Note: |
By July 17, 2026, InCommon will transition its Certificate Authority services from Sectigo to CERTInext. Teams that rely on manual certificate requests or renewals must review upcoming expirations and plan the move now. Beginning March 15, 2026, publicly trusted SSL/TLS certificates are capped at 200 days, decreasing to 47 days by March 2029. Teams using manual requests or renewals should review upcoming expirations and reach out to the UISO to discuss automation options where possible. For more information, please contact the University Information Security Office (UISO) via the UISO / UIPO Intake Form and navigate to “General Inquiries > IU Certificate Authority > Get Help.” |
Certificates
Indiana University is partnered with the InCommon Certificate Service to provide unlimited free V2 X.509 certificates to IU units for SSL/TLS web servers, code signing, and client or personal use with other services.
InCommon has introduced a new V2 certificate as a new intermediate certificate between InCommon and their partner company CERTInext. The process will remain essentially unaffected for users requesting new V2 certificates.
You can request a certificate using the CERTInext New Request page.
When asked to Choose Product & Validity, select the following:
- For the “Group” field, select "Indiana University"
- For the "CA Source" field, select "emSign"
All IU domain names are eligible for certificates, including
- iu.edu
- bloomington.iu.edu
- columbus.iu.edu
- east.iu.edu
- indianapolis.iu.edu
- kokomo.iu.edu
- northwest.iu.edu
- southbend.iu.edu
- southeast.iu.edu
Non-IU domains are also supported as long as IU hosts the domain. Requests for certificates for these domains are subject to extra vetting and approval, by both the university and InCommon.
To request a certificate for a non-IU domain, contact the UISO through the UISO / UIPO Intake Form and select “General Inquiries > IU Certificate Authority > Get Help.” Specify the domain you want a certificate for, and the UISO will initiate the process of validating it with InCommon. After the domain is validated, you can then request a certificate for a host in that domain using the Certificate Manager mentioned above.
The InCommon Certificate Service doesn't offer certificate renewal; you must instead request a new certificate. See the "Requesting a certificate" fold above.
You can re-download a previously created key using the CERTInext Orders page. Select the box to the left of the certificate(s) you wish to download, then select "Downlad all certificates."
You can also select the View option to the right of the certificate you wish to download, then select the three dots on the top right to open an option menu. From there, select "Download certificate."
You can revoke a certificate using the CERTInext Orders page. Select the box to the left of the certificate(s) you wish to download, then select "Revoke certificates."
You can also select the View option to the right of the certificate you wish to download, then select the three dots on the top right to open an option menu. From there, select "Revoke certificate."
Technical support and troubleshooting help for InCommon certificates are available through InCommon. See their Support Information page for options.
You can also access CERTInext documentation here: https://docs.certinext.io/
If the Certificate Manager says it's "Unable to Read the CSR" when you request a certificate, it's likely you generated your request using keys with fewer than 2,048 bits. Try regenerating your keys and your request using 2,048-bit keys.
For legal reasons, the organization name found on the EV certificate (displayed in the green browser indicator) must be the organization's full legal name, as listed in official records. For IU (or any of IU's domains), this is: "Indiana University" (as displayed above). Unfortunately, certificate authorities are unable to issue EV certificates bearing any other name—including those of a department, office, or service.
Multi-domain certificates (MDCs) are offered through this service. MDCs support up to 100 fully qualified domain names (FQDNs) or host names.
Wildcard certificates, when compromised by attackers, have the potential to be far more damaging to IU than standard certificates since they could be used to impersonate any FQDN in the domain of the wildcard, rather than just specific FQDNs to which standard certificates are issued. Placing copies of the wildcard certificates and their accompanying keypairs on multiple machines also increases the attack surface of the certificates. For this reason, wildcard certs
- cannot be used for one of IU's TLDs.
- must be limited to a period of 1 year.
- must be recreated with new keypairs, not renewed.
- may only be used when more than 100 FQDNs are involved. (If fewer than 100 FQDNs are needed, request a a Multi-Domain SSL certificate instead.)
Exceptions to these restrictions require approval by the University Information Security Officer, who will ask the request the following:
- What host-level measures exist on the servers containing the private key for the wildcard certificate?
- What network-level measures protect these servers?
- Where else will the private key be stored?
- What people will have access to the private key?
- What is your response procedure in case the private key is compromised?
- How many FQDNs do you need the certificate to be valid for? What are they?
- How many servers do you plan on putting the wildcard certificate on?
- Where are these servers physically located?
If you have been approved to use a wildcard certificate, the UISO recommends the following best practices:
Develop a response procedure to respond to a compromise of the private key.
Deploy the private key only where needed (e.g. not to every server you run, only those that need it, etc).
Limit access to the certificate to only those staff who need it.
Leverage the IU Data Centers to enhance physical security.
Client and code-signing certificates are no longer offered as part of IU’s agreement with InCommon.
NOTE: Due to enhanced security features in Exchange Online, you should no longer use digital signatures at IU. Follow the appropriate instructions to disable your certificates.
By July 17, 2026, InCommon will transition its Certificate Authority services from Sectigo to CERTInext. The steps below will no longer apply to requesting an extended validation certificate.
Extended validation (EV) certificates are also available through this service by selecting "EV Certificate" on the Certificate Manager site. These certificates require more behind-the-scenes work to verify the identity of the requesting institution.
The process for obtaining an EV certificate is significantly longer, so please plan ahead.
- Start by requesting an EV cert through the normal means. Record your order number; you'll need it later.
- Download and complete the IU-Sectigo EV Certificate Request Form. (Sectigo Group is the certifying authority for InCommon certificates.) Complete only the Certificate Requester section, found on Page 2.
- Send the completed form to Sectigo via email [docs@sectigo.com] or fax [1-866-446-7704]. You must include your order number, either in the body of the email or a fax cover sheet.
