SSL certificate
Multi-domain (SAN) certificate
One certificate for several different domains at once — useful when these are not subdomains of one domain but separate sites.
How Multi-domain (SAN) differs from the free one
| What we compare | Let’s Encrypt | Multi-domain (SAN) |
|---|---|---|
| Encryption | the same | the same |
| Price | free | — |
| Reissue and install | automatic | automatic, within the subscription |
| Invoice, contract, delivery note | none | yes |
| Trust seal for your site | none | yes |
| Support | community and documentation | ours, we answer for the expiry date |
| Certificate authority warranty | none | yes |
| Compatibility with older systems | modern browsers and systems | wider |
| Where it can be issued | wherever ACME works | also where ACME isn’t available |
| Google rankings | the same | the same |
The Google row is here on purpose: a paid certificate does not lift your site in search, and we do not promise that it will. Google treats HTTPS as a lightweight ranking factor and does not use it for indexing at all; the type and price of the certificate make no difference to search.
Multi-domain (SAN): when you need it, when you don’t
You need it if
You have several different domains (not subdomains of one domain), and it’s more convenient to manage one certificate than several separate ones.
You don’t need it if
If all your sites are subdomains of one domain, Wildcard is cheaper; if it’s a single domain, DV or the free one is enough.
We reissue it without you
Everything that repeats within the subscription is automated.
- 01Domain on our NSWe add the domain validation record ourselves at every reissue.
- 02Domain on other NSYou add a CNAME to our validation zone once. Then it’s automatic too.
- 03FallbackIf nothing else works: an email with a single confirm button.
_acme-challenge.kava.com.ua CNAME k7f2.acme.zrazu.comWhy a subscription, not a “2-year certificate”
Certificate authorities are shortening the life of a single certificate for everyone. So you buy a subscription, and we replace the certificate inside it.
- 200 daysfrom 15.03.2026 — now
- 100 daysfrom 15.03.2027
- 47 daysfrom 15.03.2029
Common questions about Multi-domain (SAN)
Does a paid Multi-domain (SAN) protect better than the free one?
No. The encryption is the same as Let’s Encrypt. The differences are the certificate authority warranty and compatibility with older systems.
Why a subscription and not a 2-year certificate?
A single certificate now lives no longer than 200 days, from 15.03.2027 — 100, from 15.03.2029 — 47. So we sell a subscription: within it we reissue and install the certificate automatically.
What do I need to do at reissue?
Nothing if the domain is on our NS: we add the validation record ourselves. With other NS you add a CNAME once, then everything is automatic.
When don’t I need Multi-domain (SAN)?
When the free certificate works for you and you need neither a certificate authority warranty nor compatibility with older systems.