E-Mail Address Handling in SSL and S/MIME Certificate Orders

When processing SSL Certificate orders, it's crucial to distinguish between the purchaser (the person placing the order via our website or API) and the end user (the person or organization who will be using the SSL Certificate).

These are often different entities, especially in business scenarios where IT administrators order SSL Certificates on behalf of their organizations or clients.

The Purchaser vs End User Distinction

The e-mail address of the person submitting the order represents the purchaser - the person who placed the order, manages the account, and needs to receive all order-related communications. This is typically an IT administrator, web developer, or business owner who is responsible for obtaining and installing SSL Certificates.

An e-mail address associated with the end user represents the SSL Certificate subject - the person or organization whose information will be embedded within the SSL Certificate itself.

For SSL Certificates, this might be the technical contact at the organization.

For S/MIME Digital Certificates, this is the e-mail address that will be secured by the Digital Certificate.

How E-Mail Parameters Are Used

For each SSL Certificate order we generally set four critical e-mail parameters, each serving a specific purpose :

E-Mail Address - This parameter determines where we send the actual SSL Certificate once it's issued. We set this to the purchaser customer e-mail to ensure the purchaser receives the SSL Certificate they ordered. The purchaser is responsible for installing or distributing the SSL Certificate to the appropriate systems or users.

Representative E-Mail Address - This is used for all critical customer communications, including validation instructions for OV/EV SSL Certificates, account setup information, and any security warnings. We set this to the purchaser e-mail address because the purchaser needs to receive and act on these important notifications.

Contact E-Mail Address - This specifies the e-mail address that validation staff will use if they need to contact someone during order processing. We set this to the purchaser e-mail address to ensure any validation queries or issues are directed to the person who placed the order and has the context to respond.

Validation E-Mail Address - This parameter is used by the Certificate Authority (CA) to validate that the end user e-mail address is legitimate, but importantly, there are generally no e-mails sent to this address. Instead, we make contact with the most relevant person if an issue has arisen. We set this to the end user e-mail address - which has been provided by the purchaser via our order form.

S/MIME Specific Considerations

For S/MIME Digital Certificates, there are two additional parameters that specifically relate to the Digital Certificate content :

SAN E-Mail Address and S/MIME Subject E-Mail - These parameters determine what e-mail address is embedded in the S/MIME Digital Certificate Subject Alternative Name field.

This must be the end user e-mail address (the one that will use the Digital Certificate for e-mail encryption and signing), not the purchaser e-mail address. We set both of these to the end user e-mail address from the order form.

Why This Separation Matters

This separation ensures that SSL Certificate delivery and management communications go to the right person - the purchaser who has the technical knowledge and access to handle them.

Meanwhile, the end user information is correctly embedded in the SSL Certificate for validation and usage purposes. This is particularly important in enterprise environments where a single administrator might order dozens of SSL Certificates for different end users across their organization.

Summary

In essence, all operational communications and the SSL Certificate itself are sent to the purchaser, while the end user e-mail address is used only for validation purposes and as the subject of the SSL Certificate.

This ensures smooth order processing while maintaining the correct SSL Certificate ownership and usage rights.

Most Popular Questions

Understand how Trustico® handles different e-mail addresses in SSL Certificate and S/MIME Digital Certificate orders, distinguishing between purchaser and end user roles.

What Distinguishes the Purchaser and End User When Ordering an SSL Certificate?

The purchaser is the person placing the order who manages the account and receives all order-related communications, typically an IT administrator or developer. The end user is the person or organization whose information is embedded within the SSL Certificate itself and who will actually use it.

Where Does Trustico® Send the SSL Certificate Once Issued?

Trustico® sends the issued SSL Certificate to the purchaser e-mail address provided during checkout. The purchaser is then responsible for installing or distributing the SSL Certificate to the appropriate systems or end users.

Why Does Trustico® Need Different e-mail Addresses for SSL Certificate Orders?

Different e-mail addresses serve specific purposes: the purchaser e-mail receives the SSL Certificate and all operational communications, while the end user e-mail is used for validation purposes and is embedded in the SSL Certificate subject. This separation ensures communications reach the right person while maintaining correct SSL Certificate ownership.

How Are e-mail Addresses Handled Differently for S/MIME Digital Certificates?

For S/MIME Digital Certificates, the end user e-mail address is embedded in the Subject Alternative Name field of the Digital Certificate. This must be the actual e-mail address that will use the Digital Certificate for encryption and signing, while the purchaser still receives all order communications.

Will the End User Receive e-mails During the SSL Certificate Ordering Process?

Generally, no e-mails are sent to the end user e-mail address during processing. The validation e-mail address is recorded for Certificate Authority validation purposes, but Trustico® directs all communications including validation queries to the purchaser who has the context to respond.

Can SSL Certificates Be Ordered for Clients and Organizations?

Yes, the Trustico® ordering system supports this common scenario. As the purchaser, you receive all SSL Certificate deliveries and management communications, while your clients or organization members are correctly listed as end users in the SSL Certificates themselves.

Ask Trustico® Assistant

For Instant Answers - Start Here When You Have a Question or Need Help

Website Security Checks : Essential Steps to Protect Your Business Online

Website Security Checks : Essential Steps to Pr...

Keep your website secure with the SSL Certificate checks that matter most, from expiry and chain coverage to validation levels, issuance controls, and automation.

Website Security Checks : Essential Steps to Pr...

Keep your website secure with the SSL Certificate checks that matter most, from expiry and chain coverage to validation levels, issuance controls, and automation.

Installing an S/MIME E-Mail Certificate in Mozilla Thunderbird

Installing an S/MIME E-Mail Certificate in Mozi...

Import a PKCS12 E-Mail Certificate into Mozilla Thunderbird, assign it for signing and encryption, and exchange secured messages with any recipient.

Installing an S/MIME E-Mail Certificate in Mozi...

Import a PKCS12 E-Mail Certificate into Mozilla Thunderbird, assign it for signing and encryption, and exchange secured messages with any recipient.

Repackaging a PKCS12 File for macOS Keychain Compatibility

Repackaging a PKCS12 File for macOS Keychain Co...

Fix PKCS12 imports that macOS Keychain Access rejects despite a correct password by re-exporting the file with legacy compatible encryption.

Repackaging a PKCS12 File for macOS Keychain Co...

Fix PKCS12 imports that macOS Keychain Access rejects despite a correct password by re-exporting the file with legacy compatible encryption.

Fixing the IIS Binding Error - A Specified Logon Session Does Not Exist

Fixing the IIS Binding Error - A Specified Logo...

Resolve the IIS binding error stating a specified logon session does not exist by repairing the Private Key association or reimporting correctly.

Fixing the IIS Binding Error - A Specified Logo...

Resolve the IIS binding error stating a specified logon session does not exist by repairing the Private Key association or reimporting correctly.

Converting a Java Keystore to PKCS12 Format

Converting a Java Keystore to PKCS12 Format

Convert a legacy Java KeyStore (JKS) to PKCS12 with one keytool command, verify the contents, and extract PEM files for non-Java platforms when needed.

Converting a Java Keystore to PKCS12 Format

Convert a legacy Java KeyStore (JKS) to PKCS12 with one keytool command, verify the contents, and extract PEM files for non-Java platforms when needed.

The 64 Character Limit on the Common Name Field

The 64 Character Limit on the Common Name Field

Understand the 64 character limit on the Common Name (CN) field, why long hostnames fail at CSR generation, and how Subject Alternative Names solve it.

The 64 Character Limit on the Common Name Field

Understand the 64 character limit on the Common Name (CN) field, why long hostnames fail at CSR generation, and how Subject Alternative Names solve it.

1 / 6