{"id":12689,"date":"2020-08-10T13:00:00","date_gmt":"2020-08-10T17:00:00","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=12689"},"modified":"2024-06-12T08:03:08","modified_gmt":"2024-06-12T12:03:08","slug":"what-is-a-certificate-authority-ca-and-what-do-they-do","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/what-is-a-certificate-authority-ca-and-what-do-they-do\/","title":{"rendered":"What Is a Certificate Authority (CA) and What Does It Do?"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"every-time-you-visit-a-website-that-starts-with-https-you\u2019re-using-a-certificate-authority-but-what-exactly-is-a-ca-and-how-does-it-make-your-transactions-and-communications-more-secure\">Every time you visit a website that starts with HTTPS, you\u2019re using a certificate authority. But what exactly is a CA and how does it make your transactions and communications more secure?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Certificate authorities (CA) are a critical part of the internet. If CAs didn\u2019t exist, you wouldn\u2019t be able to shop, pay taxes, or do banking online because the internet would be insecure. (Your web browser is actually using a certificate authority right now.)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But what is a certificate authority, exactly? What does a certificate authority do? And how do certificate authorities work?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s hash it out.<span id=\"newline\"><\/span><\/p>\n\n\n<span style=\"--tl-form-height-m:120.9844px;--tl-form-height-t:120.9844px;--tl-form-height-d:120.9844px;\" class=\"tl-placeholder-f-type-shortcode_17586 tl-preload-form\"><span><\/span><\/span>\n\n\n<div class=\"wp-block-advanced-gutenberg-blocks-summary\"><p class=\"wp-block-advanced-gutenberg-blocks-summary__title\">What we&#8217;re hashing out&#8230;<\/p><div class=\"wp-block-advanced-gutenberg-blocks-summary__fold\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"feather feather-chevron-up\"><polyline points=\"18 15 12 9 6 15\"><\/polyline><\/svg><\/div><ol role=\"directory\" class=\"wp-block-advanced-gutenberg-blocks-summary__list\"><li><a href=\"#every-time-you-visit-a-website-that-starts-with-https-you\u2019re-using-a-certificate-authority-but-what-exactly-is-a-ca-and-how-does-it-make-your-transactions-and-communications-more-secure\">Every time you visit a website that starts with HTTPS, you\u2019re using a certificate authority. But what exactly is a CA and how does it make your transactions and communications more secure?<\/a><ol><\/ol><\/li><li><a href=\"#what-is-a-certificate-authority-ca\">What Is a Certificate Authority (CA)?<\/a><ol><li><a href=\"#certificate-authorities-are-like-passport-authorities-for-the-internet\">Certificate Authorities Are Like Passport Authorities for the Internet<\/a><ol><\/ol><\/li><\/ol><\/li><li><a href=\"#how-a-certificate-authority-works-the-technical-details\">How a Certificate Authority Works: The Technical Details<\/a><ol><\/ol><\/li><li><a href=\"#what-does-a-certificate-authority-do-breaking-down-the-functions-of-a-ca\">What Does a Certificate Authority Do? Breaking Down the Functions of a CA<\/a><ol><li><a href=\"#verification\">Verification<\/a><ol><\/ol><\/li><li><a href=\"#digital-certificates\">Digital Certificates<\/a><ol><li><a href=\"#ssltls-certificates\">SSL\/TLS Certificates<\/a><ol><li><a href=\"#types-of-ssltls-certificates\">Types of SSL\/TLS Certificates<\/a><ol><\/ol><\/li><\/ol><\/li><li><a href=\"#code-signing-certificates\">Code Signing Certificates<\/a><ol><\/ol><\/li><li><a href=\"#email-signing-certificates\">Email Signing Certificates<\/a><ol><\/ol><\/li><li><a href=\"#document-signing-certificates\">Document Signing Certificates<\/a><ol><\/ol><\/li><\/ol><\/li><li><a href=\"#digital-signatures\">Digital Signatures<\/a><ol><\/ol><\/li><li><a href=\"#a-certificate-authority\u2019s-role-in-the-chain-of-trust\">A Certificate Authority\u2019s Role in the Chain of Trust<\/a><ol><\/ol><\/li><li><a href=\"#a-ca\u2019s-role-in-certificate-revocation\">A CA\u2019s Role in Certificate Revocation<\/a><ol><\/ol><\/li><\/ol><\/li><li><a href=\"#why-certificate-authorities-are-so-important\">Why Certificate Authorities Are So Important<\/a><ol><\/ol><\/li><li><a href=\"#but-just-how-many-cas-are-there\">But Just How Many CAs Are There?<\/a><ol><li><a href=\"#the-differences-between-a-public-certificate-authority-and-a-private-ca\">The Differences Between a Public Certificate Authority and a Private CA<\/a><ol><li><a href=\"#what-is-a-trusted-ca-and-why-do-we-trust-them\">What Is a Trusted CA (and Why Do We Trust Them)?<\/a><ol><\/ol><\/li><li><a href=\"#what-is-a-private-ca\">What Is a Private CA?<\/a><ol><\/ol><\/li><\/ol><\/li><li><a href=\"#who-decides-which-certificate-authorities-are-publicly-trusted\">Who Decides Which Certificate Authorities Are Publicly Trusted?<\/a><ol><\/ol><\/li><\/ol><\/li><li><a href=\"#final-thoughts-on-certificate-authorities-and-why-they-matter\">Final Thoughts on Certificate Authorities and Why They Matter<\/a><ol><\/ol><\/li><\/ol><\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"what-is-a-certificate-authority-ca\">What Is a Certificate Authority (CA)?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A certificate authority, also known as a certification authority, is a trusted organization that verifies websites (and other entities) so that you know who you\u2019re communicating with online. Their objective is to make the internet a more secure place for organizations and users alike. This means that they play a pivotal role in digital security.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If that sounded slightly nebulous or confusing, let\u2019s use an example to explain what a certificate authority is. Let\u2019s say you\u2019re visiting your bank\u2019s website, bbt.com:<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"523\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/bbt-website-example2-1024x523.png\" alt=\"Screenshot of the BB&amp;T website\" class=\"wp-image-12691 addshadow\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/bbt-website-example2-1024x523.png 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/bbt-website-example2-300x153.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/bbt-website-example2-768x392.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/bbt-website-example2.png 1501w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption>Here\u2019s a screenshot that shows how bbt.com displays in the Google Chrome browser<\/figcaption><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">If you\u2019re familiar with how the internet works, you know that things are not always as they seem. The website looks like bbt.com, and the domain says that it\u2019s bbt.com\u2026 but how do you <em>know<\/em> that you\u2019re actually connected to a server that\u2019s run by BB&amp;T? How do you know it\u2019s not a hacker who built a website that looks just like bbt.com? For hacker geniuses, that\u2019d be pretty easy to do \u2014 here\u2019s a recent example of this kind of attack:<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"814\" height=\"624\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/myetherwallet-tweet-example.png\" alt=\"A screenshot of the MyEtherWallet tweet\" class=\"wp-image-12692 addshadow\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/myetherwallet-tweet-example.png 814w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/myetherwallet-tweet-example-300x230.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/myetherwallet-tweet-example-768x589.png 768w\" sizes=\"auto, (max-width: 814px) 100vw, 814px\" \/><figcaption>A screenshot of a tweet by <a href=\"https:\/\/twitter.com\/myetherwallet\/status\/988787116015415296\" target=\"_blank\" rel=\"noreferrer noopener\">MyEtherWallet<\/a> that talks about an imposter phishing website.<\/figcaption><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">So how do you know you\u2019re connected to the real website? That\u2019s a certificate authority\u2019s job \u2014 they verify websites\/organizations so that you know who you\u2019re communicating with online. (This way, you don\u2019t accidentally send your credit card number to a hacker in Timbuktu.) So, if we look at the SSL\/TLS certificate details for bbt.com, we can see that the website has been verified by DigiCert Inc. This means that DigiCert is the certificate authority that verified BB&amp;T\/bbt.com so you can be 100% confident that you\u2019re connected with the official BB&amp;T website:<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"864\" height=\"472\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/bbt-certificate-info-chrome.png\" alt=\"A screenshot of BB&amp;T's website certificate &amp; certificate authority information in Chrome\" class=\"wp-image-12693 addshadow\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/bbt-certificate-info-chrome.png 864w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/bbt-certificate-info-chrome-300x164.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/bbt-certificate-info-chrome-768x420.png 768w\" sizes=\"auto, (max-width: 864px) 100vw, 864px\" \/><figcaption>Here\u2019s a screenshot that shows how the certificate information displays in the Google Chrome browser.<\/figcaption><\/figure><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"817\" height=\"509\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/bbt-certificate-info-firefox.png\" alt=\"A screenshot of BB&amp;T's website certificate &amp; certificate authority information in Firefox\" class=\"wp-image-12694 addshadow\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/bbt-certificate-info-firefox.png 817w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/bbt-certificate-info-firefox-300x187.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/bbt-certificate-info-firefox-768x478.png 768w\" sizes=\"auto, (max-width: 817px) 100vw, 817px\" \/><figcaption>Here\u2019s a screenshot that shows how the certificate information displays in the Firefox browser.<\/figcaption><\/figure><\/div>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"certificate-authorities-are-like-passport-authorities-for-the-internet\">Certificate Authorities Are Like Passport Authorities for the Internet<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If you\u2019ve ever gotten a passport to travel internationally, you probably remember the verification process that you went through to prove that you are who you claimed to be. (It probably included some legal papers, photo ID, and maybe fingerprints.)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Once you got your passport, you could use it to prove to anyone that you\u2019re really you. (Even if they\u2019d never met you before.)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Certificate authorities are like that \u2014 but for websites and online activities. Just like the passport office, a certificate authority charges a small fee to complete the verification process and issue the certificate. In this case, after they verify a website (or organization), they issue what\u2019s known as a digital certificate. This digital file enables organizations, websites, or other entities to prove who they are \u2014 that they\u2019re the real deal.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So how does all of this work? After all, websites don\u2019t have actual passports, and I don\u2019t remember scanning any passports when I visit my bank\u2019s website\u2026<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s dive into this topic in more detail.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"how-a-certificate-authority-works-the-technical-details\">How a Certificate Authority Works: The Technical Details<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Certificate authorities are one of the integral parts that make up a larger system called <a href=\"https:\/\/www.thesslstore.com\/blog\/what-is-pki-a-crash-course-on-public-key-infrastructure-pki\/\">public key infrastructure<\/a>, or PKI for short. If you want to read more about how it works, see our article that offers a deep dive on <a href=\"https:\/\/www.thesslstore.com\/blog\/how-pki-works\/\">how PKI works<\/a>. But for now, let\u2019s just give a quick overview before moving on. To keep things simple, we\u2019ll keep talking about how PKI works with websites.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When you go to a website and see the padlock (or the security details like we showed above for bbt.com), the technology that\u2019s enabling that is an SSL certificate (or, more accurately, a TLS certificate, but you can use either term).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">SSL\/TLS certificates are based on PKI, and there are a few key parts that need to be in place for the SSL certificate to work:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>A <strong>digital certificate<\/strong> (for example, an SSL\/TLS certificate) that proves the website\u2019s identity.<\/li>\n\n\n\n<li>A <strong>certificate authority<\/strong> that verifies the website and issues the digital certificate.<\/li>\n\n\n\n<li>A <strong>digital signature<\/strong> that proves the SSL certificate was issued by the trusted certificate authority.<\/li>\n\n\n\n<li>A <strong>public key<\/strong> that your browser uses to encrypt data sent to the website.<\/li>\n\n\n\n<li>A <strong>private key<\/strong> that the website uses to decrypt the data sent to it.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s take a look at this visual. It helps to break down the process of how PKI works in website security and the role that CAs play in it:<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"824\" height=\"869\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/certificate-authority.png\" alt=\"An illustration of the role a certificate authority plays in website security\" class=\"wp-image-12695 addshadow\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/certificate-authority.png 824w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/certificate-authority-284x300.png 284w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/certificate-authority-768x810.png 768w\" sizes=\"auto, (max-width: 824px) 100vw, 824px\" \/><figcaption>This visual illustrates the role that a certificate authority plays in public key infrastructure.<\/figcaption><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">As you can see there, the certificate authority is at the top of the process. That\u2019s because once someone requests a certificate, everything trickles down from the CA after that.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"Certificate Authorities - CompTIA Security+ SY0-401: 6.3\" width=\"960\" height=\"540\" src=\"https:\/\/www.youtube.com\/embed\/Bh6ZXskKuNc?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"what-does-a-certificate-authority-do-breaking-down-the-functions-of-a-ca\">What Does a Certificate Authority Do? Breaking Down the Functions of a CA<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">As we mentioned, commercial certificate authorities are integral to public key infrastructure. What they do is:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Vet domain names, individuals and organizations to validate their identities through official records.<\/li>\n\n\n\n<li>Issue digital certificates that authenticate servers, individuals and organizations (establishing trust).<\/li>\n\n\n\n<li>Maintain certificate revocation lists that indicate when certificates become invalid prior to their expiry dates. (We\u2019ll speak more to this later in the article.)<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s dive into the specific functions that they perform to explain this a bit more.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"verification\">Verification<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The process starts when a website approaches a certificate authority to obtain a digital certificate. The certificate authority completes a verification process, depending on the type of certificate requested:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Domain validation<\/strong> \u2014 The certificate authority verifies that the requestor is the legitimate manager of the domain\/website in question. That\u2019s it. Needless to say, this means that <a href=\"https:\/\/www.thesslstore.com\/support\/dv\/dv-ssl-validation-requirements.aspx\">domain validation<\/a> is the bare minimum in terms of validation.<\/li>\n\n\n\n<li><strong>Organization validation<\/strong> \u2014 The certificate authority not only verifies that the domain information is legitimate, but it goes a step further and performs basic business validation. The <a href=\"https:\/\/www.thesslstore.com\/support\/ov\/ov-ssl-validation-requirements.aspx\">OV process<\/a> involves a human element. Basically, the CA reviews information that the certificate requestor provides and also researches additional information (using third-party records and sources) to ensure the organization is legitimate.<\/li>\n\n\n\n<li><strong>Extended validation<\/strong> \u2014 This is <a href=\"https:\/\/www.thesslstore.com\/support\/ev\/extended-validation-ev.aspx\">the most thorough level of business validation<\/a>. In this one- to five-day validation process, the CA takes an extensive look at the requestor\u2019s organization. They go above and beyond the requirements of the OV validation process to ensure that your organization truly is legitimate.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">By requiring individuals and organizations to verify themselves, the CA is able to offer greater assurance that the requestor\u2019s website is real.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"digital-certificates\">Digital Certificates<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Certificate authorities bring identity into the picture through certificate authentication. And this is what helps the website to establish trust with your browser.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Although we\u2019ve only really talked about one type so far (SSL\/TLS certificates), there are actually multiple categories of digital certificates that CAs issue \u2014 and each plays a different role within PKI. In some cases, there are multiple types of digital certificates within each category. All of these certificates are known as X.509 digital certificates because X.509 is the technical standard they all comply with.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"ssltls-certificates\">SSL\/TLS Certificates<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>SSL\/TLS certificates <\/strong>(aka <a href=\"https:\/\/www.thesslstore.com\/blog\/what-is-a-website-security-certificate-and-what-does-it-do-for-your-business\/\">website security certificates<\/a>) are what we\u2019ve been talking about so far. These certs are what facilitate the secure, encrypted connections that take place between a user\u2019s browser and your web server. (Remember that padlock icon we pointed out earlier? Yeah, these certs are what make that possible.)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These certificates are what eliminate the \u201cnot secure\u201d warnings in the URL bar and the \u201cyour connection is not private\u201d warning messages that browsers display for insecure websites. For example, here\u2019s what it looks like in Chrome when no SSL\/TLS certificate is installed (or if there is one but it\u2019s improperly configured):<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"504\" height=\"45\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/not-secure.png\" alt=\"\" class=\"wp-image-12696 addshadow\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/not-secure.png 504w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/not-secure-300x27.png 300w\" sizes=\"auto, (max-width: 504px) 100vw, 504px\" \/><figcaption>&#8230; Now that&#8217;s what we call irony.<\/figcaption><\/figure><\/div>\n\n\n\n<h5 class=\"wp-block-heading\" id=\"types-of-ssltls-certificates\">Types of SSL\/TLS Certificates<\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">SSL\/TLS certificates are divided by their validation levels and functionalities:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Validation levels<\/strong>: These are the domain, organization and extended validation types that we discussed a little bit ago.<\/li>\n\n\n\n<li><strong>Functionalities:<\/strong>\n<ul class=\"wp-block-list\">\n<li><strong>Single domain certificates<\/strong> \u2014 As the name would implies, these types of SSL\/TLS certificates secure an individual domain. (This includes both the WWW and non-WWW versions of the domain.)<\/li>\n\n\n\n<li><strong>Multi-domain certificates<\/strong> \u2014 These certificates allow you to secure multiple domains and subject alternative name (SAN) domains under a single certificate. (SANs are alternative host names, common names, IP addresses, etc.)<\/li>\n\n\n\n<li><strong>Wildcard certificates<\/strong> \u2014 The term wildcard refers to subdomains. So, a wildcard SSL\/TLS certificate is one that secures an unlimited number of subdomains for one domain under a single certificate. (For example, you may see the subdomain info listed with an asterisk, like *.bbt.com or *.thesslstore.com.)<\/li>\n\n\n\n<li><strong>Multi-domain wildcard certificates<\/strong> \u2014 These certificates are kind of the best of both worlds. Not only do they enable you secure multiple domains under a single certificate, but they also allow you to secure as many subdomains as you want, too. Multi-domain wildcards offer the most in terms of versatility.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"code-signing-certificates\">Code Signing Certificates<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Developers and publishers use these types of certificates to digitally sign their code to ensure its integrity. This enables users to tell whether it\u2019s been tampered with since it was signed originally. It also helps you to authenticate yourself or your organization by showing that it was you who actually signed it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It helps you to avoid ugly warning messages like this:<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"457\" height=\"370\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/UnknownPublisher.png\" alt=\"Screenshot of an unverified publisher warning message\" class=\"wp-image-12697 addshadow\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/UnknownPublisher.png 457w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/UnknownPublisher-300x243.png 300w\" sizes=\"auto, (max-width: 457px) 100vw, 457px\" \/><figcaption>This screenshot is an example of the types of warning messages that display with unverified software.<\/figcaption><\/figure><\/div>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"email-signing-certificates\">Email Signing Certificates<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Email signing certificates are useful for authenticating individuals and clients to web servers. These certs are also known as <a href=\"https:\/\/www.thesslstore.com\/blog\/what-you-need-to-know-about-s-mime\/\">S\/MIME certificates<\/a>, personal authentication certificates, client authentication certificates, etc.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is how an email displays when it\u2019s signed with an email signing certificate:<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1002\" height=\"216\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/signed-email-example.png\" alt=\"An example of an email that's signed using a certificate from a certificate authority\" class=\"wp-image-12698 addshadow\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/signed-email-example.png 1002w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/signed-email-example-300x65.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/signed-email-example-768x166.png 768w\" sizes=\"auto, (max-width: 1002px) 100vw, 1002px\" \/><figcaption>Note the ribbon on the right and the &#8220;signed by&#8221; language under the email header fields.<\/figcaption><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">If you dig a little deeper by clicking on the ribbon on the right, it offers more information that attests that the email genuinely came from my account. (More specifically, from my device\u2019s email client.)<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"440\" height=\"297\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/email-digital-signature-info.png\" alt=\"A screenshot of a digital signature\" class=\"wp-image-12699 addshadow\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/email-digital-signature-info.png 440w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/email-digital-signature-info-300x203.png 300w\" sizes=\"auto, (max-width: 440px) 100vw, 440px\" \/><\/figure><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"440\" height=\"583\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/signed-email-certificate-info.png\" alt=\"A breakdown of the security layers of a digital signature\" class=\"wp-image-12700 addshadow\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/signed-email-certificate-info.png 440w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/signed-email-certificate-info-226x300.png 226w\" sizes=\"auto, (max-width: 440px) 100vw, 440px\" \/><\/figure><\/div>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"document-signing-certificates\">Document Signing Certificates<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">These certificates are useful for authenticating the document creator and validating the integrity of the document itself.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The way that a certificate authority gives credence to those individual certificates is by issuing root certificates that other certificates link back to. This is what we call the chain of trust (we\u2019ll discuss that more in depth shortly).<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"digital-signatures\">Digital Signatures<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A certificate authority applies something called a <a href=\"https:\/\/www.thesslstore.com\/blog\/digital-signatures-why-you-should-sign-everything\/\">digital signature<\/a> to the digital certificate. In simple terms, the digital signature:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Proves that the certificate was issued by the trusted certificate authority.<\/li>\n\n\n\n<li>Validates that the certificate has not been modified or swapped out.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">But can\u2019t someone just fake a digital signature? No \u2014 because of <a href=\"https:\/\/www.thesslstore.com\/blog\/difference-encryption-hashing-salting\/\">hashing and check-sums<\/a>. But that\u2019s a whole other complex topic that\u2019ll take us down a rabbit hole. Let\u2019s just make this simple by saying that digital signatures can\u2019t be copied, faked, or modified.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"a-certificate-authority\u2019s-role-in-the-chain-of-trust\">A Certificate Authority\u2019s Role in the Chain of Trust<\/h3>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"531\" height=\"414\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/Certificate-Chain.jpg\" alt=\"difference between root and intermediate certificate\" class=\"wp-image-7201\" style=\"width:307px;height:239px\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/Certificate-Chain.jpg 531w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/Certificate-Chain-300x234.jpg 300w\" sizes=\"auto, (max-width: 531px) 100vw, 531px\" \/><figcaption class=\"wp-element-caption\">A visual breakdown of how one certificate in the chain of trust signs the next&#8230;<\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">The chain of trust, a series of certificates that link back to the issuing CA, is a hierarchical trust model. This type of chain links back from the website\u2019s server certificate to the root by way of an intermediate certificate. This means that the trust model that all public CAs use consists of:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Root certificates,<\/li>\n\n\n\n<li><a href=\"https:\/\/www.thesslstore.com\/blog\/root-certificates-intermediate\/\">Intermediate certificates<\/a>, and<\/li>\n\n\n\n<li>Server certificates.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Since the three-part trust model is what all public certificate authorities use, that\u2019s the one that we\u2019re going to focus on here. With this in mind, this is what the chain of trust looks like for the BB&amp;T website:<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"470\" height=\"624\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/bbt-ca-certificate-chain-of-trust.png\" alt=\"\" class=\"wp-image-12701 addshadow\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/bbt-ca-certificate-chain-of-trust.png 470w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/bbt-ca-certificate-chain-of-trust-226x300.png 226w\" sizes=\"auto, (max-width: 470px) 100vw, 470px\" \/><figcaption>In the graphic above, the root certificate is labeled DigiCert. The intermediate certificate is labeled DigiCert SHA-2 Extended Validation Server CA. The server certificate is the one with BB&amp;T domain address as the title.&nbsp;<\/figcaption><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Not sure how to read it? Think of it like an upside-down tree \u2014 the root certificates are the base\/foundation, the intermediate certificates are like the tree trunk and larger branches, and the individual server certificates are the leaf certificates that have limited lifespans.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>A <strong>root certificate<\/strong> is a self-signed signed certificate that the CA issues and signs using its private key. A certificate authority only issues a handful of root certificates and they\u2019re valid for extended periods of time. As you can imagine, this means that CAs closely guard and protect these certificates. Browsers and OS key stores maintain lists of these trusted root certificates.<\/li>\n\n\n\n<li>An <strong>intermediate certificate<\/strong> is issued from root certificates. A root CA can delegate its authority to issue SSL\/TLS server certificates to its intermediate CAs. These entities essentially serve as the go-between for the root CA and server certificates. (So, if an attacker compromises an intermediate CA\u2019s key, only the certificates they signed become invalid.)<\/li>\n\n\n\n<li>A <strong>leaf certificate<\/strong> is what a CA issues for your domain. This is the certificate that you upload to your server that validates your domain, subdomains, etc. (depending on the certificate). These public certificates have a <a href=\"https:\/\/www.thesslstore.com\/blog\/google-chrome-to-join-apple-safari-in-one-year-certificate-validity\/\">limited lifespan of one year<\/a> (398 days, more specifically) starting on or before Sept. 1, 2020.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">But what happens when something goes wrong? For example, when a CA\u2019s private key gets lost or the certificate otherwise becomes compromised. This is where a certificate revocation list comes into play.<\/p>\n\n\n<span style=\"--tl-form-height-m:937.938px;--tl-form-height-t:1002.97px;--tl-form-height-d:1002.97px;\" class=\"tl-placeholder-f-type-shortcode_16294 tl-preload-form\"><span><\/span><\/span>\n\n\n<h3 class=\"wp-block-heading\" id=\"a-ca\u2019s-role-in-certificate-revocation\">A CA\u2019s Role in Certificate Revocation<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A <a href=\"https:\/\/www.thesslstore.com\/blog\/crl-explained-what-is-a-certificate-revocation-list\/\">certificate revocation list<\/a>, essentially, is a blacklist of certificates that can no longer be trusted. A certificate authority adds a certificate to this list of shame to communicate that something\u2019s wrong with a particular certificate and that it\u2019s no longer trustworthy. This is a list that clients can reach out to CAs to check (or website servers can also check and provide info to the clients for automatically through a process called <a href=\"https:\/\/www.thesslstore.com\/blog\/ocsp-ocsp-stapling-ocsp-must-staple\/\">OCSP stapling<\/a>).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Is a CRL the same as a CA\u2019s <a href=\"http:\/\/www.certificate-transparency.org\/how-ct-works\" target=\"_blank\" rel=\"noreferrer noopener\">certificate transparency (CT) log<\/a>? No. These are two different things. Whenever a CA issues a new digital certificate, it must create a new entry on its public CT log. However, if a CA invalidates any of those certificates before their assigned expiration dates, then the CA adds those certs to their CRL.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"why-certificate-authorities-are-so-important\">Why Certificate Authorities Are So Important<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A certificate authority is the Issuer of Certificates, the Signer of (Public) Keys, and the Authenticator of Organizations and Individuals. (It all sounds very <em>Game of Thrones<\/em>-esque, doesn\u2019t it? Minus the dragons and all of the requisite sex, murder, and intrigue, of course\u2026)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Without trusted CAs to issue digital certificates, you now know that wouldn\u2019t be able to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Objectively authenticate yourself or your organization,<\/li>\n\n\n\n<li>Encrypt data or the connections that data transmits through,<\/li>\n\n\n\n<li>Validate the integrity of your data.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s imagine that you\u2019re a website owner and your customers are trying to connect to your website. How do they know that they\u2019re actually connecting to your legitimate website and not a malicious fake? A certificate authority attests that the site is owned by you and that your organization is legitimate (depending on the validation level of the cert you use). This helps to establish trust with the customers\u2019 web browsers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So, when the user tries to connect with your site, your server sends its public key along with a digital certificate (SSL\/TLS certificate) that\u2019s signed by the CA. Once it establishes this trust with the client through a process known as an <a href=\"https:\/\/www.thesslstore.com\/blog\/explaining-ssl-handshake\/\">SSL\/TLS handshake<\/a> (which it too complex to get into here), then a secure, encrypted connection forms between them. Encrypting the communication channel prevents any unintended parties from intercepting and stealing the data that transmits between your customers and your server. (Ever heard of a <a href=\"https:\/\/www.thesslstore.com\/blog\/man-in-the-middle-attack\/\">man-in-the-middle attack<\/a>, or a MitM attack? That\u2019s what this is&#8230;)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Basically, all of this is to say that without these third-party entities, your site users would never know for certain whether you are who you claim or be, or if your data has been tampered with in any way. Furthermore, you\u2019d never be compliant with regulations and laws regarding data security and privacy. (Think <a href=\"https:\/\/www.thesslstore.com\/blog\/hipaa-compliance-technical-safeguards\/\">HIPAA<\/a>, <a href=\"https:\/\/www.thesslstore.com\/blog\/demystifying-pci-dss-compliance\/\">PCI DSS<\/a>, <a href=\"https:\/\/www.thesslstore.com\/blog\/understanding-data-encryption-requirements-for-gdpr-ccpa-lgpd-hipaa\/\">GDPR, CCPA<\/a>, etc.)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">All of these regulations involve the use of certificate authorities in some way. And if you\u2019re non-compliant, leaves you facing potentially significant non-compliance fines, potential lawsuits, and losing the trust (and business) of customers. That\u2019s going to take a heavy toll on your business financially, and the damage to your organization\u2019s reputation may be something that you can\u2019t come back from.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"but-just-how-many-cas-are-there\">But Just How Many CAs Are There?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">You may be surprised to know that there are actually a few hundred public CAs that exist globally. They\u2019re often divided by country or region. However, it\u2019s really just the top dozen or so that issue most of the certificates that are in use online.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Did you catch that? We said <em>public<\/em> CAs. Yes, there are actually different types of certificate authorities. You\u2019ve got your external commercial CAs \u2014 or what are also known as publicly trusted certificate authorities. (These are what people usually refer to when talking about CAs.) But then you\u2019ve also got your private CAs as well. And there are some important distinctions to know about <a href=\"https:\/\/www.thesslstore.com\/blog\/enterprise-public-key-infrastructure-pki\/\">public vs private CAs<\/a>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"the-differences-between-a-public-certificate-authority-and-a-private-ca\">The Differences Between a Public Certificate Authority and a Private CA<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">While the terms seem pretty self-explanatory, we\u2019ll go ahead and break things down a bit more regarding the players for those who are new to the game.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"what-is-a-trusted-ca-and-why-do-we-trust-them\">What Is a Trusted CA (and Why Do We Trust Them)?<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">A trusted certificate authority \u2014 or what\u2019s also known as a commercial certificate authority \u2014 is a third-party entity that issues certificates for organizations that request them. They\u2019re not controlled in any way by the person or organization that requests a certificate from them. A trusted CA issues publicly trusted digital certificates that meet at least the minimum regulatory standards (aka <a href=\"https:\/\/cabforum.org\/baseline-requirements\/\" target=\"_blank\" rel=\"noreferrer noopener\">baseline requirements<\/a>, or BRs) that are outlined by the CA\/Browser Forum (CA\/B Forum).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">According to the <a href=\"https:\/\/cabforum.org\/faq-about-the-baseline-requirements\/\" target=\"_blank\" rel=\"noreferrer noopener\">CA\/B Forum<\/a>, which has <a href=\"https:\/\/cabforum.org\/members\/\" target=\"_blank\" rel=\"noreferrer noopener\">nearly 50 CAs as members<\/a> (in addition to browsers):<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>CA service providers will have a clear understanding of the standards that they need to adhere to when providing SSL and authentication services.&nbsp; In turn, auditors will use the criteria to measure whether the CA meets industry minimum expectations.&nbsp; A CA with an audit indicating that it is compliant with the Baseline Requirements will have less risk of being rejected by the leading browsers (i.e. their certificates will be more widely accepted).&nbsp;&nbsp; Consumers will be assured of a certain level of security when they encounter SSL certificates offered by CAs that have adopted the CA\/B Baseline Requirements.&nbsp;&nbsp; The Baseline Requirements will lead to more frequent use of SSL to secure websites with stronger encryption and fewer certificate-related vulnerabilities.\u201d<\/em><\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Examples of some of the biggest publicly trusted CAs (listed alphabetically) include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>DigiCert<\/li>\n\n\n\n<li>Entrust Datacard<\/li>\n\n\n\n<li>Globalsign<\/li>\n\n\n\n<li>GoDaddy<\/li>\n\n\n\n<li>Let\u2019s Encrypt<\/li>\n\n\n\n<li>Sectigo<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"what-is-a-private-ca\">What Is a Private CA?<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">A private certificate authority (also known as private PKI), on the other hand, is an internal CA that exists within a larger organization (typically an enterprise) and issues its own certificates. A private CA functions like its public counterparts in many ways, but probably the most glaring differences are that:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>A private CA\u2019s certificates are trusted only by its internal users, clients, and IT systems.<\/li>\n\n\n\n<li>A private CA issues certificates that restrict access to a select group of users.<\/li>\n\n\n\n<li>You have to set up and host the private CA yourself (or hire a third party to do it for you).<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Because these certificates are issued by an internal CA and not a trusted third-party CA, they\u2019re best suited for use within intranets and internal networks \u2014 never any public-facing sites or endpoints. Some of the most common uses for private PKI include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Virtual private networks (VPNs),<\/li>\n\n\n\n<li>Intranet sites,<\/li>\n\n\n\n<li>Private email signing certificates,<\/li>\n\n\n\n<li>Closed user-group services, and<\/li>\n\n\n\n<li>File-sharing applications.<\/li>\n<\/ul>\n\n\n<span style=\"--tl-form-height-m:927.562px;--tl-form-height-t:999.781px;--tl-form-height-d:999.781px;\" class=\"tl-placeholder-f-type-shortcode_17591 tl-preload-form\"><span><\/span><\/span>\n\n\n<p class=\"wp-block-paragraph\">The focus of this article isn\u2019t private CAs \u2014 but we thought it would be remiss if we didn\u2019t at least mention them. Let\u2019s get back to the main focus of this articles: publicly trusted certificate authorities.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"who-decides-which-certificate-authorities-are-publicly-trusted\">Who Decides Which Certificate Authorities Are Publicly Trusted?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">That\u2019s a good question \u2014 and there\u2019s not one answer to it. For example:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Microsoft decides <a href=\"https:\/\/docs.microsoft.com\/en-us\/security\/trusted-root\/participants-list\" target=\"_blank\" rel=\"noreferrer noopener\">which CAs are trusted by Windows machines<\/a>,<\/li>\n\n\n\n<li>Mozilla decides <a href=\"https:\/\/blog.mozilla.org\/security\/2019\/02\/14\/why-does-mozilla-maintain-our-own-root-certificate-store\/\" target=\"_blank\" rel=\"noreferrer noopener\">which CAs are trusted in Firefox and Linux machines<\/a>,<\/li>\n\n\n\n<li>Apple decides <a href=\"https:\/\/www.apple.com\/certificateauthority\/ca_program.html\" target=\"_blank\" rel=\"noreferrer noopener\">which CAs are trusted on their Safari browser, device operating systems, etc.<\/a><\/li>\n<\/ul>\n\n\n\n<div class=\"wp-block-group\"><div class=\"wp-block-group__inner-container is-layout-constrained wp-block-group-is-layout-constrained\">\n<div class=\"wp-block-group has-central-palette-5-background-color has-background\"><div class=\"wp-block-group__inner-container is-layout-constrained wp-block-group-is-layout-constrained\">\n<div class=\"wp-block-group\"><div class=\"wp-block-group__inner-container is-layout-constrained wp-block-group-is-layout-constrained\">\n<h2 class=\"wp-block-heading\"><strong>Looking for More CA-Related Content?<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.thesslstore.com\/blog\/how-to-become-a-certificate-authority\/\">How to Become a Certificate Authority (Public vs Private)<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.thesslstore.com\/blog\/setting-up-your-own-certificate-authority\/\">15 Steps for Setting Up Your Own Certificate Authority<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.thesslstore.com\/blog\/creating-your-own-certificate-authority-server\/\">Creating Your Own Certificate Authority Server<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.thesslstore.com\/blog\/what-is-a-ca-certificate-an-overview-of-these-key-pki-elements\/\">What Is a CA Certificate? An Overview of These Key PKI Elements<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.thesslstore.com\/blog\/what-is-caa-record-certificate-authority-authorization\/\">What Is a CAA Record? Your Guide to Certificate Authority Authorization<\/a><\/li>\n<\/ul>\n<\/div><\/div>\n<\/div><\/div>\n<\/div><\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"final-thoughts-on-certificate-authorities-and-why-they-matter\">Final Thoughts on Certificate Authorities and Why They Matter<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The internet is inherently insecure. It puts all of the world\u2019s information at your fingertips and offers an unparalleled level of convenience. But as you can imagine, all of those benefits don\u2019t come without a hefty price tag.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">All you have to do is look at news headlines to see that <a href=\"https:\/\/www.thesslstore.com\/blog\/cyber-security-statistics\/\">cyber attacks, data breaches, identity theft, and other threats and dangers<\/a> lurk everywhere. If you want to be able to surf the web or use its capabilities to benefit your ecommerce business, that\u2019s why you need to have a trusted third party on your side who can bring identity and trust to the table.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At their core, the job of CAs is to make the internet a more secure place for organizations and users. As such, they\u2019re responsible for:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Validating individuals and organizations,<\/li>\n\n\n\n<li>Issuing digital certificates that authenticate and facilitate encryption, and<\/li>\n\n\n\n<li>Maintaining the certificate revocation lists that web browsers and servers rely on to know which certificates are no longer legitimate.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.thesslstore.com\/blog\/33-alarming-cybercrime-statistics-you-should-know\/\">Cybercrime events and the costs associated with them<\/a> continue to increase with no end in sight. This is why it\u2019s crucial for every website \u2014 ecommerce sites in particular \u2014 to have an SSL\/TLS certificate from a trusted certificate authority. We hope this article provides you with a greater understanding of what a certificate authority is and what it does.<\/p>\n\n\n<span style=\"--tl-form-height-m:140.667px;--tl-form-height-t:118.1042px;--tl-form-height-d:118.1042px;\" class=\"tl-placeholder-f-type-shortcode_16373 tl-preload-form\"><span><\/span><\/span>","protected":false},"excerpt":{"rendered":"<p>Every time you visit a website that starts with HTTPS, you\u2019re using a certificate authority. But what exactly is a CA and how does it make your transactions and communications more secure? Let&#8217;s hash it out.<\/p>\n","protected":false},"author":17,"featured_media":12712,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":1,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[16,10200],"tags":[164],"class_list":["post-12689","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hashing-out-cyber-security","category-monthly-digest","tag-certificate-authorities","post-with-tags"],"views":117119,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/08\/what-is-a-certificate-authority.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/12689","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/17"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=12689"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/12689\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/12712"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=12689"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=12689"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=12689"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}