Ordering a .Onion Certificate from DigiCert

December 15, 2015 DigiCert

We recently fielded a high volume of questions about how to obtain a SSL Certificate for a .onion address. This blog post should provide basic answers to queries regarding .onion certificates.


As of September, .onion is recognized as a special-use domain by the IESG, which means they can be secured with SSL Certificates. (Previously .onion was considered an internal name.) Publicly trusted certificates authenticate organizations to Tor users and are an essential part to fighting phishing and MITM attacks. The CA/B Forum outlined guidelines for vetting .onion names, which you can read here.

Certificates Available for .Onion Sites

The Tor project is dedicated to helping users browse the web anonymously. However, getting a SSL Certificate to identify yourself (or an organization) to users is not about anonymity. This makes ordering a SSL Certificate for a .onion site a complicated process, which is why DigiCert adheres to the CA/B Forum guidelines for .onion certificates. When ordering a .onion certificate, make sure to remember the following:

  • EV Certificates: DigiCert only offers Extended Validation Certificates for .onion addresses.
  • Wildcard name: There is a unique use-case for these .onion EV Certificates that allows for a wildcard name to be used (e.g., *.yourdomain.onion).
  • Validity period: Under the CA/B Forum guidelines, .onion certificates can be issued for a validity period no longer than 15 months. (The DigiCert system will automatically adjust the validity period to 15 months based on the application to secure a .onion common name.)

How to Order a Certificate for a .Onion Address

If you want to buy an EV Certificate for your .onion site, please contact our Support team:

Direct line: 1-801-701-9600
Spanish: 1-801-701-9601

They can help you order your .onion EV Certificate.

Previous Article
DDoS Trends & Predictions for 2016
DDoS Trends & Predictions for 2016

DDoS attacks cost 41% of businesses at least $100,000 for every hour of downtime. As every hour passes the ...

Next Article
‘Tis the Season for Holiday Cyber Scams
‘Tis the Season for Holiday Cyber Scams

This year 51% of online shopping will be done on a mobile device but most mobile devices do not have the s...