Through the Incommon Certificate Service, the University can provide free Secure Sockets Layer (SSL) certificates for any domain name (including non ".edu" domains) controlled by a University entity (division, department, school, lab, etc.). The prerequisite is that the domain must pass an industry-standard process known as Domain Control Validation (DCV). Before any SSL certificate can be issued by Comodo (the Certificate Authority) to a University entity, it must demonstrate the domain name is affiliated with the University and under the University entity's administrative control. This is a common-sense precaution to prevent misuse of certificates by third parties. DCV must be completed prior to issuing a certificate for a new domain and then annually.
This requirement affects:
The process can be completed using any one of three supported methods:
InCommon Certificate Manager provides documentation detailing all of these methods.
If you would like to add a new domain to the InCommon system so that SSL certificates can be provided for you, please note that DCV requires participation of the domain administrator and the campus Registration Authority Officers (Information Security).
Step 1: Verify that the Registrant Name listed in Whois Lookup demonstrates an affiliation with the University of Chicago. Note in particular that domains protected by registration privacy services will be denied.
Step 2: Please initiate the DCV process by emailing certs@uchicago.edu the following information:
Step 3: IT Services will request the domain be validated by InCommon, who will check the whois contact (Step 1) and then allow IT Services to proceed with the DCV method of choice (Step 2).
Step 4: IT Services will email instructions to the DCV requester on how to complete the Email, DNS, or HTTP step. Follow those instructions and reply when ready. IT Services will contact the Certificate Authority and finish the validation process. Once it is complete, you will receive an automated email from cert-manager.com. After you receive that email, you can request certificates for the newly validated domain.
This is a multi-step process. Allow at least five business days for IT Services to handle the administrative aspects of your request (requesting DCV and delegating the approved domain). Any delay by the domain administrator in handling their part in the DCV process will add to that time.
If you have any questions about the process, please email certs@uchicago.edu.