Secure public IPv4 and IPv6 endpoints with full browser compatibility and trusted CA assurance.
$5,76 – $24,41Price range: $5,76 through $24,41
Publicly-trusted X.509 TLS certificates issued directly to an IPv4 or IPv6 address:
For modern browsers and TLS clients to trust the connection, the IP must appear in the Subject Alternative Name (SAN) field as an iPAddress entry. Cloudflare's public DNS resolver at https://1.1.1.1 is a prominent real-world example.
Since November 2015, the CA/B Forum Baseline Requirements prohibit public CAs from issuing certificates for private RFC 1918 ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) or internal hostnames (.local, .corp).
Secure a single dedicated public IP with Sectigo InstantSSL Pro (Business Validation), or combine up to 250 public IPs and domain names onto one unified certificate with GoGetSSL Public IP SAN (Domain Validation).
Essential for architectures where services and devices are reached directly by IP rather than DNS:
Mail servers and SMTP relays that expose administrative or relay endpoints by IP address where DNS routing is impractical.
Routers, firewalls, NAS appliances, and IoT controllers with web admin interfaces bound to static public IP addresses.
High-throughput cloud backends, direct server-to-server APIs, and dedicated partner endpoints reached via static public IPs.
Older legacy client systems that do not support Server Name Indication (SNI) and require an IP-bound TLS handshake to connect.
A step-by-step walkthrough of the order and authentication procedure:
Select Sectigo InstantSSL Pro for single IP Business Validation or GoGetSSL Public IP SAN for multiple IPs. Generate a CSR with the public IP as the Common Name (for single IP) or specify IPs in the SAN extension list.
Verify control using HTTP file-based DCV: host the CA validation .txt file under /.well-known/pki-validation/ on port 80. Once authenticated, install the certificate, private key, and CA intermediate chain on your server.
Common questions about this certificate type, validation standards, and deployment.
No. Only public, routable IPv4 or IPv6 addresses are eligible. DV and BV/OV validation are available, but EV is prohibited by CA/B Forum guidelines for IP certificates.
Yes. The GoGetSSL Public IP SAN supports up to 250 SAN entries combining public IPs and fully-qualified domain names on a single certificate.
No. It uses identical TLS 1.2 and 1.3 protocols, identical 256-bit AES encryption, identical RSA/ECC key options, and identical warranty protections.
A public CA cannot issue for private RFC 1918 IPs. Sectigo Private PKI is the production enterprise answer; self-signed certificates are only suitable for non-trusted internal testing.
About 5 minutes for GoGetSSL Public IP SAN (DV). Sectigo and Comodo InstantSSL Pro take 1–2 business days because Business Validation requires verification of company registration documents.
The premier marketplace for seamless SSL certificate issuance, renewal, and website trust management worldwide.
Global Certificate Distribution Hub
Support: support@renewalssl.com
Knowledge Base & Guides
CSR Generator Guide
Contact Support Team
Client Portal Login
View Shopping Cart
Quick Checkout
© 2026 RenewalSSL.com. All rights reserved.
Next-gen PKI platform. Manage digital trust at enterprise scale.
Automate the full certificate lifecycle. Stay secure and compliant.
Simplify certificate lifecycle management across your entire network.
Automate the full certificate lifecycle. Stay secure and compliant.
Protect software supply chains. Ensure secure code delivery.
Digitally sign and validate documents. Preserve integrity and origin.