The TermsSSL Certificate service(‘Website Security’, ‘SSL Certificate’, ‘SSL Certification’) is a legal agreement between Pho Tue SoftWare And Technology Solutions Joint Stock Company (‘Pho Tue SoftWare Solutions JSC’, ‘HiTechCloud’, ‘we’) and each of our customers (‘you’, ‘Customer’) in connection with the use of the SSL digital certificate service.
We may amend these Terms of Service at any time. Except in urgent cases, we will notify you by email at least 10 working days before any amendment takes effect.
When using the SSL digital certificate service at Pho Tue SoftWare Solutions JSC, you must understand, agree to and accept the binding conditions of the following Agreement, together withthe General Provisionsabout the services at Pho Tue SoftWare Solutions JSC, including without limitation
1. Definitions and interpretation:
SSL (Secure Sockets Layer):This is a global technology security standard that creates an encrypted link between a web server and a browser. That link keeps all data exchanged between the web server and the browser private and secure.
CA (Certificate Authority):The organization that issues SSL certificates. SSL certificates from Pho Tue SoftWare Solutions JSC are issued by the certificate authorities GeoTrust, Comodo and Symantec.
Public Key:A public key used to verify identity information and encrypt files or data before they are transmitted over the internet.
Private Key:This is the private security key (also called the secret key), generated as part of creating the CSR. The private key pairs with the public key, using the same cryptographic algorithm, to decrypt data that the public key encrypted.
CSR (Certificate Signing Request):A CSR is an encoded block of text containing the details of the domain owner applying for an SSL certificate; it is generated in order to request issuance of the SSL certificate from a CA.
CRT (Certificate):It is a file containing an encrypted text string issued by the CA and sent to the domain holder registering the SSL certificate. The CRT encodes the SSL certificate based on the information declared and verified in the CSR. The CRT file is used to install SSL on a website's or email server.
Wildcard SSL:This type of certificate is for websites that need to cover multiple different subdomains. For example: forum.domain.tld, blog.domain.tld, shop.domain.tld, …
UCC/SAN SSL:This means purchasing additional domains to include in an SSL certificate. It also goes by other names: Unified Communication Certificate / Subject Alternative Name SSL, UCC SSL, SAN SSL, Multi-Domain SSL, UC Certificate, UC/SAN SSL or UCC/SAN SSL, SAN(s), SANs.
DV SSL (Domain Validation SSL):A domain-validated SSL certificate for individuals. DV SSL requires only proof of domain ownership.
OV SSL (Organization Validation SSL):An organization-validated SSL certificate for companies and organizations. OV SSL requires verification that the business or organization applying for the certificate is actively trading and owns the domain the certificate is for.
EV SSL (Extended Validation SSL):This is an extended validation SSL certificate that a CA verifies very thoroughly before issuing it to a business or organization. When visiting the website, users will see a small padlock icon in the browser's address bar; clicking it shows detailed information about the EV SSL certificate and the verified business behind it.
Email Approve:Also called the addressVerification email(or Approve mail). This is the email address of the person registering the SSL certificate, used to receive information from the CA and to confirm details when the CA requests them.
The approval email address must meet all of the following conditions:
- The approver email address must exist and be able to send and receive throughout the SSL certificate issuance process.
- The domain after the @ must be the domain for which the SSL certificate is being issued, and must be one of these five email addresses:
- admin@domain.tld (default – commonly used)administrator@domain.tldpostmaster@domain.tldhostmaster@domain.tldwebmaster@domain.tld
- Lưu ý: domain.tldis the domain for which you are requesting the SSL certificate. For example, if the website you want to secure is photuesoftware.com thì domain.tldyours will bephotuesoftware.com
2. General terms:
2.1.You must understand and agree that, before applying for an SSL certificate, you have already generated the CSR and the Private Key using information you declared clearly and accurately yourself. We only forward the CSR to the CA in order to submit the SSL registration request for you.
2.2.You must ensure that all information you declare when registering for an SSL digital certificate is complete and accurate as required by the CA. Pho Tue SoftWare Solutions JSC is not responsible for, and does not retain, any information you declared and provided in the CSR when registering for the SSL digital certificate.
2.3.The private key is critical: it decrypts transmitted data and is used to install SSL on your server once SSL certificate issuance is complete. Make sure you store your private key carefully. If you need to provide the private key to Pho Tue SoftWare Solutions JSC so that we can help install the SSL certificate on your website or email server, you understand and agree that Pho Tue SoftWare Solutions JSC does not retain your private key and accepts no responsibility for any matter relating to the security of your SSL information.
2.4.You must make sure you have an approver email address before you register an SSL certificate. You must keep monitoring that approver email address so you receive information from the CA and confirm all the information the CA sends you.
2.5.Pho Tue SoftWare Solutions JSC accepts no responsibility for any issue arising from errors or omissions in the information you declared before applying for an SSL certificate.
2.6.You must understand and agree that verification of information between you and the CA — including verification by approval email and by telephone, where applicable — takes place privately between you and the CA, with no involvement whatsoever from Pho Tue SoftWare Solutions JSC.
2.7.For OV SSL (Organization Validation SSL) or EV SSL (Extended Validation SSL) certificates that verify a Business/Organization, you must ensure that you have declared complete, accurate information matching the Business/Organization details registered on your business license, and that you have listed it on the following websites that record business information:
- For GeoTrust SSL and Symantec SSL: you must declare your business/organization information on thewww.yp.vn
- For Sectigo SSL: you must register your company or organization details with Dun & Bradstreet (D&B)www.upik.de
- Note: SSL issuers (CAs) look up and verify business/organization details against the information held on the business information websites listed above.
2.8.You must understand and agree that we are not responsible for how long it takes for an SSL certificate to be issued, because this depends on the verification of information between you and the SSL certificate authority (CA) and on the CA's working time zone.
2.9.All SSL Certificate plans includeGeoTrust SSL, Sectigo SSLandSymantec SSLat Mắt Bão are registered and issued with a maximum term of 1 year. When an SSL Certificate is close to expiry, the Pho Tue SoftWare Solutions JSC system will send you a notice torenewal registration(i.e. continuing to request the issuance of a new certificate).
Note:Because the certificate is issued entirely afresh, you need to re-activate the SSL service and then reinstall the certificate on the website or email server.
2.10.You must understand and agree that both Pho Tue SoftWare Solutions JSC and you are bound by all the rules and binding terms on SSL certificates set by the issuing certificate authority (CA), including without limitation.
3. Rights and responsibilities of the customer
3.1.Provide accurate details when generating the CSR, and supply a valid CSR when requesting an SSL certificate from Pho Tue Software Solutions JSC.
3.2.Provide accurate details when generating the CSR, and supply a valid CSR when requesting an SSL certificate from Pho Tue Software Solutions JSC.
3.4.Register the approval email address before sending the SSL issuance request to the CA.
3.3.Keep the CSR and private key safe for installation later.
Note:You do this at my.photuesoftware.vn
3.5.If the digital certificate being registered is an OV SSL (Organization Validation SSL) or EV SSL (Extended Validation SSL) package: you must declare the business/organization information exactly as that business/organization is registered on its business license, on the pageswww.yp.vnor the Dun & Bradstreet (D&B) pagewww.upik.de(as stated in clause 2.7).
3.6.Watch for the approval email so you can receive and confirm the details sent by the CA.
3.7.Verification by telephone (which may be conducted in English), where the SSL certificate authority (CA) calls to verify the business/organization details.
3.8.Once you receive the CRT file from the SSL issuer, you can install it on your own website or email server. If you need help from Pho Tue SoftWare Solutions JSC to install the SSL certificate on your website or email, you must provide all three files — a valid CRT, CA and private key — so that we can check them and complete the installation. We accept attachments for SSL installation requests only when they are sent through the Requests section at my.photuesoftware.vn
4. Rights and responsibilities of Pho Tue SoftWare Solutions JSC
4.1.Provide exactly the SSL certificate service the customer selected.
4.2.Full advice on features, usage conditions and SSL service pricing.
4.3.Tools to help customers generate a CSR and private key and check SSL details.
4.4.Guidance on the steps, the process, the points to note, … when registering and using an SSL certificate.
4.5.Assistance for customers in contacting the SSL provider (GeoTrust, Sectigo, Symantec, etc.).
4.6.Reissue (that is, revoke and re-register) the SSL certificate at the customer's request.
5. Install SSL certificate
Pho Tue SoftWare Solutions JSC installs SSL certificates free of charge in the following cases:
- The SSL certificate is registered with Pho Tue SoftWare Solutions JSC and is requested for installation on a website under the Cloud Hosting service at Pho Tue SoftWare Solutions JSC.
- The SSL certificate is registered with Pho Tue SoftWare Solutions JSC and is requested for installation on an email domain under the Email Pro service at Pho Tue SoftWare Solutions JSC.
- The SSL certificate is registered with Pho Tue SoftWare Solutions JSC and is requested for installation on a website under the Cloud Server service at Pho Tue SoftWare Solutions JSC.
- The SSL certificate is registered with Pho Tue SoftWare Solutions JSC and is requested for installation on a website running under a different Pho Tue SoftWare Solutions JSC service.
During SSL certificate installation, our technical team may contact you for additional information, account access or permissions needed to complete the work. You understand and agree that we are not liable for any risk relating to data, disclosure of information, passwords and the like, either during the work or after the SSL certificate installation you requested has been completed.
6. Outside the scope of support:
6.1.Creating the Approve email address on a third-party email system. Along with creating the Approve email address, if you use DNS for your domain at Pho Tue SoftWare Solutions JSC, we do not configure DNS to point to the Approve email server either. You must configure the DNS yourself, with the records and MX values required to reach that Approve email server.
6.2.We generate the CSR and private key on the customer's behalf. You can also generate them from a control panel, on your own server, or with a tool.
6.3.We cannot guarantee delivery or receipt of the approval email on the customer's own mail system.
6.4.The information the Customer declared when registering the SSL certificate cannot be modified.
6.5.We cannot notify or intervene in the verification process. Verification takes place privately between the CA and the party registering the SSL certificate.
Last updated: 22/01/2025