SSL Certificate

SSL/TLS Certificate Service Terms

PART I – CLASSIFICATION AND DESCRIPTION

Article 1. Types of SSL/TLS certificates

1.1. HiTechCloud provides and supports the following SSL/TLS certificate types:

(a) DV SSL (Domain Validation) — Domain validation:

– Verify domain ownership (via email/DNS/file);

– Issued within 5–30 minutes;

– Suited to: blogs, information websites and non-sensitive applications;

– For example: Let's Encrypt (free), Comodo PositiveSSL and AlphaSSL.

(b) OV SSL (Organization Validation) — Organization validation:

– Verify the company's business registration details;

– Issued within 1–3 business days;

  • Displays the organization name in the certificate details;
  • Suited to: corporate websites, B2B portals and applications handling sensitive information;
  • For example: DigiCert Standard SSL, Sectigo OV, Comodo OV.

(c) EV SSL (Extended Validation) — Extended validation:

  • The strictest verification process: checking the legal entity, registered address and authorized representative;
  • Issued within 3–7 business days;
  • The green address bar in the browser;
  • Required for: banking, finance, insurance, large e-commerce;
  • For example: DigiCert EV, Sectigo EV, GeoTrust EV.

(d) Wildcard SSL:

  • Protects the main domain and all first-level subdomains (*.example.com);
  • Available as DV Wildcard and OV Wildcard;
  • There is no EV wildcard (the CA/B Forum standard does not permit it).

(e) Multi-Domain SSL (SAN/UCC):

  • Protects multiple different domains and subdomains in one certificate;
  • Suited to: Microsoft Exchange, Lync/Skype for Business and multi-domain systems.

Article 2. Ordering and certificate issuance process

2.1. General process:

  • Step 1: The customer generates a CSR (certificate signing request), or asks HiTechCloud to generate one;
  • Step 2: Choose the SSL type and enter the required information (DV: domain only; OV/EV: organization details required);
  • Step 3: Complete the validation process (DV: by email/DNS/file; OV/EV: submit legal documentation);
  • Step 4: The certificate authority (CA) issues the certificate after verification;
  • Step 5: HiTechCloud sends the certificate by email and helps install it if needed.

2.2. Free SSL installation support for:

  • (a) Websites on HiTechCloud hosting (cPanel AutoSSL, automatic Let's Encrypt);
  • (b) Websites on common platforms: Nginx, Apache, IIS and LiteSpeed.

2.3. Consultation and SSL installation on complex systems (load balancer, CDN, Kubernetes) is charged as a service fee.

Article 3. SSL replacement and refund policy

3.1. SSL certificates are reissued free of charge in the following cases:

  • (a) The certificate is revoked because the private key was found to be compromised;
  • (b) You need to add a SAN domain to an existing multi-domain certificate;
  • (c) A technical error during issuance.

3.2. SSL certificates are non-refundable once the CA has successfully issued them, in line with CA/Browser Forum rules and the CA provider's policy.

3.3. Refund exception: if the Customer requests cancellation within 24 hours of placing the order but before the CA has issued the certificate, HiTechCloud will refund the amount paid less a processing fee of 50,000 VND.

Article 4. Certificate revocation

4.1. The certificate will be revoked immediately (as required by the CA/Browser Forum) when:

  • (a) The private key is exposed or stolen;
  • (b) The domain in the certificate is no longer owned by the Customer;
  • (c) The certificate was mis-issued (incorrect details or invalid validation);
  • (d) A request from a competent legal authority.

4.2. After revocation, HiTechCloud notifies you immediately and helps issue an emergency replacement certificate.

4.3. Revocation processing time: < 24 hours (per CA/B Forum Baseline Requirements section 4.9.1.1).

Article 5. Let’s Encrypt auto-renewal

5.1. Let’s Encrypt certificates (free) are renewed automatically every 60–90 days (30 days before expiry).

5.2. For auto-renewal to work, the Customer must:

  • (a) Keeping DNS pointed correctly at HiTechCloud servers;
  • (b) Do not block HTTP (port 80) access to the .well-known/acme-challenge/ directory;
  • (c) The server is not shut down or offline at the time of renewal.

5.3. HiTechCloud sends warning emails 30, 14 and 7 days ahead if auto-renewal has a problem.

Revision history

Current versionby HiTechCloud
Updatedby HiTechCloud
Updatedby HiTechCloud
Updatedby HiTechCloud
Monitored category: SSL CertificateGet notified when new documents are added to this category.

If this article did not answer your question, please contact HiTechCloud for help.

Contact