GoGetSSL Logo
SSL CertificatesTrust solutions
Home Wiki SSL Basics How to Get an SSL Certificate

How to Get an SSL Certificate

  • Obtaining an SSL certificate from GoGetSSL is a straightforward process that follows the same steps regardless of the certificate type. Here is what to expect from start to finish.

Step 1 — Choose Your Certificate

Start by selecting the certificate that matches your needs in terms of validation level (DV, OV, or EV) and domain coverage (single domain, wildcard, or multi-domain). If you are unsure which option is right for your use case, see our guide: [link to Types of SSL Certificates]. If you need help choosing a specific brand or product, contact our support team and we will be happy to assist.

Step 2 — Generate a CSR

A Certificate Signing Request (CSR) is a file that contains your domain name, organization details, and public key. It is required to place your order and is submitted to the Certificate Authority during the issuance process. A CSR can be generated directly on your server using your server software, or using an online tool.

For most server types, you can generate a CSR using the GoGetSSL Online CSR Generator. It produces a ready-to-use CSR in seconds without any command line required.

⚠ Note: Microsoft IIS users: If your server runs IIS, you must generate the CSR directly on the server using IIS Manager — not via an online tool. IIS binds the private key to the server at the time of CSR generation, and the certificate cannot be installed if the key was created elsewhere. See our IIS CSR generation guide for step-by-step instructions.

About Your Private Key

When a CSR is generated, a private key is created alongside it. The private key is the cryptographic counterpart to the public key embedded in your certificate — it is what your server uses to decrypt incoming connections and prove ownership of the certificate.

The private key is generated once and cannot be retrieved or regenerated after the fact. If you lose it, the certificate becomes unusable — a certificate cannot be installed without its corresponding private key. In that case you will need to reissue with a new CSR and key pair. Store it securely on your server and do not share it — not with your hosting provider, not with the CA, and not via email or any unencrypted channel.

⚠ Note: If your private key is ever exposed or compromised, the certificate must be revoked immediately. A compromised private key means a third party could impersonate your server. Contact GoGetSSL support to initiate revocation and reissuance as soon as possible.

Step 3 — Complete Domain Control Validation

Before the CA issues the certificate, you must prove that you control the domain. This is called Domain Control Validation (DCV) and is required for all certificate types. There are three common methods: adding a DNS record, uploading a verification file to your server, or responding to a validation email sent to an address at your domain.

OV and EV certificates require additional steps beyond DCV — the CA will also verify your organization's legal registration and contact details. For EV, the process includes further checks of authorized representatives and physical address. Full details on each validation type are covered in our Validation Guidelines.

Step 4 — Install the Certificate

Once the CA issues the certificate, you will receive the certificate file along with an intermediate CA bundle. Both must be installed on your server — the intermediate is required for browsers to complete chain validation. Missing the intermediate is the most common cause of trust errors after installation.

Installation steps vary by server platform. Our Installation Guides cover all major environments including Apache, Nginx, IIS, cPanel, and Plesk.

Fast Issuance within 3-5 minutes

Get a Domain Validation SSL certificate within just 5 minutes using our friendly and automated system. No paperwork or company required.

ACME SSLAutomation

Say goodbye to manual installations and the hassle of expiring certificates with our automated services. We offer a range of solutions designed to suit any environment

WHMCSReseller Plugin

We offer a professional WHMCS plugin to help you quickly and easily sell and resell SSL certificates. More details on our Partner program

Money Back 30-day guarantee

Customer satisfaction is our major concern. Get a full refund within 30 days for any purchase of SSL certificates with 100% guarantee.

Boost Validation

The Legal Entity Identifier (LEI) is a robust and modern way to verify and identify companies, helping to validate OV SSL certificates

Register LEI for $62.00

Help Center

Installation issues or SSL errors? Our Knowledgebase has clear, step-by-step guides to help you install, fix, and troubleshoot fast

Check Manuals

The trust that never expires

For 15+ years, we've delivered web security and trust services worldwide. See why customers keep choosing us. From startups to enterprises, we help businesses of all sizes stay secure and build trust with their audience.

Shopper Approved reviews for GoGetSSL