24/7 Validation Support · Certificates issued in minutes
0
PUBLIC IP SSL PROTECTION

SSL Certificates for IP Address

An SSL certificate for an IP address secures any public, routable IPv4 or IPv6 address on the open internet, with the IP listed in the certificate’s Subject Alternative Name (SAN) field as an iPAddress entry. Public CAs issue these for servers and services reached directly by IP rather than by domain name, with identical 256-bit encryption.

100% IDENTICAL ENCRYPTION

HTTPS over an IP address uses identical TLS 1.2 and 1.3 protocols, 256-bit AES symmetric encryption, and 2048-bit RSA or ECC keys. There is zero cryptographic compromise compared to domain certificates.

STRICT HTTP DCV VALIDATION

Under CA/B Forum Baseline Requirements, IP address certificates must be validated using HTTP file-based verification (.well-known/pki-validation/). Email and DNS challenges are strictly prohibited.

PRODUCT CATALOG

IP Address SSL Certificates

Secure public IPv4 and IPv6 endpoints with full browser compatibility and trusted CA assurance.

Single IP

Domain Validation

Sectigo For IP

Price range: $5,76 through $24,41

PROTOCOL MECHANICS

What an SSL Certificate for an IP Address Does

Publicly-trusted X.509 TLS certificates issued directly to an IPv4 or IPv6 address:

SAN IP ADDRESS ENTRY

Subject Alternative Name Mechanics

For modern browsers and TLS clients to trust the connection, the IP must appear in the Subject Alternative Name (SAN) field as an iPAddress entry. Cloudflare's public DNS resolver at https://1.1.1.1 is a prominent real-world example.

• Standards: X.509 SAN iPAddress attribute • Protocol: Full TLS 1.2 & TLS 1.3 • Encryption: AES-256 bit / 2048-bit RSA • CAs: Sectigo, Comodo, GoGetSSL
PUBLIC VS PRIVATE RESTRICTION

Only Public IPs Are Allowed

Since November 2015, the CA/B Forum Baseline Requirements prohibit public CAs from issuing certificates for private RFC 1918 ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) or internal hostnames (.local, .corp).

• Public IPs: 100% supported & globally trusted • Private IPs: Public CAs prohibited by rule • Internal Networks: Use Sectigo Private PKI • Validation Tiers: DV and BV/OV (EV prohibited)
SINGLE IP VS MULTI-IP SAN

Single IP & Hybrid SAN Capacities

Secure a single dedicated public IP with Sectigo InstantSSL Pro (Business Validation), or combine up to 250 public IPs and domain names onto one unified certificate with GoGetSSL Public IP SAN (Domain Validation).

• Single IP: Sectigo InstantSSL Pro (1-2 days) • Multi-IP: GoGetSSL Public IP SAN (5 minutes) • Hybrid Support: Mix IPs and FQDNs in SAN • Expansion: Up to 250 total entries
COMMON USE CASES

When You Need an IP Address SSL Certificate

Essential for architectures where services and devices are reached directly by IP rather than DNS:

Mail & SMTP/IMAP Gateways

Mail servers and SMTP relays that expose administrative or relay endpoints by IP address where DNS routing is impractical.

IoT Devices & Appliances

Routers, firewalls, NAS appliances, and IoT controllers with web admin interfaces bound to static public IP addresses.

Cloud Backend APIs

High-throughput cloud backends, direct server-to-server APIs, and dedicated partner endpoints reached via static public IPs.

Legacy Systems & Non-SNI

Older legacy client systems that do not support Server Name Indication (SNI) and require an IP-bound TLS handshake to connect.

VERIFICATION WORKFLOW

How to Get an SSL Certificate for Your IP Address

A step-by-step walkthrough of the order and authentication procedure:

STEP 01 & 02

1. Choose Product & Generate CSR

Select Sectigo InstantSSL Pro for single IP Business Validation or GoGetSSL Public IP SAN for multiple IPs. Generate a CSR with the public IP as the Common Name (for single IP) or specify IPs in the SAN extension list.

• Single IP: Place IP in Common Name (CN) • Multi-IP: Leave CN blank or domain; list IPs in SAN • Key length: 2048-bit RSA or ECC (P-256/P-384)
STEP 03 & 04

2. HTTP File DCV & Server Installation

Verify control using HTTP file-based DCV: host the CA validation .txt file under /.well-known/pki-validation/ on port 80. Once authenticated, install the certificate, private key, and CA intermediate chain on your server.

• Mandatory Method: HTTP file upload on port 80 • Prohibited Methods: Email & DNS challenges NOT allowed • Issuance Speed: ~5 mins (DV), 1-2 days (BV/OV)
FAQ

Frequently Asked Questions

Common questions about this certificate type, validation standards, and deployment.

No. Only public, routable IPv4 or IPv6 addresses are eligible. DV and BV/OV validation are available, but EV is prohibited by CA/B Forum guidelines for IP certificates.

Yes. The GoGetSSL Public IP SAN supports up to 250 SAN entries combining public IPs and fully-qualified domain names on a single certificate.

No. It uses identical TLS 1.2 and 1.3 protocols, identical 256-bit AES encryption, identical RSA/ECC key options, and identical warranty protections.

A public CA cannot issue for private RFC 1918 IPs. Sectigo Private PKI is the production enterprise answer; self-signed certificates are only suitable for non-trusted internal testing.

About 5 minutes for GoGetSSL Public IP SAN (DV). Sectigo and Comodo InstantSSL Pro take 1–2 business days because Business Validation requires verification of company registration documents.

0