A certificate authority (CA) is a trusted organisation that issues digital certificates confirming who owns a website, domain, key or piece of software.
How certificate authorities work
A CA verifies the applicant and signs an X.509 certificate that binds a public key to a domain name, company or person. Browsers and operating systems ship a list of trusted root CAs. Roots are kept offline and sign intermediate CAs, which issue the certificates for websites. When you open an HTTPS site, the browser checks this chain of trust, the validity period and revocation status.
Certificates come in three validation levels: domain validation (DV), organisation validation (OV) and extended validation (EV). Let’s Encrypt made free, automated DV certificates the norm using the ACME protocol. Other large CAs include DigiCert, Sectigo and GlobalSign. Rules for public CAs are set by the CA/Browser Forum; certificate lifetimes, currently up to 398 days, will be shortened step by step to 47 days by 2029.
Why CAs matter for security
A CA that issues a certificate to the wrong party lets attackers impersonate any site. In 2011 the Dutch CA DigiNotar was hacked and fake Google certificates were used to spy on users in Iran; the CA went bankrupt. In 2018 browsers stopped trusting Symantec certificates after repeated mis-issuance. Since then, Certificate Transparency logs make every public certificate visible, so domain owners can spot rogue ones.
Best practices
- Automate certificate renewal (ACME) to prepare for shorter lifetimes.
- Monitor Certificate Transparency logs for certificates issued for your domains.
- Restrict which CAs may issue for your domain with DNS CAA records.
- Protect private keys and never install unknown root certificates on your devices.