How do I obtain an SSL certificate for my bIT managed or self-managed server?

A knowledge base article about How do I obtain an SSL certificate for my bIT managed or self-managed server? provided by the UC Berkeley IT Service Hub - Knowledge Portal

Managed Windows Server Customers

Submit a support request for the certificate. Be sure to indicate if you want a single, multi-domain, or wildcard certificate. You must include the fully qualified domain name (FQDN) for single certificates. The FQDN and subject alternative names (SANs) must be provided for multi-domain certificates.

Certificates will be issued using Internet Information Services (IIS). If your application is unable to use an IIS-issued certificate, you must provide at least a 2048-bit CSR.

The Windows team support ticket address is win-ticket@berkeley.edu.

Managed Unix Server Customers

Submit a ticket to unix-tickets@berkeley.edu specifying the Common Name (CN/hostname) and any additional Subject Alternative Names (SANs/CNAMEs), as well as the server(s) where the certificates will be installed.

Certificates installed in customer-maintained applications require a 2048-bit CSR; certificates installed at the OS level do not. Most deployments support automated renewals through ACME or similar.

Self-Managed Customers

Supply a 2048-bit or higher CSR by adding it as a text attachment or including it directly in the body of the email or Notes section of the ServiceNow ticket. The support ticket address is cloud-ticket@berkeley.edu.

If you are requesting a multi-domain certificate, you must also list the subject alternative names you want. The common name and subject alternative names must be fully qualified; Sectigo no longer accepts short names.

Please plan ahead if you need a wildcard certificate. There will be a delay while the vendor reviews requests for this type of certificate. Be prepared to provide a business reason for the request. Additionally, your VPS will be flagged as a Protection Level 4 system if it isn't already.

If you do not qualify as one of the above-mentioned customers but are affiliated with campus, you can request a certificate via the TLS Service Request Form.