Overview
This internal article explains how to assist customers with linking an UltraDNS account to DigiCert CertCentral for automated Domain Control Validation (DCV). DCV is the process used to confirm control of a domain for certificate issuance.
Setup includes enabling the integration, linking the accounts, and selecting which domains CertCentral can manage. The account connection must be completed in CertCentral after the connection details are generated in UltraDNS.
When to Use This Article
- A customer wants to connect UltraDNS to CertCentral.
- A customer needs to enable automated validation for selected domains.
- A customer needs to reset or unlink an existing connection.
- Support needs to investigate a connection or validation issue.
Before You Begin
- The integration feature must be enabled on both the UltraDNS and CertCentral accounts before the accounts can be linked.
- The UltraDNS user must have administrative permissions. The source procedure identifies the primary account user or a user in the
ADMINISTRATIVEgroup. - Someone with administrative access to CertCentral must complete the CertCentral portion of the connection.
- The Account ID and Secret must be copied and stored securely when displayed. The connection window states that these details cannot be retrieved after leaving the window.
Internal confirmation is required for the feature-enablement procedure. The source article states both that Support enables Cert Central DCV in UltraAdmin and that the feature cannot be viewed or enabled in UltraAdmin and requires a CST ticket. These instructions conflict. Confirm the supported procedure before advising an agent how to enable the feature.
Link the Accounts
- Sign in to the UltraDNS Managed Services Portal using an account with administrative permissions.
- Go to
Accounts> select the account >Account Info>DigiCert CertCentral Connection. - Click
Link. - Review the
Important: Save Your Account and Secretmessage and proceed to the connection details. - Use
Click to Copyto copy the Account ID and Secret. Store both values securely before leaving the window. - Click
Ok, saved. - If another administrator manages CertCentral, securely provide that administrator with the Account ID and Secret.
- Complete the connection in CertCentral. Refer to the DigiCert CertCentral documentation for supporting product guidance.
The supplied UltraDNS Managed Services Portal User Guide states that the connection status changes from Pending to Established when the connection is completed.
If DigiCert CertCentral Connection is missing, check the user's administrative permissions and whether the feature is enabled for the account.
Enable Domain Visibility
After linking the accounts, use Visible to CertCentral to select which domains CertCentral can automatically manage validations for.
- For an individual domain, set its
Visible to CertCentralselector toOn. - For multiple domains, select the domains and click
Enable Visibility.
The selector remains disabled and off by default until the account is linked to CertCentral.
If a user has access to multiple UltraDNS accounts, enabling visibility for a domain in an account that is not linked to CertCentral returns an error.
Verify the Setup
- Check that the UltraDNS connection status is
Established. - Check that
Visible to CertCentralisOnfor each intended domain. - Check the domain's validation status in CertCentral.
Account connection and domain validation are separate checks. Verify both before reporting that setup and validation are complete.
The source article states that validation can take up to one hour after setup is completed in both products. The supplied portal guide does not confirm that timeframe. Obtain SME confirmation before presenting it as a current expected completion time.
Investigate Validation Issues
The source article identifies the following conditions that can interfere with automated validation:
- The domain is not delegated to UltraDNS, which can cause DCV validation to fail.
- A manually created
_dnsauthTXT record can block automation from creating the required system record.
Check the domain's delegation and any existing _dnsauth TXT records when investigating a validation failure. The presence of either condition alone does not establish the cause of a specific failure.
The source article records the following audit observations:
- TXT record additions and deletions appear in the API/UI audit log.
- The user
ultradns_systemcreates a TXT record withownerNameset to_dnsauth.{zoneName}. - A login to
ultradns_system_CERTCENTRAL_DCVwas observed before record creation.
Review the audit entries for the affected domain to identify recorded creation or deletion activity. These observations do not establish the complete revalidation lifecycle.
Reset the Connection
Clicking Reset temporarily suspends the connection and generates a new Secret.
- In
DigiCert CertCentral Connection, clickReset. - Copy and securely store the Account and Secret values displayed in the connection window.
- Click
Ok, saved. - Enter the new Secret in CertCentral to reactivate the connection.
- Check that the connection is established.
Unlink the Connection
Clicking Unlink disconnects UltraDNS from CertCentral and prevents CertCentral from automating management of the designated domains through that connection.
To resume automated management, the connection must be reestablished and the domains must be designated again in CertCentral.
Internal Technical Notes
The source article states that DigiCert uses an API call to create the validation TXT record and that access control list (ACL) restrictions on the UltraDNS side limit the integration endpoint to DigiCert.
The source does not identify the endpoint or explain how those restrictions are implemented. Do not identify a standard TXT record endpoint as the integration endpoint without confirmation.
The source also refers to a security-information PDF, but does not provide its title or location. Confirm the document before using it to answer security questions.