Managed Windows servers customers - Submit a support request for the certificate. Be sure to indicate if you want a single, multi-domain, or wildcard certificate. You must include the fully qualified domain name for single certificates. The FQDN and subject alternative names must be provided for multi-domain certificates.
Certificates will get issued using Internet Information Services (IIS). If your application is unable to use an IIS issued certificate you must provide at least a 2048-bit CSR.
The Windows team support ticket address is win-ticket@berkeley.edu.
Self-managed customers - Supply a 2048-bit or higher CSR by adding it as a text attachment or including it directly in the body of the email or Notes section of the ServiceNow ticket. The support ticket address is cloud-ticket@berkeley.edu.
If you are requesting a multi-domain certificate you must also list the subject alternative names you want. The common name and subject alternative names must be fully qualified. Sectigo no longer accepts short names.
Please plan ahead if you need a wildcard certificate. There will be a delay while the vendor reviews requests for this type of certificate. Be prepared to provide a business reason for requesting this type of certificate. Also, your VPS will be flagged as a Protection Level 4 system if it isn't already.
If you qualify as one of the above mentioned customers, but you are affiliated with campus, you can request an SSL certificate by going to https://calnet.berkeley.edu/calnet-technologists/web-certificates.