SSL validation and installation

From CNAME to ready-to-use files

Know who changes DNS and who installs the certificate.

DV validation proves domain control with a CNAME record. The automation scope depends on where DNS is managed and where the certificate will be used.

Your domain
CNAME
Issued SSL
Domain Control Validation

One CNAME method, two execution paths

Both paths give the issuer the same proof of control. The only difference is who publishes and removes the DNS record.

Domain and DNS in the panel

Automatic record handling

Automation runs only for a domain owned by your account and a DNS zone editable in our panel.

  • We obtain the exact CNAME name and value from the issuer.
  • We publish the record in your zone and wait for confirmation.
  • After validation, we remove the technical record in a controlled way.
DNS outside the panel

Exact manual instructions

We do not request access to external DNS. The panel shows the record name, type and value for you to add at your provider.

  • Copy the exact CNAME record shown with the certificate.
  • Add it at your DNS provider without changing the value or target.
  • Wait for propagation and track the validation result in the panel.
Private key and CSR

Choose who generates the key material

For external hosting, keep your own key or ask us to generate a temporary encrypted package.

Guided option

We generate the key and protect it in escrow

The key enters encrypted, temporary escrow. After issuance, we prepare an encrypted package protected with the password you set.

Advanced option

You provide your own CSR

Generate the key pair in your environment and send only the CSR. The corresponding private key never leaves your system.

Responsibility boundaries

Installation depends on the target location

External hosting: self-installation

We provide the certificate, chain and — for a generated key — the one-time key package. We never log in to third-party infrastructure.

Awesome SRV is responsible for the sale, DCV and delivery of files.

Managed hosting: free TLS by default

Let’s Encrypt remains free and automatic. Paid-certificate auto-installation stays disabled until the supported agent contract is ready.

You do not need to buy paid SSL to use HTTPS on managed hosting.
Secure workflow

Secrets never become diagnostic data

Key material, CSRs and issuer responses use dedicated flows. Status remains diagnosable without exposing secrets.

  • Private keys and CSRs do not enter ordinary logs or error messages.
  • A generated key package is encrypted, temporary and single-download.
  • Before release, we verify SAN/CN and public-key compatibility.
  • We never request login credentials for external hosting.
Ready to choose

Compare available certificates and terms

The catalog shows only active DV options with a published gross price.

Open SSL pricing