E-Mail Address Handling in SSL and S/MIME Certificate Orders

When processing SSL Certificate orders, it is crucial to distinguish between the purchaser (the person placing the order via our website or Application Programming Interface (API)) and the end user (the person or organization who will be using the SSL Certificate).

These are often different entities, especially in business scenarios where IT administrators order SSL Certificates on behalf of their organizations or clients.

Distinguishing the Purchaser from the End User

The e-mail address of the person submitting the order represents the purchaser - the person who placed the order, manages the account, and needs to receive all order-related communications. This is typically an IT administrator, web developer, or business owner who is responsible for obtaining and installing SSL Certificates.

An e-mail address associated with the end user represents the SSL Certificate subject - the person or organization whose information will be embedded within the SSL Certificate itself.

For SSL Certificates, this might be the technical contact at the organization.

For S/MIME Digital Certificates, this is the e-mail address that will be secured by the Digital Certificate.

The Four E-Mail Parameters We Set

For each SSL Certificate order we generally set four critical e-mail parameters, each serving a specific purpose :

E-Mail Address - This parameter determines where we send the actual SSL Certificate once it is issued. We set this to the purchaser customer e-mail to ensure the purchaser receives the SSL Certificate they ordered. The purchaser is responsible for installing or distributing the SSL Certificate to the appropriate systems or users.

Representative E-Mail Address - This is used for all critical customer communications, including validation instructions for Organization Validation (OV) and Extended Validation (EV) SSL Certificates, account setup information, and any security warnings. We set this to the purchaser e-mail address because the purchaser needs to receive and act on these important notifications. Learn About The Validation Procedure 🔗

Contact E-Mail Address - This specifies the e-mail address that validation staff will use if they need to contact someone during order processing. We set this to the purchaser e-mail address to ensure any validation queries or issues are directed to the person who placed the order and has the context to respond.

Validation E-Mail Address - This parameter is used by the Certificate Authority (CA) to validate that the end user e-mail address is legitimate, but importantly, there are generally no e-mails sent to this address. Instead, we make contact with the most relevant person if an issue has arisen.

We set this to the end user e-mail address - which has been provided by the purchaser via our order form.

Considerations Specific to S/MIME

For S/MIME Digital Certificates, there are two additional parameters that specifically relate to the Digital Certificate content :

Subject Alternative Name (SAN) E-Mail Address and S/MIME Subject E-Mail - These parameters determine what e-mail address is embedded in the S/MIME Digital Certificate Subject Alternative Name field.

This must be the end user e-mail address (the one that will use the Digital Certificate for e-mail encryption and signing), not the purchaser e-mail address. We set both of these to the end user e-mail address from the order form.

The Reason This Separation Matters

This separation ensures that SSL Certificate delivery and management communications go to the right person - the purchaser who has the technical knowledge and access to handle them.

Meanwhile, the end user information is correctly embedded in the SSL Certificate for validation and usage purposes. This is particularly important in enterprise environments where a single administrator might order dozens of SSL Certificates for different end users across their organization.

Summary

In essence, all operational communications and the SSL Certificate itself are sent to the purchaser, while the end user e-mail address is used only for validation purposes and as the subject of the SSL Certificate.

This ensures smooth order processing while maintaining the correct SSL Certificate ownership and usage rights.

Most Popular Questions

Frequently asked questions covering how Trustico® handles purchaser and end user e-mail addresses across SSL Certificate and S/MIME Digital Certificate orders, including the parameters set and why the roles are kept separate.

The Purchaser and End User Distinction When Ordering

The purchaser is the person placing the order who manages the account and receives all order-related communications, typically an IT administrator or developer. The end user is the person or organization whose information is embedded within the SSL Certificate itself and who will actually use it.

Delivery of the Issued SSL Certificate

Trustico® sends the issued SSL Certificate to the purchaser e-mail address provided during checkout. The purchaser is then responsible for installing or distributing the SSL Certificate to the appropriate systems or end users.

The Purpose of Different E-Mail Addresses in an Order

Different e-mail addresses serve specific purposes: the purchaser e-mail receives the SSL Certificate and all operational communications, while the end user e-mail is used for validation purposes and is embedded in the SSL Certificate subject. This separation ensures communications reach the right person while maintaining correct SSL Certificate ownership.

E-Mail Address Handling for S/MIME Digital Certificates

For S/MIME Digital Certificates, the end user e-mail address is embedded in the Subject Alternative Name field of the Digital Certificate. This must be the actual e-mail address that will use the Digital Certificate for encryption and signing, while the purchaser still receives all order communications.

End User E-Mails During the Ordering Process

Generally, no e-mails are sent to the end user e-mail address during processing. The validation e-mail address is recorded for Certificate Authority validation purposes, but Trustico® directs all communications including validation queries to the purchaser who has the context to respond.

Ordering SSL Certificates for Clients and Organizations

Yes, the Trustico® ordering system supports this common scenario. As the purchaser, you receive all SSL Certificate deliveries and management communications, while your clients or organization members are correctly listed as end users in the SSL Certificates themselves.

Ask Trustico® Assistant

For Instant Answers - Start Here When You Have a Question or Need Help

Merkle Tree Certificates Explained

Merkle Tree Certificates Explained

The move toward post-quantum cryptography solves one problem and creates another. It protects encrypted traffic against future quantum computers, but the new signature algorithms are far larger than the ones...

Merkle Tree Certificates Explained

The move toward post-quantum cryptography solves one problem and creates another. It protects encrypted traffic against future quantum computers, but the new signature algorithms are far larger than the ones...

SSL Certificates and Front-of-Site Services Like Cloudflare

SSL Certificates and Front-of-Site Services Lik...

Learn how front-of-site services like Cloudflare affect which SSL Certificate visitors see and how to apply your purchased SSL Certificate to them.

SSL Certificates and Front-of-Site Services Lik...

Learn how front-of-site services like Cloudflare affect which SSL Certificate visitors see and how to apply your purchased SSL Certificate to them.

Understanding X9 Certificates and the Public Trust Model

Understanding X9 Certificates and the Public Tr...

Learn what X9 Certificates are, how X9 PKI differs from public browser trust, and why they are not a substitute for a publicly trusted SSL Certificate.

Understanding X9 Certificates and the Public Tr...

Learn what X9 Certificates are, how X9 PKI differs from public browser trust, and why they are not a substitute for a publicly trusted SSL Certificate.

Why Your SSL Certificate Type and Brand Matter by Industry

Why Your SSL Certificate Type and Brand Matter ...

Why the type and brand of SSL Certificate matter across regulated industries, who examines your validation standing, and what is at stake when they do.

Why Your SSL Certificate Type and Brand Matter ...

Why the type and brand of SSL Certificate matter across regulated industries, who examines your validation standing, and what is at stake when they do.

Revocation Status Errors on a Valid SSL Certificate

Revocation Status Errors on a Valid SSL Certifi...

A revocation status error such as RevocationStatusUnknown can appear on a valid SSL Certificate. Learn how to confirm it is not revoked and what to do next.

Revocation Status Errors on a Valid SSL Certifi...

A revocation status error such as RevocationStatusUnknown can appear on a valid SSL Certificate. Learn how to confirm it is not revoked and what to do next.

Website Security Checks : Essential Steps to Protect Your Business Online

Website Security Checks : Essential Steps to Pr...

Keep your website secure with the SSL Certificate checks that matter most, from expiry and chain coverage to validation levels, issuance controls, and automation.

Website Security Checks : Essential Steps to Pr...

Keep your website secure with the SSL Certificate checks that matter most, from expiry and chain coverage to validation levels, issuance controls, and automation.

1 / 6