All are on the GoDaddy account #30357302 with auto renewals setup, but they must be manually saved from GoDaddy and then installed on the servers right before expiration.
*.alta.org
-
Wildcard for all internal alta.org web sites: www, dw, intranet, etc.
-
Passes through Cloudflare, so shows up externally as Google Trust on web sites.
-
Two year period.
-
Next expires 4/12/2026
-
Wildcard SSL must be installed in the IIS certificate store for all servers that will need it, then set in the IIS bindings for all web sites that use it.
-
SSL files should be moved around securely, not emailed, etc.
-
Renewal Request and Install is done on one server (Hostek “dev”) and then can be exported to a password protected PFX and imported on live (Hostek “web1”).
-
The PFX also needs to be installed on the VPN.
-
GoDaddy will auto-renew, and as long as we're still in the window, the process should be to download the new certificate, and only install it. If for some reason this doesn't work, there is a longer re-keying process.
-
Steps:
-
Go to GoDaddy, SSL Certificates, pick *.alta.org and "Manage".
-
Choose Server Type IIS and download ZIP. Move that to your computer, unzip. Copy the CRT file to the D: drive on “dev”.
-
RDP to “dev”. Open IIS. Go to the server root configuration and open "Server Certificates".
-
Choose "Complete Certificate Request" on the right.
-
Choose the CRT file from the GoDaddy download (it's not a CER). Give it a Friendly Name such as "*.alta.org 2024 March" just so it's identifiable.
-
It's in the "Personal" store and then "OK.
-
It should show up in the list. To confirm it really is usable, go OUT of the "Server Certificates" and come back. It should still be listed.
-
-
Steps if this doesn't work and a full Re-Key is necessary:
-
Choose "Create Certificate Request". Fill in all fields with no abbreviations, so "Washington" and "District of Columbia".
-
Choose 2048 for bit length.
-
Save to the D: drive as something like "altaXXXreq.txt" and Finish.
-
Go to GoDaddy, SSL Certificates, pick *.alta.org and "Manage".
-
Toward the bottom, under "Manage Certificate" choose to "Re-Key" and paste the request into the box, then "Add Change" and then "Submit Changes".
-
Make any DNS changes or other required validation steps, and wait for Pending Verification to complete.
-
Download Certificate with IIS as server type, save ZIP file to your computer.
-
Open ZIP file and copy CRT file to the D: drive on the web server.
-
Back in IIS, choose "Complete Certificate Request", pick the file from the D: drive (Change .cer to *.*)
-
Make a Friendly Name that you will know when you see it differently from the existing one, Personal, and OK.
-
-
NEXT Steps after you have a new completed certificate:
-
For EVERY web site that uses it on “dev”, select site and choose "Bindings".
-
For each https/443 entry, choose "Edit".
-
Check the SSL in the list is the correct new one, select if not.
-
Close Bindings and check web site in a fresh browser, view SSL, configure new expiration date.
-
Once 100% sure the new SSL is in use fully on “dev” delete the old SSL from the "Server Certificates".
-
-
FINAL Steps to Export and use elsewhere:
-
Choose to "Export" the full SSL to a PFX file with a password, keep that secure, but will need to be shared with anyone else using that PDF file from “dev”'s D: drive elsewhere.
-
Save this with a name that makes the year clear on the D: drive on “web”.
-
Copy the PFX file to the D: drive on “web1”, go into IIS and "Server Certificates" and choose "Import" in IIS, then proceed with Bindings for all sites on that server.
-
Check all sites that they are using the new SSL, once confirmed, delete the old from the list.
-
Delete the PFX file on the target machines. (Leave it on the original “dev” so it could be used elsewhere.)
-
*.altaidregistry.org
-
Next expires 12/16/2025
-
Passes through Cloudflare, so shows up externally as Google Trust on web sites
Free Auto-Renew Let's Encrypt/Cloudflare via WPEngine
-
meetings.alta.org
-
altagooddeeds.org
-
stopwirefraud.org
-
homeclosing101.org/com/net/info
-
titleinsurancecareers.org
Depricated
-
As of September 2025, uses free Let's Encrypt, auto-renewing
-
Used for Impexium portal.
-
Two year period
-
Impexium's documentation for the PFX file they need is here.
-
A PFX file contains both the request and the certificate all in one file so they can install it on their server. Since this can't be downloaded as is from GoDaddy, the certificate has to be installed on one of our web server's Certificate Stores, then exported from there. It's best to use WEB5dv so there's no issues, but it in no way conflicts or has anything to do with our web sites, just the store in IIS.
-
Now uses free Let's Encrypt, auto-renewing
-
Used for Elevate site.
-
Send SSL to Elevate to install on their system.
-
If there is not a new CSR (so just a simple GoDaddy Renewal) then just download from GoDaddy, and get the ZIP file to help@commpartners.com securely.
-
If there is a new CSR (so a re-key situation) then Elevate will provide the CSR, re-key with that, and then get that ZIP file to them.
www.altaidregistry.org
staging.altaidregistry.org
-
Currently managed by DesignData as separate single SSLs
-
MOVE TO ALTA CONTROL BEFORE NOVEMBER 2023 with wildcard SSL for domain.
vpn.alta.org
- Now uses *.alta.org
utm.alta.org
- Not in use
-
Used for HC101 WordPress site on WEB4wp.
-
Four year period
-
Revoked on GoDaddy 1/20/2022
-
Was expiring 5/16/2022, no longer in list, shouldn't renew
-
For AGDF WordPress site on WEB4wp.
-
One year period.
-
Revoked on GoDaddy 2/1/2022
-
Was expiring 8/20/2022, no longer in list, shouldn't renew
donate.altagooddeeds.org
-
Was going to be for an Impexium portal for AGDF, not used.
-
Revoked in GoDaddy 1/4/2022.
-
Was expiring 3/7/2022, no longer in list, shouldn't renew.
PaperSaves DAS
- Uses *alta.org