Sectigo® CaaS DV + Multi Domain is a multi-domain SSL Certificate delivered through Trustico® Certificate as a Service (CaaS). It secures a primary domain along with a group of additional names held together as Subject Alternative Names (SANs), all on one SSL Certificate.
The SSL Certificate is issued and reissued automatically through the Automatic Certificate Management Environment (ACME) protocol, which pairs the trust of a long-established Certificate Authority (CA) with programmatic management. Coverage runs from a few names to hundreds, with more available as additional Subject Alternative Names (SANs) when you need them.
It suits a business running several websites, a set of brand or regional domains, and teams that provision and retire names through automation rather than by hand.
The sections below explain what the SSL Certificate covers, how the automation works, and how to put it in place.
Sectigo® Trust Across Your Domains
Sectigo® is a long-established, widely trusted commercial Certificate Authority (CA), with root Certificates present in virtually every browser, operating system, and device. Each name on your SSL Certificate inherits that trust, so visitors reach every secured site over a connection their browser already recognizes.
This matters when you present several brands or regional sites to the public, since each name is trusted without any configuration on the visitor's device. Learn About the Sectigo® Certificate Authority (CA) 🔗
Multiple Names on One Automated SSL Certificate
A multi-domain SSL Certificate holds several separate names on one SSL Certificate through Subject Alternative Names (SANs). Those names can be different domains, such as example.com, example.net, and another-brand.com, along with subdomains, all covered by a single SSL Certificate.
Coverage runs from a few names to hundreds, and further names can be added as additional Subject Alternative Names (SANs) when the need arises. One SSL Certificate and one automated lifecycle then cover the whole group. Explore Multi Domain Coverage 🔗
The Case for Certificate as a Service (CaaS) with Multiple Domains
Managing a multi-domain SSL Certificate by hand grows more awkward as the list of names changes. Each time it nears expiry, someone generates a Certificate Signing Request (CSR), completes validation for every name, downloads the files, and installs them on each server. Certificate as a Service (CaaS) automates all of that.
Note : Where no Automatic Certificate Management Environment (ACME) client can be run, the same SSL Certificate can be issued from your Certificate as a Service (CaaS) license in a browser using the hosted tool. Explore the Hosted Issuance Tool 🔗
When you order Sectigo® CaaS DV + Multi Domain, you are buying an SSL Certificate license for a set period. Through that period your ACME client reissues the SSL Certificate as it approaches expiry, so every name stays protected for the term.
When the license nears its end, you can extend it without reinstalling or reconfiguring anything across your servers. The extended validity is recognized automatically, with no change to your External Account Binding (EAB) credentials or your automation. Learn About License Extensions 🔗
Multi Domain Validation with ACME
Sectigo® CaaS DV + Multi Domain uses the Automatic Certificate Management Environment (ACME) protocol, defined in RFC 8555, to run the SSL Certificate lifecycle. An ACME client on your server handles verification, issuance, installation, and reissue for every name on the SSL Certificate.
Each name is validated on its own. Domain Validation (DV) confirms control of that name, with no organization checks, so the SSL Certificate issues quickly once every name is confirmed. Names on different servers or run by different teams are validated independently.
For each name the client answers a challenge automatically, either by serving a token over HTTP or by publishing a Domain Name System (DNS) TXT record. Many clients complete the Domain Name System (DNS) method through integrations with major providers such as Cloudflare, AWS Route 53, and DigitalOcean.
Because a name can be confirmed over Domain Name System (DNS), coverage extends to sites behind a firewall or on internal networks that are not publicly reachable. Once control is confirmed, the SSL Certificate is issued, and every later reissue runs the same way. Explore ACME Protocol Details 🔗
Supported ACME Clients
Any major Automatic Certificate Management Environment (ACME) client works with Sectigo® CaaS DV + Multi Domain. Certbot is the most widely used and handles multiple names on one request. acme.sh suits scripted, scheduled reissue and offers a wide range of provider integrations.
For Kubernetes, cert-manager issues and reissues the SSL Certificate as a native cluster resource. Windows environments are covered by win-acme and Certify The Web for Microsoft Internet Information Services (IIS), while lego, dehydrated, and Posh-ACME cover Go, shell, and PowerShell setups.
Whichever client you choose, it authenticates with the Certificate Authority (CA) through the same External Account Binding (EAB) process and validates each name before the SSL Certificate is issued. Find Out More About Supported ACME Clients 🔗
Tip : If your sites run on cPanel, the Trustico® Certificate as a Service (CaaS) cPanel plugin brings automated SSL Certificate management into your hosting control panel, without the command line. It retrieves, installs, and reissues your SSL Certificates from within cPanel. Explore the Trustico® cPanel Plugin 🔗
On cPanel hosting the plugin fills the role of the ACME client, requesting and reissuing the SSL Certificate for the names you manage on that server.
External Account Binding Credentials
External Account Binding (EAB) links your ACME client to the Certificate Authority (CA). Trustico® creates a Key Identifier and an HMAC Key and sends them to you via e-mail after purchase, and they are also available in your ordering account for a limited time. You provide them when you first set up the client to authorize it.
You can generate separate External Account Binding (EAB) credentials for different servers or environments, which helps where the same group of names is managed by more than one client across production, staging, and development. View Our EAB Credential Setup Guide 🔗
Encryption and Protocols
Protection is built on a 2048-bit RSA key with 256-bit symmetric encryption, applied consistently to every name, over the Transport Layer Security (TLS) 1.2 and 1.3 protocols with SHA-256 hashing.
Certificate Transparency logging adds accountability, and Elliptic Curve Cryptography (ECC) keys are supported for environments that benefit from smaller keys and faster handshakes. Compare Encryption Standards 🔗
Preparing for Shorter Validity Periods
Industry rules are reducing the maximum validity of an individual SSL Certificate to 200 days from March 2026, 100 days from March 2027, and 47 days from March 2029. These reductions apply to every publicly trusted Certificate Authority (CA), Sectigo® included.
At a 47 day cycle, a multi-domain SSL Certificate covering many names across several servers would need reissuing roughly eight times a year. With Certificate as a Service (CaaS), your ACME client handles each reissue quietly, so every name stays protected whatever the validity period. Explore Traditional and Certificate as a Service (CaaS) Compared 🔗
USD $500,000 Warranty
Every Sectigo® CaaS DV + Multi Domain SSL Certificate carries a USD $500,000 Relying Party Warranty covering the secured names, which provides financial cover in the unlikely event that the Certificate Authority (CA) issues the SSL Certificate in error. Reissues are unlimited across the license through the automation. Review Warranty Details 🔗
Sectigo® Site Seal
Your order includes a Sectigo® site seal that you can display across your secured sites to reassure visitors. The Sectigo® name on the seal is one that visitors and businesses already recognize. Implement Trust Seals 🔗
Browser Compatibility
Because the Sectigo® roots are in virtually every trust store, each secured name is trusted by around 99.9% of web browsers, including Chrome, Firefox, Safari, and Edge, and by mobile devices on iOS and Android without any additional configuration. Understand Browser Compatibility 🔗
Unlimited Server Licenses
You can install the SSL Certificate on as many servers as you need at no extra cost. This matters when your names run on separate infrastructure, across web servers, application servers, load balancers, and container nodes.
The same SSL Certificate and key file are deployed to each server that serves a secured name, and where a server needs its own key you can reissue as often as required through the automation.
Programmatic Installation
The ACME client installs the SSL Certificate for you, generating the Certificate Signing Request (CSR), validating each name, and deploying the issued files. Documentation covers Apache, Nginx, Microsoft Internet Information Services (IIS), cloud platforms, and container systems. Access Installation Guides 🔗
Guides and Resources
Trustico® provides guides covering ACME client setup, Domain Name System (DNS) validation, External Account Binding (EAB) credentials, and multi-domain deployment. For reissue scheduling specific to your client, refer also to that client's own documentation. Browse Technical Resources 🔗
Who Should Use Sectigo® CaaS DV + Multi Domain
It fits a business that keeps several websites or a group of regional and brand domains together on one SSL Certificate, provisioned through infrastructure as code with tools such as Terraform, Ansible, and CloudFormation.
It also suits agencies and hosting providers securing many client domains under a single automated SSL Certificate, and continuous integration pipelines that create and retire named environments as work moves through them. Learn About the Partner Service 🔗
Other Options
If you do not need programmatic automation and would rather manage a multi-domain SSL Certificate by hand, the standard Domain Validation option covers the same names. Compare Sectigo® DV + Multi Domain 🔗
Where you also need to secure every subdomain under a domain at the wildcard position alongside these named sites, a combined wildcard and multi-domain option is available in the same automated range. Explore Certificate as a Service (CaaS) 🔗