Question

Who issues SSL certificates, and what do they actually prove?

Vault Verified
Curated Intelligence
Definitive Source
Answer

A certificate authority (CA) issues them, and what most certificates prove is narrower than people assume: control of the domain name, and nothing else.

What a certificate contains. The domain name it covers, a public key, an issuer, validity dates, and a digital signature from the CA. Your browser trusts it because the CA's own certificate is in a root store shipped with your operating system or browser — a list of a few hundred authorities that the vendors have decided to trust.

The three validation levels:

Domain Validated (DV). The CA confirms only that the applicant controls the domain — typically by asking them to publish a specific DNS record or file. Issued automatically in seconds, frequently free. The overwhelming majority of certificates are DV.

Organisation Validated (OV). Some verification of the organisation's existence and identity.

Extended Validation (EV). A more rigorous identity check. Browsers formerly displayed a green bar with the company name; they no longer do, because research found users did not notice or understand it, and the extra assurance had little practical effect.

The crucial consequence. A padlock means the connection is encrypted and the site is what the address says it is. It does not mean the site is legitimate, honest or safe. A phishing site can obtain a valid DV certificate for its own domain in seconds — and most do. "Look for the padlock" is obsolete advice and was never a fraud check.

Certificate Transparency is the significant safeguard: CAs must log every certificate they issue to public, append-only logs, so domain owners can detect certificates issued for their domain without authorisation. This has caught real misissuance.

What happens when a CA misbehaves. Browser and OS vendors can distrust it, invalidating every certificate it ever issued. This has happened to several authorities following misissuance or poor practice, and it is the ultimate sanction in a system with no central regulator.

Practical points: Let's Encrypt made DV certificates free and automatic, which is why HTTPS became near-universal; certificate lifetimes have been shortened substantially, making automated renewal effectively mandatory; and an expired certificate is a maintenance failure, not an attack.

Related Questions