Terms and Conditions

These Terms and Conditions govern use of the HKUST Request for SSL certificate (the “Service”). By accessing or using the Service, users acknowledge and agree to be bound by these Terms and Conditions. User’ continued use of the Service constitutes acceptance of these Terms and Conditions.

Details

1. Responsibilities and Obligations

This section details users’ fundamental duties and responsibilities when using the Request for SSL certificate, regardless of the renewal method chosen.

1.1 Domain Ownership and Authorization

  • Users represent and warrant that they possess the right, ownership, and necessary authorization to request and manage SSL certificates for all domain names that they submit to or manage through the Service.

  • Users must be able to provide verifiable proof of control over the domain name if requested by ITSO.

1.2 Compliance with HKUST Policies

  • This includes compliance with any specific directives or guidelines issued by ITSO concerning server administration, network usage, and information security.

2. Specific Responsibilities for Renewal Methods

2.1 Automatic Renewal via ACME Protocol

This pathway is for users who wish to have their SSL certificates automatically renewed using the ACME protocol.

2.1.1 Technical Configuration and Maintenance

  • ACME Protocol Compliance: Users are entirely responsible for ensuring that users’ web server environment and associated Domain Name System (DNS) records are correctly configured to enable the successful operation of the ACME protocol for certificate renewal.

  • Ongoing Readiness: Users must ensure server configurations remain compatible with ACME requirements throughout the certificate’s validity period to facilitate automated renewals. ITSO may provide documentation for general guidance, but successful implementation rests solely with users.

2.1.2 Proactive Monitoring for ACME Renewals

  • Users must ensure systems are operational and accessible for ACME challenges to occur during the renewal window.

2.2 Manual Renewal via Certificate Signing Request (CSR)

This pathway is for users who will manually generate and submit a Certificate Signing Request (CSR) for renewal.

2.2.1 CSR Generation

  • Users are solely responsible for generating a valid and correctly formatted CSR for the domain(s) they wish to renew the certificate for.

2.2.2 CSR Submission and Verification

  • Users are responsible for ensuring the accuracy of the information within the CSR. Any errors in the CSR will result in an incorrectly issued certificate.

2.2.3 Certificate Installation

  • Once the renewed certificate is issued by ITSO, users are solely responsible for downloading and installing it onto users’ web server(s).

  • Users must ensure that the certificate is correctly installed and configured to secure users’ domain(s). Failure to install the certificate in a timely manner will result in service interruption for users.

3. Permitted Use of SSL Certificates

3.1 Legitimate Use: Users agree to use the SSL certificates obtained or renewed through this Service strictly for legitimate academic, research, or official HKUST-related purposes.

3.2 Prohibited Use: Users shall not use the certificates for any illegal, unethical, fraudulent, or unauthorized activities, including but not limited to, impersonation, phishing, or the distribution of malicious content.

4. ITSO Service Provisions and Limitations

4.1 Service Operation: ITSO will provide and maintain the infrastructure necessary for both ACME-based and manual CSR renewal processes.

4.2 ACME Renewal Support: For ACME renewals, ITSO will manage the ACME server infrastructure and its integration with accredited Certificate Authorities (CAs).

4.3 Manual CSR Renewal Facilitation: For manual CSR renewals, ITSO will facilitate the submission of users’ CSR to the CA and provide users with the issued certificate upon successful validation.

4.4 Service Availability: ITSO will employ reasonable efforts to ensure the consistent availability of the Service for both renewal methods.

4.5 Technical Support Scope:

  • ITSO will provide technical support for issues directly related to the functionality of the Request for SSL certificate itself.

  • For ACME renewals: Support includes troubleshooting ACME challenges, communication with the ITSO-managed ACME server, and the overall renewal workflow.

  • For manual CSR renewals: Support includes guidance on the CSR submission process and assistance with retrieving the issued certificate.

  • ITSO support does not extend to:

  • General web server configuration or troubleshooting

  • Application-level code or software issues

  • Configuration or maintenance of users’ hosted services

  • Generation of CSRs or private key management

  • Installation of renewed certificates onto users’ servers

4.6 Third-Party Costs: Any costs incurred by users for their own domain name registration, DNS hosting, or other external services required for their web presence remain their sole responsibility and are not covered by this Service.

5. Modifications and Updates

5.1 Right to Amend: ITSO reserves the right to modify these Terms and Conditions at any time without prior notice. Any amendments will become effective immediately upon their posting on the Service’s official webpage.

5.2 User Acceptance of Amendments: Users continued use of the Service following any modifications constitutes acceptance of the revised Terms and Conditions. Users are responsible for reviewing these Terms and Conditions periodically for updates.

6. Termination

6.1 Termination by ITSO: ITSO reserves the right to suspend or terminate users’ access to the Service at any time, with or without notice, for any reason, including (without limitation) violations of these Terms and Conditions, unauthorized use of the Service, or discontinuation of the Service.

6.2 Termination by Users: Users may discontinue use of the Service at any time.


Support

General Enquiries cchelp@ust.hk
Suggestions & Complaints cclisten@ust.hk
Serviceline +852-2358-6200