Overview
This article explains how to link your UltraDNS account to DigiCert CertCentral for automated Domain Control Validation (DCV). DCV confirms control of a domain before a certificate can be issued.
The integration allows CertCentral to manage the DNS TXT records required for validation. After linking the accounts, you must make the required domains visible to CertCentral and import them into CertCentral to start automated validation.
When to Use This Article
- You want to connect UltraDNS to an existing CertCentral account.
- You want CertCentral to automate DNS-based domain validation.
- You need to reset or remove an existing connection.
Before You Begin
- You need an UltraDNS account and a DigiCert CertCentral account.
- Your UltraDNS user must have permission to manage account connections.
- A CertCentral administrator must complete the CertCentral portion of the setup.
- The
DigiCert CertCentral Connectionfeature must be available in UltraDNS, andIntegrate with UltraDNSmust be enabled in CertCentral. - Domains used for this automated validation workflow must be delegated to UltraDNS authoritative name servers.
If the connection option is not visible in UltraDNS, contact UltraDNS Support and provide your DigiCert CertCentral Account ID.
If Integrate with UltraDNS is missing from the Automation menu in CertCentral, contact your account manager or DigiCert Support to enable the feature.
CertCentral can connect to one UltraDNS account at a time. Connecting a different UltraDNS account disconnects the existing account and disables automated validation for domains linked to that account.
Start the Connection in UltraDNS
- Sign in to the UltraDNS portal.
- Select
Accounts, select your account, and openAccount Info. - Locate
DigiCert CertCentral Connectionand clickLink. - In the connection window, use
Click to Copyto copy the displayedAccount IDandSecret key. Store both values securely. - Click
Ok, savedafter saving the connection details.
The Secret key is entered as the API secret in CertCentral. The secret is displayed only once and cannot be retrieved later. Generating a replacement secret invalidates the previous secret.
If another administrator will complete the CertCentral setup, securely provide that administrator with the connection details.
Complete the Connection in CertCentral
- Sign in to CertCentral as an administrator.
- Go to
Automation > Integrate with UltraDNS. - Under
Link account, enter the connection details copied from UltraDNS intoUltraDNS Account IDandAPI secret. - Select
Link. - Return to
DigiCert CertCentral Connectionin UltraDNS and check the connection status. The UltraDNS Managed Services Portal User Guide describes the status changing fromPendingtoEstablishedwhen the connection is complete.
Make Domains Available for Automated Validation
An established account connection does not confirm that a domain has completed validation. Domain visibility and import are separate setup steps.
- In UltraDNS, select
Domains. - Locate the domain and turn
Visible to CertCentralOn. - Follow DigiCert's Import domains and automate domain validation instructions to import the domain into CertCentral and assign it to an organization.
DigiCert recommends testing with one domain before importing multiple domains.
To make multiple domains visible in UltraDNS, select the domains, open the Visible to CertCentral menu, and select Enable Visibility.
Expected Outcome
The accounts are connected, and the domains you import into CertCentral are submitted for DNS TXT record validation. Review the domain validation status in CertCentral to confirm the result.
DigiCert documents the first automated validation run at the top of the hour after import. This schedule is not a guarantee that validation will complete within one hour of linking the accounts.
Reset the Connection
Use Reset when you need a replacement Secret key. Resetting temporarily suspends the connection.
- In UltraDNS, open
Accounts > Account Name > Account Info. - In
DigiCert CertCentral Connection, clickResetand securely save the new connection details. - In CertCentral, go to
Automation > Integrate with UltraDNS. - Under
Link account, enter the new value inAPI secretand selectLink.
The new secret must be entered in CertCentral to reactivate the connection. See DigiCert's API secret update instructions for the complete workflow.
Remove the Connection
In the UltraDNS DigiCert CertCentral Connection section, click Unlink to remove the connection. This stops CertCentral from automatically managing domain validation through that connection.
To use the integration again, reestablish the connection and designate the domains again in CertCentral.
Important Notes
-
Visible to CertCentralremains disabled until the UltraDNS account is linked to CertCentral. - If you have access to multiple UltraDNS accounts, each domain must belong to an account linked to CertCentral before you enable its visibility.
- Manually created
_dnsauthTXT records can block automated validation. The automation does not delete user-generated_dnsauthTXT records. - Domains using legacy Static Signing cannot be made visible to CertCentral. Review the UltraDNS Visible to CertCentral documentation if this limitation applies.