Definition · TLS & Certificates
What is Certificate Authority?
A certificate authority is the trusted third party in the public TLS system. It checks that an applicant controls the name being requested, then issues a certificate signing that name to a public key. Clients trust the certificate because they trust the CA that signed it — not because of anything the server itself asserts.
Roots, intermediates and trust stores
CAs keep their root keys offline and sign day-to-day certificates with intermediate CAs, producing the certificate chain a server presents. Only the root needs to be pre-installed on the client; the server supplies the intermediates. Those roots live in trust stores curated by browser and operating system vendors, each running its own root programme with its own admission and removal criteria. A CA that misbehaves can be distrusted, which has happened several times and invalidates every certificate it issued.
Validation levels
- Domain Validated (DV) — proves control of the domain only. Issued automatically, typically via ACME.
- Organisation Validated (OV) — adds vetted organisation details to the certificate.
- Extended Validation (EV) — a stricter organisational check. Browsers no longer give EV certificates distinct visual treatment, so their practical benefit is limited.
All three provide identical cryptographic protection. The difference is what was checked before issuance, not the strength of the connection.
Governance and issuance controls
Publicly trusted CAs operate under the CA/Browser Forum Baseline Requirements, which set validation methods, certificate contents and maximum lifetimes. Lifetimes have fallen steadily and the Forum has agreed a further phased reduction, which makes automated renewal a practical necessity rather than a convenience.
Two controls sit either side of issuance. CAA records are preventative: they name which CAs may issue for your domain, and compliant CAs must refuse otherwise. Certificate Transparency logs are detective: every certificate is logged publicly, so mis-issuance or an unauthorised certificate for your domain can be spotted after the fact. Monitoring CT logs is also a useful asset discovery technique, because certificates reveal hostnames that were never meant to be public.
Related concepts
See certificate revocation for withdrawing a certificate early, self-signed certificates for the no-CA case, OCSP, wildcard certificates, and TLS and certificates.