We specialise in tuning Java EE servers: Oracle WebLogic and IBM WebSphere.

Log in WebMail Jobs
DigiCert · Sectigo · GeoTrust · Thawte

SSL certificates — issuance, installation, A+ on SSL Labs

DV, OV, EV, Wildcard, Multi-domain (SAN). Issuance from 5 minutes to 5 business days. Installation on the client's server included — Apache, Nginx, IIS, WebLogic, WebSphere. ECDSA / RSA-4096, PEM/PFX/CRT/PKCS12 formats. Renewal monitoring: zero expirations across our managed clients in the last 24 months.

01 / Planner

Three questions. One certificate

Scope, validation level and timing — these three answers point at a specific package and price. Timing does not change the product, but it tells you straight whether you will make it.

01 How many names must it cover?
02 Who has to be validated?
03 By when?
02 / Why SSL

A technical, legal and business requirement

SSL is not a “green padlock for decoration”. It is a technical, legal and business requirement. No SSL = no modern internet — WebAuthn, HTTP/2, HTTP/3, service workers, SameSite cookies, most APIs.

Data encryption

Logins, passwords, card details, contact forms — without SSL they travel as plain text across the network. Anyone on the same Wi-Fi can intercept them. AES-256 + ECDSA P-256 with PFS: traffic captured today cannot be decrypted even if the server key is stolen later.

TLS 1.3 · AEAD · PFS

Trust + brand credibility

Without SSL, Chrome and Firefox print "Not secure" in the address bar — before anyone reads your offer. OV and EV put a verified company name inside the certificate: in finance and e-commerce that is the difference between "some website" and "that company".

OV/EV · company name in the certificate

SEO + Core Web Vitals

Google treats SSL as a ranking signal since 2014. No HTTPS = lower position. Plus HTTP/2 and HTTP/3 require TLS — faster pages, better LCP, FID, CLS.

Google ranking · HTTP/3 ready

Compliance & GDPR

GDPR art. 32 requires "appropriate technical measures" — HTTPS is the minimum. PCI-DSS for card payments: TLS 1.2+ mandatory. Financial regulators: TLS, HSTS, OCSP stapling.

GDPR · PCI-DSS · compliance
03 / Certificate types

DV, OV, EV, Wildcard, SAN — what for what

The choice depends on budget, time and brand trust needs. DV for a blog, OV for a company, EV for a bank, Wildcard for multi-subdomain apps, SAN for microservices.

Domain Validation

Only checks that you own the domain. Email to admin@ or DNS TXT record. Issued in 5–15 minutes.

DV · 5 min · blog, MVP

Organization Validation

Additionally verifies the company: company registry, phone, address. CA calls the public number. Issued in 1–3 business days.

OV · 1–3 days · company, B2B

Extended Validation

The highest level of validation. Audit of company documents, legal verification. Older browsers showed a green bar with the company name. 3–5 days.

EV · 3–5 days · bank, fintech

Wildcard

Covers *.domain.com — any number of first-level subdomains. Ideal for dynamic apps (app1., app2....).

unlimited subs · SaaS

Subject Alternative Name

One certificate for multiple domains (e.g. flexnet.pl + flexnet.com + flexnet.eu). Up to 250 SAN entries in one certificate.

SAN · multi-TLD · microservices
04 / FlexSSL packages

One price list. From blog to bank

Prices net per first year. Second year 10% cheaper. Installation on client's server (Apache, Nginx, IIS, WebLogic, WebSphere) free. Hosting with us? We file the installation request with the data centre ourselves — the hosting panel will not let you do it. Renewal monitoring, SSL Labs A+ guarantee.

Bronze · DV

FlexSSL Bronze

Basic DV for blogs and company websites.

129PLN / year
single domain · issued in 5 min
  • Domain Validation (DV)
  • Single domain (1x)
  • 256-bit encryption
  • 10k USD financial warranty
  • 99.9% browser compatibility
  • Site security seal
  • Issued in 5–15 min
  • Installation included
Choose Bronze
Silver · DV

FlexSSL Silver

DV with additional financial warranty.

369PLN / year
single domain · mobile-ready
  • Everything in Bronze
  • Financial warranty 100k USD
  • Mobile optimisation (iOS/Android)
  • OCSP Stapling support
  • Free reissuance for 1 year
  • Premium trust seal logo
  • SSL Labs A+ guarantee
Choose Silver
Platinum · EV

FlexSSL Platinum

EV for finance and premium e-commerce.

869PLN / year
EV · company name in certificate
  • Extended Validation (EV)
  • Company document audit
  • Company name in certificate
  • Financial warranty 1M USD
  • Premium trust seal
  • Phishing protection (CT logs)
  • Priority support 24/7
Choose Platinum
// Budget option — certificate only, no installation

Running your own server and installing yourself? These certificates cost less — TPay payment, automatic issuance after you click the validation link, .pem file delivered by email. You generate the private key on your side and never send it to us. If you cannot configure TLS on the server yourself, choose a package with installation.

Trustico DV1 domain · DV · email validation
99 PLNnet per certificate121.77 PLN gross
PositiveSSL1 domain · DV · Sectigo
129 PLNnet per certificate158.67 PLN gross
Trustico Wildcard*.domain.com · DV · all subdomains
349 PLNnet per certificate429.27 PLN gross
PositiveSSL Wildcard*.domain.com · DV · Sectigo
569 PLNnet per certificate699.87 PLN gross

Automated DV — usually 15–30 min after you click the validation link, valid for up to 200 days. You will need a CSR (we show the command in the order form). Need OV/EV or server installation? That's the FlexSSL packages above.

Need Multi-domain (SAN) or larger volume (10+ certificates)? Custom quote — volume discounts, one contract, one renewal cycle.

05 / Feature comparison

Black and white, no asterisks

All features at a glance. The choice becomes simple: if you need Wildcard — Gold. If EV — Platinum. If simple DV for a blog — Bronze.

Feature
Bronze
Silver
Gold
Platinum
Validation type
DV
DV
DV
EV
Wildcard *.domain
Company name in bar
Issuance time
5–15 min
5–15 min
15–30 min
3–5 days
Financial warranty
10k USD
100k USD
250k USD
1M USD
Mobile + OCSP
Price net / year
129 PLN
369 PLN
569 PLN
869 PLN
06 / Issuance process

From order to A+ on SSL Labs

For DV the whole process takes 30 minutes. For EV — 5 business days. Installation on the client's server always included — and on our hosting we do it for you, because the panel does not allow uploading a certificate yourself. After issuance we run SSL Labs scan and tune until A+.

1

Order

You choose a package, provide the domain and company details (for OV/EV). You receive the data for generating a CSR (Certificate Signing Request).

10 min
2

CSR + details

We generate a CSR on your server (or we provide one). We sign the CSR and submit to CA (DigiCert/Sectigo/GeoTrust).

15 min
3

Validation

DV: email to admin@ or DNS TXT. OV: company verification (phone, company registry). EV: legal document audit (notarised).

5 min — 5 days
4

Installation + A+

We install the cert on Apache/Nginx/IIS/WebLogic/WebSphere. We configure HSTS, OCSP Stapling, ciphers. SSL Labs scan — tuning to A+.

30 min
07 / Free vs paid — honestly

Let's Encrypt is free. When does paid make sense?

We'll be straight: for 80% of sites Let's Encrypt is enough. Paid SSL makes sense where you need brand trust, OV/EV, a financial warranty or support with an SLA. Since 15 March 2026, a publicly trusted certificate can be valid for no more than 200 days. The difference is in validation, warranty and service, not a longer validity period.

Let's Encrypt (free)

free · auto-renewal · DV only

What you get

  • Price: 0, forever
  • Issued in 1 minute (ACME protocol)
  • Auto-renewal via certbot / acme.sh
  • Wildcard (since 2018) and SAN (up to 100)
  • Same encryption algorithms (TLS 1.3)

What's missing

  • DV only — no OV or EV
  • 90-day validity (requires automation)
  • No financial warranty
  • No support (community only)
  • No company name in certificate
  • Rate limits (5 issuances/week/domain)
08 / Certificate authorities (CA)

Only trusted Certificate Authorities

We only work with CAs with the highest browser trust (Mozilla CA Certificate Program, Apple Trust Store, Microsoft Root). Their certificates are trusted by 99.9% of browsers since 2010.

Certificate authorities (CA) we work with

DigiCert Sectigo (Comodo) GeoTrust Thawte RapidSSL GlobalSign Entrust Let's Encrypt
09 / FAQ

Frequently asked questions

No answer here? Write to us — an engineer replies, not sales.

Do you support ECDSA / ECC / dual cert?
Yes. ECDSA P-256 and P-384 — faster and smaller than RSA, ideal for mobile and HTTP/3. RSA-2048 and RSA-4096 — classic default, compatibility with legacy clients. Dual certificate — server presents ECDSA for modern browsers (~95% of users) and RSA for old ones (XP, Java 6, some IoT). We configure dual cert in Apache, Nginx, WebLogic, WebSphere — transparent to the application.
What if the SSL expires?
In short: the site stops working. Chrome will show "NET::ERR_CERT_DATE_INVALID", users cannot enter. What we do to prevent this: renewal monitoring at 90/60/30/14/7 days before expiry (email alert). We contact managed clients before expiry. The current online checkout does not enable automatic renewal. Track record: 0 expirations in the last 24 months for clients under our care (vs ~12% industry average).
Do you offer SAN / Multi-domain?
Yes. SAN (Subject Alternative Name) — one certificate for multiple domains, up to 250 SANs in one certificate (depends on CA). Ideal for microservices (api1.company.com, api2.company.com...), multi-TLD (flexnet.pl + flexnet.com + flexnet.eu), or white-label (client hosts their domains on your infrastructure). Price: base package price + ~80–150 PLN/SAN above 5. Custom quote for 50+ SANs.
What does installation on WebLogic / WebSphere / IIS look like?
Apache HTTPD: SSLCertificateFile + SSLCertificateChainFile in ssl.conf, graceful restart. Nginx: ssl_certificate in server block, reload without downtime. IIS: import PFX to Personal store, bind in Site Bindings. WebLogic: identity keystore (JKS), config.xml ssl section, Managed Server restart. WebSphere: SSL configuration in wsadmin or Admin Console, sync nodes. Tomcat: server.xml connector, keystoreFile. For all: we configure HSTS, OCSP Stapling, modern ciphers (TLS 1.2+ only), SSL Labs scan to A+. Installation takes 30 min.
Do you offer Wildcard for EV?
No — this is a CA/Browser Forum restriction. EV is never Wildcard (reason: company validation must be for a specific domain, not *). If you need EV for multiple subdomains — we issue EV SAN with a list of specific subdomains (up to 250). Alternative: EV on main domain + separate Wildcard DV/OV on *.subdomain.company.com. For most fintech, EV on www.company.com + company.com is enough — that's where clients go anyway.
How to get started?
Fastest path: (1) choose a package from the section above or write to [email protected]; (2) for DV — provide domain and technical details (5 min); (3) for OV/EV — additionally company details (company registry, tax ID, phone, address); (4) we generate CSR and submit to CA; (5) validation (DV: 5 min, OV: 1–3 days, EV: 3–5 days); (6) we install on the server + SSL Labs A+ tuning. The VAT invoice is issued after payment confirmation.
TALK TO AN ENGINEER

Consultation, audit, support

Tell us what you're facing. Your choices in the form build a brief — exactly what the engineer who replies will see.

How we work Audit, project, 24/7 care
Hours Mon–Fri 9–17 · outages 24/7 for clients on contract
  • we take over systems from other vendors
  • we support older WebLogic and WebSphere
  • urgent issue? quick diagnosis first

Tell us about it

01 I'm interested in…
02 Type of engagement…
03 Ballpark budget (PLN)…
04 Timeline…
05 Contact details…
PDF, DOC, TXT, JPG/PNG · max 5 MB
An engineer replies Not a salesperson, not a call centre — someone who understands your infrastructure.
A clear next step The first reply includes an initial scope and rough estimate.
Confidentiality & NDA on request Your environment details stay between us. We sign an NDA before the call if you need it.

Your data is safe. It will be used only to handle your request. More info in our privacy policy.