tool expires, and nothing is queued behind a deadline of ours. Validation proceeds only when you press the button, which matters when a Domain Name System (DNS) change has to pass through someone else.

You may also step away entirely. At any point you can download a configuration file, close the browser, and return later, on a different day or a different computer, to continue from exactly where you stopped.

A request begun on a workstation can be finished from elsewhere without starting again, and an afternoon spent waiting for a record to propagate costs you nothing.

File Generation and Storage

The key file that accompanies your SSL Certificate is generated on the Trustico® server, not inside your browser. This affects how the resulting files should be handled, so it is stated plainly here.

Warning : For privacy and security purposes, we strongly recommend using tools provided within your hosting or server environment.

This service may store data in an encrypted state for a period of up to 48 hours to facilitate the issuance and delivery process, and anyone holding your configuration file can retrieve your issued files during that time. Stored data is subsequently destroyed and unrecoverable.

Treat the configuration file as a credential for as long as it stays valid. It is what allows a session to be resumed and the issued files to be collected.

Where your equipment can produce its own key material, doing so keeps everything sensitive inside your own environment and is the stronger practice. Learn About Generating Your Own Files 🔗

Transit Protection

Every exchange with the tool travels over Hypertext Transfer Protocol Secure (HTTPS). Outbound requests are restricted to approved Trustico® and Sectigo® endpoints, so the tool will not connect anywhere else.

The connection between the tool and its storage layer is encrypted in the same way. The issuing authority is pinned, and any unverified endpoint is refused.

Storage Protection

A stored session is never written in readable form. It is encrypted before it reaches storage, and the key that encrypts it is derived from your own session token, not from anything Trustico® holds.

Most services of this kind hold a decryption key of their own. Trustico® deliberately does not, which is the point of the design.

The key that unlocks your session stays with you, not on our servers. The table below shows how.

Measure Implementation
Cipher AES-256-GCM
Key Derivation HKDF-SHA256
Key Source Customer Session Token, 256 Bit
Salt 16 Random Bytes, Fresh per Write
Initialization Vector 12 Random Bytes, NIST SP 800-38D
Integrity Galois/Counter Mode (GCM) Tag

The salt is generated fresh on every write, so two saves of the same session are encrypted under different keys.

Consequences of the Design

Trustico® can decrypt a session only while handling a request that presents your token, and that token is not stored. At rest the data is opaque, so a copy of the storage on its own reveals nothing, and no master key exists on our side to be leaked or mismanaged.

Presenting the token is itself the decryption. An incorrect token fails the authentication tag, so it can neither read the session nor alter it.

Your configuration file is therefore your own recovery path, and the only one. If the token is lost and no configuration file has been kept, the session cannot be recovered by Trustico® or by anyone else.

In practice, keeping your configuration file safe matters. Losing it costs you the session without exposing it to anyone.

Session Cookie Handling

The token is carried in a cookie marked HttpOnly, Secure and SameSite strict, using the host prefix that browsers refuse to set without Secure. Scripts running on the page cannot read it.

Failing Closed

Where any part of this protection cannot be applied in full, the tool stops instead of continuing with something weaker. Failing closed is the deliberate choice throughout.

Stored data is destroyed after 48 hours. It is not archived and cannot be recovered afterwards, by Trustico® support or by anyone else.

Installing the Issued SSL Certificate

Installation is unchanged from any other SSL Certificate. The files are supplied in standard formats that every common platform accepts.

This tool exists for equipment that cannot automate, so plan the reissue well before the current SSL Certificate reaches its validity end date. Learn About Installing an SSL Certificate 🔗

Open The Issuance Tool Certificate as a Service

The tool is available to every Certificate as a Service (CaaS) customer and adds nothing to the cost of the license you already hold.

Tip : This tool is one of several ways to use your Certificate as a Service (CaaS) license, alongside a standalone ACME client and the Trustico® cPanel Plugin. The license places no limit on how often SSL Certificates are issued for your licensed domain names throughout the license period, and more than one method can be in use at the same time, all sharing the same External Account Binding (EAB) credentials. You are free to move between them whenever you need to.

Most Popular Questions

Frequently asked questions covering the hosted Certificate as a Service (CaaS) issuance tool, who it is for, the basis on which it is offered, the steps involved, and how the resulting files are generated and protected.

Hosted Issuance Tool Purpose

The tool performs the same role as an Automated Certificate Management Environment (ACME) client, hosted by Trustico® rather than installed on your own equipment. It issues a real SSL Certificate from an existing Certificate as a Service (CaaS) license through four steps in a browser.

Intended Users

It suits customers holding a Certificate as a Service (CaaS) license who need an SSL Certificate for equipment where an Automated Certificate Management Environment (ACME) client cannot be installed. It also shows plainly what an automated client does on the customer's behalf.

Recommended Use

Trustico® recommends this tool for installations within a testing or development environment, or where an SSL Certificate is required for development purposes. Customers are equally welcome to carry out every step themselves within their own environment rather than involving any third party.

Assistance and Authorization

Customers already engage Trustico® to assist with the generation and installation of their SSL Certificates, and this tool is an extension of that existing assistance. Files are produced on request and only where Trustico® has been authorized to do so by the customer holding the license.

Requirements Before Starting

A current Certificate as a Service (CaaS) license is required, along with the External Account Binding (EAB) credentials belonging to it, being a Key Identifier and an HMAC Key. You also need the ability to publish a Domain Name System (DNS) record or place a file on the website being secured.

Domain Names Permitted Per SSL Certificate

This tool issues a single SSL Certificate covering up to 100 domain names, with wildcard entries supported alongside ordinary names. A Certificate as a Service (CaaS) license itself can secure more, from a few names to hundreds, through an automated client where a larger count is needed.

Domain Control Verification Methods

Validation remains the customer's to complete, because proving control of a domain name is something only the domain holder can do. Every domain name offers a Domain Name System (DNS) record or a file served over Hypertext Transfer Protocol (HTTP), and a wildcard entry offers the Domain Name System (DNS) record only.

Pausing and Resuming Requests

A configuration file may be downloaded at any point, allowing the browser to be closed and the request continued later from a different day or a different computer. Nothing restarts and nothing inside the tool expires.

Files Produced

Four files are produced, being the SSL Certificate itself, the intermediate chain, the full chain, and the matching key file. They may be taken individually or together as an archive.

File Generation and Storage

The key file that accompanies your SSL Certificate is generated on the Trustico® server rather than inside the browser. A stored session is encrypted before it is written, using a key derived from your own session token rather than anything Trustico® holds, and stored data is destroyed after 48 hours.