Ribbon Icon Celebrating 27 Years – Announcing the new GeoTrust Horizon® platform. Learn More
Home Icon > Resources > Expert Guides > Beginner’s Guide to SSL/TLS > How to Get an SSL Certificate for My Website

How to Get an SSL Certificate for My Website

If you have a website, you need an SSL (TLS) certificate. Without one, your user’s data will be unprotected as it travels across the internet.

how-to-upload-an-ssl-certificate-to-website/

Ready to learn how to get a security certificate for your website? Then start the clock — we’ve got 60 seconds to break it all down.

How to Get a Server Security Certificate for My Website (9 Steps)

Getting an SSL/TLS certificate is something that can be done relatively quickly:

1. Choose Your Certificate

For obvious reasons, we recommend that you purchase an SSL/TLS certificate from GeoTrust, which has been a trusted industry name for 25+ years.

Automate Your SSL Certificate in 5 Minutes

Keep your website secure and online… no manual certificate renewals needed!

2. Complete a Certificate Signing Request (CSR)

You can generate a CSR on your server command line or via a management tool such as cPanel.

A snippet from cPanel that shows where to find the option to generate a certificate signing request (CSR)
Image caption: An example of where to find the CSR generator tool in cPanel.

Information you’ll provide as part of your certificate signing request includes:

  • Fully qualified domain name (or a wildcard domain for wildcard SSL certificates)
  • Organizational details
  • Site admin and technical contacts
  • Preferred method of domain control validation

This information, along with other data, will be used by the CA to validate your domain and organization. 

3. Save the Private Key (Do It Now, as You Can’t Access It Later!)

Once you’ve completed the CSR, you’ll need to save the private key that’s generated to a safe location. Be sure you know where a copy is saved, the CA won’t be able to provide you with a copy later. (This means you’ll have to generate and submit a new CSR and have a new certificate issued.)

An example of a fake SSL/TLS certificate CSR file
Image caption: A redacted example of SSL/TLS certificate private key data.

4. Submit the CSR to Your Certificate Provider

For GeoTrust customers who purchase certificates through our website, you can easily submit your CSR through your GeoTrust Horizon account dashboard.

Your CSR will look akin to the following (be sure to save everything between and including the —– BEGIN CERTIFICATE REQUEST —– and —– END CERTIFICATE REQUEST —– tags):

A phony example of an SSL/TLS certificate's fake secret (private) key.
Image caption: A redacted example of a certificate signing request.

Before completing your CSR submission, you also must provide contact details for your domain’s administrator (e.g., the admin’s name, email address, and phone number). You may be asked to provide additional information if you’ve purchased an SSL/TLS certificate with a higher level of business validation (more on that in step 6).

5. Complete the Domain Control Validation (DCV) Process

Depending on which type of SSL/TLS certificate you get, there are up to three domain validation methods you can choose from:

  1. Email-based validation
  2. HTTP file-based validation (not available for wildcard certificates)
  3. CNAME DNS record-based validation
You can download your CA authentication file and find instructions on where to place it in your domain's hierarchy in GeoTrust.
Image caption: A redacted example of the validation steps you’ll see in the CertPanel dashboard.

6. Complete Additional Business Validation Requirements (Optional)

This step is for organizations that choose organization validation (OV) and extended validation (EV) SSL/TLS certificates. These are two of the three options of identity validation you can choose from to protect your brand.

If you’ve chosen a domain validation (DV) only certificate, then you can skip this step.

7. Download Your Server and Chain Certificate Files

Once the validation process is completed, you’ll be able to download your SSL/TLS certificate and intermediate CA certificate from the CA website. If you’re using one of our GeoTrust certificates, then you can do this easily through the GeoTrust Horizon dashboard.

A close-up shot of the button showing where to download your SSL/TLS certificate.
Image caption: An image showing where to download your new SSL/TLS certificate in GeoTrust Horizon

Once these steps are complete, it’s time to put your new certificate to use. We’ll now walk you through how to get an SSL certificate installed on your website.  

8. Upload and Install Your Certificate Files on Your Server

Now’s the time to upload your server and CA chain certificates. (We have a guide that walks you through how to upload an SSL certificate to your website’s server.)

If you need specific details on how to install your new certificate on your specific type of server (Windows IIS, Apache, NGINX), check out our SSL/TLS installation guides.

Don’t want to have to renewal and install your certificates every time it’s required? Put your SSL renewal and installation tasks on autopilot with GeoTrust Horizon AutoInstall SSL.

Automate Your SSL Certificate in 5 Minutes

Keep your website secure and online… no manual certificate renewals needed!

9. Test Your Site to Ensure Everything Is Set Up Properly

This final step of how to get an SSL certificate on your website entails opening a new browser and visiting your domain. If you see https:// in the URL and no warnings about the site being insecure, then you’re golden.

A real-world example of how a business can display its verified organizational details using an EV SSL/TLS certificate
Image caption: An example of our website, which uses a valid EV SSL/TLS certificate.

To be absolutely certain nothing is misconfigured, run an SSL/TLS configuration and vulnerability scan of your website using SSL Monitor. This low-cost tool is perfect for small businesses that value security but aren’t looking for a tool that costs an arm and a leg.