Adding or Dropping Subject Alternative Names from UCC Certificates

 

After your Multiple Domain (UCC) SSL certificate is issued, you can add or remove Subject Alternative Names (SANs) at any time. SANs are the additional, non-primary domain names secured by your UCC SSL certificate. However, keep in mind:

  • Changing your SANs generates a new certificate, which you must install on your server.
  • Your old certificate only remains valid for 72 hours.

To Add or Remove Subject Alternative Names

  1. Log in to your Account Manager.
  2. Click SSL Certificates.
  3. Next to the certificate you want to manage, click Launch.
  4. From the Filters list, click Certificates.
  5. Click the UCC certificate you want to manage.
  6. Click Manage.
  7. Do one of the following:
    • To add a SAN: In the New Subject Alt Name field, enter a new Subject Alt Name and click Add.

      NOTE: SANs do not need to be fully qualified domain names. For example, if you are using cool or example for your intranet and want to secure it, you can use those network names as SANs. However, you need to know how your server is configured to properly secure them.

    • To remove a SAN: Click the X next to SAN you want to remove.

      NOTE: After any SAN change, download the new certificate and install it on your server. When you delete a SAN, the new certificate is available in minutes. When you add a SAN, it must be vetted. You’ll receive an email after vetting is complete. For more information, see Downloading an SSL Certificate.

  8. Click Manage.

This generates a new certificate that you must install on your server. Your old certificate only remains valid for 72 hours. After that, your websites using the old certificate will begin generating errors.

For installation instructions based on your server see Installing an SSL: Server Instructions.

For Exchange or IIS servers, you must generate a new CSR, and then use it to re-key your UCC certificate (more info). Finally, install the certificate as if it were new.

Installing on Multiple Servers

If you want to install the UCC on multiple servers, export the private key from the original server and import it on the additional servers you want to secure. Then, install the UCC on the new servers.

If you need further information regarding the replacement of an existing certificate or the import/export of a private key, contact the manufacturer of your hosting server software.

*Information provided courtesy of GD Support*