Customer Agreement for Digital Certificates
This Customer Agreement for Digital Certificates identifies the customer terms that apply to this service category.
This customer agreement sets the terms for SSL and TLS certificates, validation, key management, revocation, automation, certificate-authority dependencies, fees and liability.
1. CA Dependencies
Certificate issuance and use are governed by the issuing Certificate Authority (CA) (e.g., Let’s Encrypt, Sectigo) Subscriber Agreements and CA/B Forum Baseline Requirements. These terms are incorporated by reference and prevail in case of conflict.
2. Validation
You agree to complete required domain control validation (DCV) and organization validation (if applicable) via methods allowed by the CA.
3. Key Management
- You are responsible for generating, protecting, and rotating private keys.
- Compromised or exposed private keys must trigger immediate certificate revocation and reissue.
4. Revocation and Reissue
We or the CA may revoke a certificate for policy violations, suspected compromise, or inaccurate data. Reissue policies depend on the CA and product.
5. Automation
Where supported, we may offer automated issuance/renewal (ACME). You must keep DNS/HTTP validation endpoints functional.
6. Warranty and Liability
Any certificate warranties are provided by the issuing CA, not by us. Our liability is limited per the Master Agreement.
7. Fees
Some certificates are free (e.g., Let’s Encrypt). Paid certificates are billed per order and are generally non‑refundable once issued.
8. Contact
ssl@fairewebhost.ca
