{"id":1121,"date":"2020-06-23T08:56:00","date_gmt":"2020-06-23T08:56:00","guid":{"rendered":"https:\/\/sectigostore.com\/blog\/?p=1121"},"modified":"2020-06-23T13:13:09","modified_gmt":"2020-06-23T13:13:09","slug":"understanding-the-ssl-validation-process-with-faqs","status":"publish","type":"post","link":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/","title":{"rendered":"Understanding the SSL Validation Process with FAQs"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"explore-what-the-three-types-of-ssl-validation-are-and-learn-how-to-verify-whether-your-certificate\u2019s-validation-was-successful-on-your-site-and-how-to-validate-an-ssl-certificate-through-a-trusted-ca\">Explore what the three types of SSL validation are, and learn how to verify whether your certificate\u2019s validation was successful on your site and how to validate an SSL certificate through a trusted CA<\/h2>\n\n\n\n<p><em>\u201cHey, I just bought an SSL certificate for my domain name, but my website is still not showing the padlock sign. Is there a technical error in my certificate?&#8221;<\/em><\/p>\n\n\n\n<p>We hear this every day from customers who are buying SSL\/TLS certificates for the first time. When we inform them about the certificate signing request (CSR) generation, SSL validation and installation processes, they get flustered \u2014 which is quite normal. That\u2019s because they think it\u2019s going to be a painful and drawn-out process, but it\u2019s really not (as you\u2019ll soon discover).<\/p>\n\n\n\n<p>So, whether you\u2019ve already purchased an SSL certificate and looking for its activation procedures or are planning to buy new one, this article will help you navigate the entire <a href=\"https:\/\/sectigostore.com\/blog\/the-difference-between-authentication-and-authorization-explained-in-detail-by-a-security-expert\/\">SSL validation and authentication process<\/a>. For other two parts of the SSL activation steps, check out these two resources on <a href=\"https:\/\/help.sectigostore.com\/support\/solutions\/folders\/22000168634\">CSR generation<\/a> and <a href=\"https:\/\/help.sectigostore.com\/support\/solutions\/folders\/22000168667\">SSL certificate installation<\/a>.<\/p>\n\n\n\n<div class=\"wp-block-advanced-gutenberg-blocks-summary\"><p class=\"wp-block-advanced-gutenberg-blocks-summary__title\">Table of contents<\/p><div class=\"wp-block-advanced-gutenberg-blocks-summary__fold\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"24\" viewbox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"feather feather-chevron-up\"><polyline points=\"18 15 12 9 6 15\"><\/polyline><\/svg><\/div><ol role=\"directory\" class=\"wp-block-advanced-gutenberg-blocks-summary__list\"><li><a href=\"#explore-what-the-three-types-of-ssl-validation-are-and-learn-how-to-verify-whether-your-certificate\u2019s-validation-was-successful-on-your-site-and-how-to-validate-an-ssl-certificate-through-a-trusted-ca\">Explore what the three types of SSL validation are, and learn how to verify whether your certificate\u2019s validation was successful on your site and how to validate an SSL certificate through a trusted CA<\/a><ol><\/ol><\/li><li><a href=\"#what-is-ssl-validation\">What Is SSL Validation?<\/a><ol><li><a href=\"#the-3-types-of-ssl-validation-levels\">The 3 Types of SSL Validation Levels<\/a><ol><\/ol><\/li><\/ol><\/li><li><a href=\"#how-to-complete-the-ssl-authentication-process\">How to Complete the SSL Authentication Process<\/a><ol><li><a href=\"#breaking-down-the-domain-validation-process\">Breaking Down the Domain Validation Process<\/a><ol><li><a href=\"#1-email-verification\">1. Email Verification<\/a><ol><\/ol><\/li><li><a href=\"#2-file-verification\">2. File Verification<\/a><ol><\/ol><\/li><\/ol><\/li><li><a href=\"#breaking-down-the-organization-validation-process\">Breaking Down the Organization Validation Process<\/a><ol><li><a href=\"#1-complete-the-enrollment-form\">1. Complete the Enrollment Form<\/a><ol><\/ol><\/li><li><a href=\"#2-await-organization-authentication\">2. Await Organization Authentication:<\/a><ol><\/ol><\/li><li><a href=\"#3-prove-locality-presence\">3. Prove Locality Presence:<\/a><ol><\/ol><\/li><li><a href=\"#4-complete-telephone-verification\">4. Complete Telephone Verification<\/a><ol><\/ol><\/li><li><a href=\"#5-await-domain-authentication\">5. Await Domain Authentication<\/a><ol><\/ol><\/li><li><a href=\"#6-complete-the-final-verification-call\">6. Complete the Final Verification Call<\/a><ol><\/ol><\/li><\/ol><\/li><li><a href=\"#breaking-down-the-extended-validation-process\">Breaking Down the  Extended Validation Process<\/a><ol><li><a href=\"#what-we-mean-by-\u2018operational-existence\u2019\">What We Mean by \u2018Operational Existence\u2019 <\/a><ol><\/ol><\/li><\/ol><\/li><\/ol><\/li><li><a href=\"#ssl-validation-faqs\">SSL Validation FAQs<\/a><ol><\/ol><\/li><li><a href=\"#final-thoughts\">Final Thoughts<\/a><ol><\/ol><\/li><\/ol><\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"what-is-ssl-validation\">What Is SSL Validation?<\/h2>\n\n\n\n<p>There\u2019s going to be a two-part answer to this particular question.<\/p>\n\n\n\n<p>First, some people who search for answers to this question online are looking for something that\u2019s known as an <a href=\"https:\/\/sectigostore.com\/ssl-tools\/ssl-checker.php\">SSL certificate checker<\/a>. This tool is useful for trying to validate that a certificate is properly installed and that there aren\u2019t any issues from the installation process. For example, here\u2019s what it looks like when you search for a website using our SSL certificate checker:<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"525\" src=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/06\/ssl-validation-certificate-checker-1024x525.png\" alt=\"Graphic: A screenshot from the SSL validation certificate checker website.\" class=\"wp-image-1123 addshadow\" srcset=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/06\/ssl-validation-certificate-checker-1024x525.png 1024w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/06\/ssl-validation-certificate-checker-300x154.png 300w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/06\/ssl-validation-certificate-checker-560x287.png 560w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/06\/ssl-validation-certificate-checker-1536x788.png 1536w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/06\/ssl-validation-certificate-checker-940x482.png 940w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/06\/ssl-validation-certificate-checker.png 1920w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption>You can use SectigoStore.com&#8217;s SSL certificate checker tool to verify whether your SSL certificate was installed properly.<\/figcaption><\/figure><\/div>\n\n\n\n<p>The second reason why people ask this question is typically because they\u2019re trying to learn more about what SSL validation is in terms of the certificates themselves.<\/p>\n\n\n\n<p>When you buy an SSL certificate, it doesn&#8217;t get installed on your server automatically. You must prove the certificate authority (CA) you control the domain for which you have applied the certificate. <\/p>\n\n\n\n<p>For a business authenticated SSL certificate, the CA also verifies whether your website is backed by and belongs to a genuine business. The process of validating the domain ownership and business\u2019s genuineness is called SSL validation (also known as SSL authentication) process. <\/p>\n\n\n\n<p>To know the technical side of it, scroll down to the FAQ section.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"the-3-types-of-ssl-validation-levels\">The 3 Types of SSL Validation Levels<\/h3>\n\n\n\n<p>An SSL certificate can be classified into the three categories according to their validation requirements:<\/p>\n\n\n\n<p>1) <strong>Domain Validation (DV<\/strong>): This process enables you to prove domain ownership (and nothing else).<\/p>\n\n\n\n<p>2) <strong>Organization Validation (OV)<\/strong>: This process involves both DV and business authentication.<\/p>\n\n\n\n<p>3) <strong>Extended Validation (EV)<\/strong>: This process involves both domain and organization validation, plus your organization must be at least three years old and in good standing<\/p>\n\n\n\n<p>If you\u2019re not sure which SSL certificate (DV, OV, EV) you bought, please contact your certificate provider and ask them. In general, if there isn\u2019t any validation information stipulated on the certificate, it\u2019s a basic <a href=\"https:\/\/sectigostore.com\/ssl-types\/dv-ssl-certificates\">DV SSL certificate<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"how-to-complete-the-ssl-authentication-process\">How to Complete the SSL Authentication Process<\/h2>\n\n\n\n<p>Let\u2019s understand the steps involved in each type of SSL validation process.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"breaking-down-the-domain-validation-process\">Breaking Down the Domain Validation Process<\/h3>\n\n\n\n<p>This basic SSL validation type enables you to prove your domain ownership. The SSL certificates that require only domain validation are known as DV SSL certificates. Here, the CA verifies whether the public key (CSR code) you sent to the CA actually belongs to the server where the claimed website is hosted. There are two ways the CA verifies your ownership:<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"1-email-verification\">1. Email Verification<\/h4>\n\n\n\n<p>The CA sends you an email with a verification link on the email address that can be accessible to the legitimate person only. The link can be sent on one of these five (chosen by you) email addresses.<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Admin@yourdomain.com<\/li><li>Administrator@yourdomain.com<\/li><li>Webmaster@yourdomain.com<\/li><li>Hostmaster@yourdomain.com<\/li><li>Postmaster@yourdomain.com<\/li><\/ul>\n\n\n\n<p>They don&#8217;t send emails to generic Gmail, Yahoo, Hotmail email addresses. Once you receive the email, you just need to click on the verification link, and you\u2019re done!<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"2-file-verification\">2. File Verification<\/h4>\n\n\n\n<p>Here, the CA will send some files and instruct you to upload them to a specific folder within the root directory. If you can\u2019t get or afford an email address with your domain name from hosting company or Google suite, you can choose this option in lieu of the email SSL validation process.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"breaking-down-the-organization-validation-process\">Breaking Down the Organization Validation Process<\/h3>\n\n\n\n<p>If you buy an OV SSL certificate, you must follow all the steps of DV SSL certificate, plus go through an <a href=\"https:\/\/help.sectigostore.com\/support\/solutions\/articles\/22000218716-organization-validated-ov-\">additional business verification process<\/a>. This helps you to assert identity in a more profound way to help gain the trust of your site users.<\/p>\n\n\n\n<p>The OV requirements are as follow:<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"1-complete-the-enrollment-form\">1. Complete the Enrollment Form<\/h4>\n\n\n\n<p>After purchasing an OV SSL certificate, the CA will send you an enrollment form via email. You need to fill out the following details on the form:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>The company\u2019s registration information.<\/li><li>The organization&#8217;s name, if your organization is working under trade names, assumed names, or DBAs, you must clarify the same in the form.<\/li><li>The organization\u2019s locality information (same as in registration papers) that shows it has a physical presence in a specific city, state or country.<\/li><li>An official phone number to contact the organization directly.<\/li><li>The full name of the organizational contact and their official title.<\/li><li>The organizational contact&#8217;s signature and the date and place of signing.<\/li><\/ul>\n\n\n\n<p>You&#8217;ll have to print the form out, sign it, and then either scan or fax the document back to the CA. (No electronic transfer is allowed)<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"2-await-organization-authentication\">2. Await Organization Authentication:<\/h4>\n\n\n\n<p>The CA\u2019s staff will manually check whether your organization is registered and active within your territory. They will check online government databases in your local municipality, state, or country that publicly displays your business entity\u2019s registration status. If all the details match and that CA is satisfied, you\u2019re good to go.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"3-prove-locality-presence\">3. Prove Locality Presence:<\/h4>\n\n\n\n<p>The CA will verify whether your company has an active legal, physical presence in its registered location. They will check the relevant online government database to verify the registration details \u2013 the city\/state\/country of your company.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"4-complete-telephone-verification\">4. Complete Telephone Verification<\/h4>\n\n\n\n<p>CA will verify the phone number that you have listed in the enrolment form by checking online government databases. If they can\u2019t verify your number from there, they will check online phone directly or third-party directory such as Kompass, Infobel, Yellow Pages, etc. The listing must display the exact same business name and physical address as they have already had verified.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"5-await-domain-authentication\">5. Await Domain Authentication<\/h4>\n\n\n\n<p>By this time, you\u2019ve completed all the steps of domain verification (email or file verification). However, there are some additional steps involved with organization validation. Here, the CA will check the <a href=\"https:\/\/www.whois.net\/\" target=\"_blank\" rel=\"noreferrer noopener\">WHOIS records<\/a> to verify that your company owns the domain.<\/p>\n\n\n\n<p>However, most of the hosting companies offer a service named \u201cdomain privacy\u201d for a small fee to hide your information from WHOIS records. If you have opted for that service, you must request your hosting provider to keep your WHOIS records open until your SSL authentication is completed.<\/p>\n\n\n\n<p><strong>Important Note<\/strong>: If there\u2019s any discrepancy in the information \u2014 if the CA finds something fishy while SSL authentication process in the above three verifications \u2014 or If you want to keep WHOIS records private, you will be asked to provide one of the following.<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Official registration documents<\/li><li>Dun &amp; Bradstreet credit report<\/li><li>Legal Opinion Letters, or Professional Opinion Letters (POLs) obtained by a lawyer or an accountant<\/li><\/ul>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"6-complete-the-final-verification-call\">6. Complete the Final Verification Call<\/h4>\n\n\n\n<p>The CA will call on your office number and talk to an authorized person (or the one that applied for the SSL certificate) to confirm the details of the order. If you don&#8217;t have a direct number and use extensions or Interactive Voice Response (IVR), the CA will reach out to you using them, too.<\/p>\n\n\n\n<p>If all these 6 SSL verification steps are completed successfully, the CA will issue you an OV SSL certificate.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"breaking-down-the-extended-validation-process\">Breaking Down the  Extended Validation Process<\/h3>\n\n\n\n<p>There is a thin line between organization validation and <a href=\"https:\/\/help.sectigostore.com\/support\/solutions\/articles\/22000218717-extended-validation-ev-\">extended validation<\/a> as far as the verification process is a concern. You need to go through all the steps of DV and OV \u2014 but after that, you must prove your organization\u2019s operational existence.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"what-we-mean-by-\u2018operational-existence\u2019\">What We Mean by \u2018Operational Existence\u2019 <em><\/em><\/h4>\n\n\n\n<p>The CA must confirm that your company has been operating in the market for <strong>three<\/strong> or more years. Once again, the CA will verify your company&#8217;s operational existence just by checking an online government database \u2014 either in your local municipality, state, or country \u2014 that displays your incorporation date.<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>If your company is situated in a place whose municipality doesn&#8217;t keep online records, you need to provide <strong>official registration documents<\/strong> in which the date of incorporation is mentioned.<\/li><li>If your company is <strong>younger than three years<\/strong> but it\u2019s well-established and in good standing, you can still get an EV SSL certificate. All you need to do is provide additional documents such as:<ul><li>Dun &amp; Bradstreet credit report,<\/li><\/ul><ul><li>A legal opinion letter, or a<\/li><\/ul><ul><li>Confirmation letter from the bank in which your organization has an active checking account.<\/li><\/ul><\/li><\/ul>\n\n\n\n<p><strong><em>Note:<\/em><\/strong><em> You don\u2019t need to provide all the documents. Generally, the CA will let you know which documents you need to provide. The requirement varies on a case-by-case basis.<\/em><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"ssl-validation-faqs\">SSL Validation FAQs<\/h2>\n\n\n\n<p>Now, we\u2019d like to take a few moments to answer some of the most commonly asked questions relating to SSL validation.<\/p>\n\n\n\n<div class=\"schema-faq wp-block-yoast-faq-block\"><div class=\"schema-faq-section\" id=\"faq-question-1592848512065\"><strong class=\"schema-faq-question\">Which type of SSL certificate should I buy?<\/strong> <p class=\"schema-faq-answer\"><strong>Domain validation<\/strong>: <a href=\"https:\/\/sectigostore.com\/ssl-types\/dv-ssl-certificates\">DV SSL validation certificates<\/a> are ideal for blogs, personal websites, small-business websites, and informative sites. Basically, any website that doesn\u2019t deal with customers\u2019 financial information (payment card numbers) or sensitive details.<br\/><br\/><strong>Organizational validation<\/strong>: <a href=\"https:\/\/sectigostore.com\/ssl-types\/ov-ssl-certificates\">OV SSL validation certificates<\/a> are best suited for non-profits, educational institutes, medium scale businesses, and ecommerce websites as a minimum. Basically, any businesses or organizations that deal with their users\u2019 sensitive information.<br\/><br\/><strong>Extended validation<\/strong>: <a href=\"https:\/\/sectigostore.com\/ssl-types\/ev-ssl-certificates\">EV SSL validation certificates<\/a> are best suited for healthcare institutions, eCommerce websites, military\/government websites, large scale enterprises with high traffic, etc. If you\u2019re dealing with your customers&#8217; financial information or sensitive healthcare information, transferring internal information such as trade secrets, employee&#8217;s personally identifiable information (PII), sensitive political and government-related information, then you should be using an EV SSL certificate to provide the highest level of validation and authentication.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1592849257496\"><strong class=\"schema-faq-question\">What if I\u2019m running an online store but don\u2019t qualify for an OV or EV SSL certificate?<\/strong> <p class=\"schema-faq-answer\">These days, people start and operate their online businesses from home. It\u2019s quite common for businesses that deal in homemade products, designer clothes, artwork, accessories, etc. These businesses frequently have neither an office nor registration with the government. If that is the case, you have to go for domain validated (DV) SSL certificates only. It would be risky, but it&#8217;s not illegal (yet) to use DV certs for websites handling users&#8217; financial information. But as soon as you register your business, don&#8217;t forget to switch your SSL certificate from DV to OV.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1592849339966\"><strong class=\"schema-faq-question\">What is the price difference among all three SSL authentications?<\/strong> <p class=\"schema-faq-answer\">DV SSL certificates are the cheapest. They cost as little as <a href=\"https:\/\/sectigostore.com\/ssl-certificates\/positivessl\">$8.78\/year<\/a>.<br\/><br\/>OV has a medium-priced range, with a starting price of <a href=\"https:\/\/sectigostore.com\/ssl-certificates\/instantssl\">$30.80\/year<\/a>.<br\/><br\/>EV SSL certificates are the most expensive ones, which starts from <a href=\"https:\/\/sectigostore.com\/ssl-certificates\/positivessl-ev\">$79.84<\/a>.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1592849376962\"><strong class=\"schema-faq-question\">Is there any hidden SSL authentication cost for business validated SSL certificates?<\/strong> <p class=\"schema-faq-answer\">No. CAs aren\u2019t going to charge you anything extra for the validation process. The cost of SSL authentication is, by default, included in the certificate\u2019s price. That\u2019s why they are more expensive than DV SSL certificates. Even if your data is not up to date on the online government directories and the CA needs to go the extra mile to request and vet the physical documents, there\u2019s no additional charges or penalties. This responsibility is just par the course for CAs, and they understand that and calculate that in their SSL certificate prices.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1592849407043\"><strong class=\"schema-faq-question\">How much time does SSL validation take?<\/strong> <p class=\"schema-faq-answer\"><strong>Domain validation<\/strong>: Within minutes. (Basically, as soon as you click on the verification link or place the files on the root directory.)<br\/><br\/><strong>Organization Validation<\/strong>: 1-3 days.<br\/><br\/><strong>Extended Validation<\/strong>: 1-5 days.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1592849456138\"><strong class=\"schema-faq-question\">How long is SSL authentication valid?<\/strong> <p class=\"schema-faq-answer\">You must renew your SSL certificate after two years and go through the SSL validation process again at the time of renewal \u2014 although this <a href=\"https:\/\/www.thesslstore.com\/blog\/ssl-certificate-validity-will-be-limited-to-one-year-by-apples-safari-browser\/\">changes to one year<\/a> starting Sept. 1, 2020. So, for example, even if you have bought an SSL certificate for five years, according to the <a rel=\"noreferrer noopener\" href=\"http:\/\/cabforum.org\" target=\"_blank\">CA\/B Forum<\/a>&#8216;s guidelines, you must reissue it after two years (i.e., you must go through CSR generation, SSL validation, and installation process once again).<br\/><br\/>However, it\u2019s important to note that if you haven&#8217;t changed your certificate authority and business information (physical address, phone numbers, etc.), this second OV\/EV process will be way quicker than the first time around. Of course, using a <a href=\"https:\/\/sectigostore.com\/enterprise\">reliable certificate manager also can help enterprises<\/a> with managing all of their SSL certificates (and other digital certificates) at scale.<br\/><br\/>Also, the same rule applies to all the CAs regardless of which brand you choose. So, if a CA, reseller, or hosting site tells you different, they\u2019re providing you with the wrong information that can <a href=\"https:\/\/www.thesslstore.com\/blog\/what-happens-when-your-ssl-certificate-expires\/\" target=\"_blank\" rel=\"noreferrer noopener\">result in downtime or costly non-compliance penalties<\/a>.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1592849502163\"><strong class=\"schema-faq-question\">Will I get a green address bar with an extended validated SSL certificate?<\/strong> <p class=\"schema-faq-answer\">Yes and no! Some browsers, such as Internet Explorer, Safari, Microsoft Edge, and Opera, are still showing a green bar (organization&#8217;s legally registered name on the address bar in the green color).<br\/><img loading=\"lazy\" decoding=\"async\" width=\"484\" height=\"48\" src=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/06\/ssl-validation-wells-fargo-padlock.png\" class=\"attachment-full size-full\" alt=\"Graphic: Screenshot of the SSL validation security padlock for the official Wells Fargo website\" style=\"max-width: 100%; height: auto;\" srcset=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/06\/ssl-validation-wells-fargo-padlock.png 484w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/06\/ssl-validation-wells-fargo-padlock-300x30.png 300w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/06\/ssl-validation-wells-fargo-padlock-480x48.png 480w\" sizes=\"auto, (max-width: 484px) 100vw, 484px\" \/><br\/>Google Chrome and Firefox have recently changed their policies for the green bar, and now they are showing the organization&#8217;s name on the certificate itself. Anyone can see it after clicking on the padlock sign:<br\/><img loading=\"lazy\" decoding=\"async\" width=\"541\" height=\"347\" src=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/06\/ssl-validation-security-padlock-google-chrome.png\" class=\"attachment-full size-full\" alt=\"A screenshot of SSL validation information for Wells Fargo as an organization using an EV SSL certificate\" style=\"max-width: 100%; height: auto;\" srcset=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/06\/ssl-validation-security-padlock-google-chrome.png 541w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/06\/ssl-validation-security-padlock-google-chrome-300x192.png 300w\" sizes=\"auto, (max-width: 541px) 100vw, 541px\" \/><\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1592849950886\"><strong class=\"schema-faq-question\">What happens if my business can\u2019t pass the business validation process?<\/strong> <p class=\"schema-faq-answer\">If a CA finds anything fishy while validating your company\u2019s information, they won\u2019t issue an SSL certificate to your website. But that happens only in rare cases for legitimate businesses. If your business is genuine and all the information you have provided is accurate, you don\u2019t need to worry about anything.<br\/><br\/>The general rule is that if a CA denies issuing you the certificate, you generally lose your money. <strong>But<\/strong> <strong>if you have bought your certificate from SectigoStore, we will give you 100% money-back if you encounter any issues within 30 days of the purchase.\u00a0<\/strong><\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1592849983634\"><strong class=\"schema-faq-question\">Who should I contact if I run into some issues during the SSL validation process?<\/strong> <p class=\"schema-faq-answer\">If you have bought a Sectigo SSL certificate from SectigoStore.com, you can either contact our <a href=\"https:\/\/sectigostore.com\/contact\">customer care<\/a> team or <a href=\"https:\/\/sectigo.com\/support\">Sectigo CA<\/a> directly. At SectigoStore.com, we provide 24\/7 live customer support via chat, phone, and emails.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1592849999989\"><strong class=\"schema-faq-question\">What if the CA makes any errors in the validation process?<\/strong> <p class=\"schema-faq-answer\">If that happens, the SSL warranty comes handy. The below is Sectigo\u2019s policy for warranty:<br\/><br\/><em>\u201cShould we fail to properly validate the information contained in a digital certificate and our failure causes the end-user to lose money (in connection with a fraudulent online credit card transaction), then the end-user may have a claim to recovery under our certificate warranty.\u201d<\/em><br\/><br\/>For more details, check out <a href=\"https:\/\/support.sectigo.com\/Com_KnowledgeDetailPage?Id=kA01N000000zFS5\" target=\"_blank\" rel=\"noreferrer noopener\">Sectigo\u2019s Warranty Guidelines<\/a>.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1592850043577\"><strong class=\"schema-faq-question\">Is SSL validation compulsory? Can I omit the authentication step?<\/strong> <p class=\"schema-faq-answer\">According to the CA\/B Forum&#8217;s regulations, SSL authentication is mandatory, and hence, no legit CA can issue you an SSL certificate before you complete the validation process.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1592850056837\"><strong class=\"schema-faq-question\">What role does SSL validation play in website security?<\/strong> <p class=\"schema-faq-answer\">Anyone can buy an SSL certificate for any domain they want! It\u2019s the SSL authentication process where you have to prove that you actually control the domain and represent a genuine business to the CA.<br\/><br\/>When a CA issues an SSL certificate to your domain name, it ties your server&#8217;s public key to a hostname (i.e., a domain name). So, for example, when a CA issues an SSL certificate for amazon.com, it attaches Amazon&#8217;s server&#8217;s public to the certificate and writes &#8220;hostname&#8221; as &#8220;amazon.com&#8221; on it. Now, when someone tries to open amazon.com, their browser simply checks the website&#8217;s SSL certificate and redirects all the traffic to amazon\u2019s server. Only Amazon\u2019s server can decrypt the traffic because it has the unique corresponding private keys.<br\/><br\/>As you can see, attaching the right public key to the right hostname is a crucial thing. If the CA ties the wrong server&#8217;s public key, all the traffic will be redirected to the wrong server. Now how would the CA know your domain\u2019s public key? Because you\u2019ll send it to the CA during the CSR generation process.<br\/><br\/>So, how would CA know whether the public key provided by you actually belongs to the domain you control? Here\u2019s where the SSL validation comes into the play. It&#8217;s only through the validation process that the CA gets an idea of whether you are providing them the right public key.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1592850092073\"><strong class=\"schema-faq-question\">What is the CA\u2019s risk in the SSL validation process?<\/strong> <p class=\"schema-faq-answer\">Once the CA attaches the public key to a hostname, it signs the SSL certificate with its own intermediate root certificate&#8217;s private key. This means that the CA vouches for the authenticity of the SSL certificate. The web browser simply checks the CA&#8217;s signature from its trusted root store and trusts the certificate and the details it contains.<br\/><br\/>Hence, if the CA makes a mistake in attaching the keys, and if someone suffers from the financial loss due to such a mistake, the CA must reimburse the legal penalty up to the warranty amount to the victim.<\/p> <\/div> <\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"final-thoughts\">Final Thoughts<\/h2>\n\n\n\n<p>SSL cert validation is there for your domain and website visitors\u2019 security reasons. No browsers will trust your website\u2019s SSL certificate if you buy a certificate that doesn\u2019t require any sort of validity for example: self-signed certificates. And as we said earlier, you will receive all the needed support from us if you got stuck at any part of the SSL validation process.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Explore what the three types of SSL validation are, and learn how to verify whether your certificate\u2019s validation was successful on your site and how to validate an SSL certificate&#8230;<\/p>\n","protected":false},"author":6,"featured_media":1130,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[13],"tags":[85],"class_list":["post-1121","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cyber-security","tag-ssl-validation","post-with-tags"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Understanding the SSL Validation Process with FAQs - InfoSec Insights<\/title>\n<meta name=\"description\" content=\"What is SSL validation? How do you verify your site&#039;s certificate validation was successful? Here&#039;s what to know about how to validate your SSL certificate.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Understanding the SSL Validation Process with FAQs - InfoSec Insights\" \/>\n<meta property=\"og:description\" content=\"What is SSL validation? How do you verify your site&#039;s certificate validation was successful? Here&#039;s what to know about how to validate your SSL certificate.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/\" \/>\n<meta property=\"og:site_name\" content=\"InfoSec Insights\" \/>\n<meta property=\"article:published_time\" content=\"2020-06-23T08:56:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-06-23T13:13:09+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/06\/ssl-validation-sectigostore-website.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1600\" \/>\n\t<meta property=\"og:image:height\" content=\"1000\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Medha Mehta\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Medha Mehta\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"15 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/\"},\"author\":{\"name\":\"Medha Mehta\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/#\\\/schema\\\/person\\\/41d095943b7798ade1bc3683c8822f15\"},\"headline\":\"Understanding the SSL Validation Process with FAQs\",\"datePublished\":\"2020-06-23T08:56:00+00:00\",\"dateModified\":\"2020-06-23T13:13:09+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/\"},\"wordCount\":3141,\"image\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/06\\\/ssl-validation-sectigostore-website.jpg\",\"keywords\":[\"SSL validation\"],\"articleSection\":[\"Cyber Security\"],\"inLanguage\":\"en-US\"},{\"@type\":[\"WebPage\",\"FAQPage\"],\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/\",\"url\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/\",\"name\":\"Understanding the SSL Validation Process with FAQs - InfoSec Insights\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/06\\\/ssl-validation-sectigostore-website.jpg\",\"datePublished\":\"2020-06-23T08:56:00+00:00\",\"dateModified\":\"2020-06-23T13:13:09+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/#\\\/schema\\\/person\\\/41d095943b7798ade1bc3683c8822f15\"},\"description\":\"What is SSL validation? How do you verify your site's certificate validation was successful? Here's what to know about how to validate your SSL certificate.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#breadcrumb\"},\"mainEntity\":[{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#faq-question-1592848512065\"},{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#faq-question-1592849257496\"},{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#faq-question-1592849339966\"},{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#faq-question-1592849376962\"},{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#faq-question-1592849407043\"},{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#faq-question-1592849456138\"},{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#faq-question-1592849502163\"},{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#faq-question-1592849950886\"},{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#faq-question-1592849983634\"},{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#faq-question-1592849999989\"},{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#faq-question-1592850043577\"},{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#faq-question-1592850056837\"},{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#faq-question-1592850092073\"}],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#primaryimage\",\"url\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/06\\\/ssl-validation-sectigostore-website.jpg\",\"contentUrl\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/06\\\/ssl-validation-sectigostore-website.jpg\",\"width\":1600,\"height\":1000},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Understanding the SSL Validation Process with FAQs\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/\",\"name\":\"InfoSec Insights\",\"description\":\"SectigoStore.com Blog\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/#\\\/schema\\\/person\\\/41d095943b7798ade1bc3683c8822f15\",\"name\":\"Medha Mehta\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a1e5b5025e87d4e1acfd683fbede8c366e652e9ddb2164b7a0d0a77e2d9da727?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a1e5b5025e87d4e1acfd683fbede8c366e652e9ddb2164b7a0d0a77e2d9da727?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a1e5b5025e87d4e1acfd683fbede8c366e652e9ddb2164b7a0d0a77e2d9da727?s=96&d=mm&r=g\",\"caption\":\"Medha Mehta\"},\"description\":\"Medha is a regular contributor to InfoSec Insights. She's a tech enthusiast and writes about technology, website security, cryptography, cyber security, and data protection.\",\"sameAs\":[\"https:\\\/\\\/sectigostore.com\\\/\"]},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#faq-question-1592848512065\",\"position\":1,\"url\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#faq-question-1592848512065\",\"name\":\"Which type of SSL certificate should I buy?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"<strong>Domain validation<\\\/strong>: <a href=\\\"https:\\\/\\\/sectigostore.com\\\/ssl-types\\\/dv-ssl-certificates\\\">DV SSL validation certificates<\\\/a> are ideal for blogs, personal websites, small-business websites, and informative sites. Basically, any website that doesn\u2019t deal with customers\u2019 financial information (payment card numbers) or sensitive details.<br\\\/><br\\\/><strong>Organizational validation<\\\/strong>: <a href=\\\"https:\\\/\\\/sectigostore.com\\\/ssl-types\\\/ov-ssl-certificates\\\">OV SSL validation certificates<\\\/a> are best suited for non-profits, educational institutes, medium scale businesses, and ecommerce websites as a minimum. Basically, any businesses or organizations that deal with their users\u2019 sensitive information.<br\\\/><br\\\/><strong>Extended validation<\\\/strong>: <a href=\\\"https:\\\/\\\/sectigostore.com\\\/ssl-types\\\/ev-ssl-certificates\\\">EV SSL validation certificates<\\\/a> are best suited for healthcare institutions, eCommerce websites, military\\\/government websites, large scale enterprises with high traffic, etc. If you\u2019re dealing with your customers' financial information or sensitive healthcare information, transferring internal information such as trade secrets, employee's personally identifiable information (PII), sensitive political and government-related information, then you should be using an EV SSL certificate to provide the highest level of validation and authentication.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#faq-question-1592849257496\",\"position\":2,\"url\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#faq-question-1592849257496\",\"name\":\"What if I\u2019m running an online store but don\u2019t qualify for an OV or EV SSL certificate?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"These days, people start and operate their online businesses from home. It\u2019s quite common for businesses that deal in homemade products, designer clothes, artwork, accessories, etc. These businesses frequently have neither an office nor registration with the government. If that is the case, you have to go for domain validated (DV) SSL certificates only. It would be risky, but it's not illegal (yet) to use DV certs for websites handling users' financial information. But as soon as you register your business, don't forget to switch your SSL certificate from DV to OV.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#faq-question-1592849339966\",\"position\":3,\"url\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#faq-question-1592849339966\",\"name\":\"What is the price difference among all three SSL authentications?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"DV SSL certificates are the cheapest. They cost as little as <a href=\\\"https:\\\/\\\/sectigostore.com\\\/ssl-certificates\\\/positivessl\\\">$8.78\\\/year<\\\/a>.<br\\\/><br\\\/>OV has a medium-priced range, with a starting price of <a href=\\\"https:\\\/\\\/sectigostore.com\\\/ssl-certificates\\\/instantssl\\\">$30.80\\\/year<\\\/a>.<br\\\/><br\\\/>EV SSL certificates are the most expensive ones, which starts from <a href=\\\"https:\\\/\\\/sectigostore.com\\\/ssl-certificates\\\/positivessl-ev\\\">$79.84<\\\/a>.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#faq-question-1592849376962\",\"position\":4,\"url\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#faq-question-1592849376962\",\"name\":\"Is there any hidden SSL authentication cost for business validated SSL certificates?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"No. CAs aren\u2019t going to charge you anything extra for the validation process. The cost of SSL authentication is, by default, included in the certificate\u2019s price. That\u2019s why they are more expensive than DV SSL certificates. Even if your data is not up to date on the online government directories and the CA needs to go the extra mile to request and vet the physical documents, there\u2019s no additional charges or penalties. This responsibility is just par the course for CAs, and they understand that and calculate that in their SSL certificate prices.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#faq-question-1592849407043\",\"position\":5,\"url\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#faq-question-1592849407043\",\"name\":\"How much time does SSL validation take?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"<strong>Domain validation<\\\/strong>: Within minutes. (Basically, as soon as you click on the verification link or place the files on the root directory.)<br\\\/><br\\\/><strong>Organization Validation<\\\/strong>: 1-3 days.<br\\\/><br\\\/><strong>Extended Validation<\\\/strong>: 1-5 days.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#faq-question-1592849456138\",\"position\":6,\"url\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#faq-question-1592849456138\",\"name\":\"How long is SSL authentication valid?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"You must renew your SSL certificate after two years and go through the SSL validation process again at the time of renewal \u2014 although this <a href=\\\"https:\\\/\\\/www.thesslstore.com\\\/blog\\\/ssl-certificate-validity-will-be-limited-to-one-year-by-apples-safari-browser\\\/\\\">changes to one year<\\\/a> starting Sept. 1, 2020. So, for example, even if you have bought an SSL certificate for five years, according to the <a rel=\\\"noreferrer noopener\\\" href=\\\"http:\\\/\\\/cabforum.org\\\" target=\\\"_blank\\\">CA\\\/B Forum<\\\/a>'s guidelines, you must reissue it after two years (i.e., you must go through CSR generation, SSL validation, and installation process once again).<br\\\/><br\\\/>However, it\u2019s important to note that if you haven't changed your certificate authority and business information (physical address, phone numbers, etc.), this second OV\\\/EV process will be way quicker than the first time around. Of course, using a <a href=\\\"https:\\\/\\\/sectigostore.com\\\/enterprise\\\">reliable certificate manager also can help enterprises<\\\/a> with managing all of their SSL certificates (and other digital certificates) at scale.<br\\\/><br\\\/>Also, the same rule applies to all the CAs regardless of which brand you choose. So, if a CA, reseller, or hosting site tells you different, they\u2019re providing you with the wrong information that can <a href=\\\"https:\\\/\\\/www.thesslstore.com\\\/blog\\\/what-happens-when-your-ssl-certificate-expires\\\/\\\" target=\\\"_blank\\\" rel=\\\"noreferrer noopener\\\">result in downtime or costly non-compliance penalties<\\\/a>.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#faq-question-1592849502163\",\"position\":7,\"url\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#faq-question-1592849502163\",\"name\":\"Will I get a green address bar with an extended validated SSL certificate?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Yes and no! Some browsers, such as Internet Explorer, Safari, Microsoft Edge, and Opera, are still showing a green bar (organization's legally registered name on the address bar in the green color).<br\\\/><br\\\/>Google Chrome and Firefox have recently changed their policies for the green bar, and now they are showing the organization's name on the certificate itself. Anyone can see it after clicking on the padlock sign:<br\\\/>\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#faq-question-1592849950886\",\"position\":8,\"url\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#faq-question-1592849950886\",\"name\":\"What happens if my business can\u2019t pass the business validation process?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"If a CA finds anything fishy while validating your company\u2019s information, they won\u2019t issue an SSL certificate to your website. But that happens only in rare cases for legitimate businesses. If your business is genuine and all the information you have provided is accurate, you don\u2019t need to worry about anything.<br\\\/><br\\\/>The general rule is that if a CA denies issuing you the certificate, you generally lose your money. <strong>But<\\\/strong> <strong>if you have bought your certificate from SectigoStore, we will give you 100% money-back if you encounter any issues within 30 days of the purchase.\u00a0<\\\/strong>\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#faq-question-1592849983634\",\"position\":9,\"url\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#faq-question-1592849983634\",\"name\":\"Who should I contact if I run into some issues during the SSL validation process?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"If you have bought a Sectigo SSL certificate from SectigoStore.com, you can either contact our <a href=\\\"https:\\\/\\\/sectigostore.com\\\/contact\\\">customer care<\\\/a> team or <a href=\\\"https:\\\/\\\/sectigo.com\\\/support\\\">Sectigo CA<\\\/a> directly. At SectigoStore.com, we provide 24\\\/7 live customer support via chat, phone, and emails.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#faq-question-1592849999989\",\"position\":10,\"url\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#faq-question-1592849999989\",\"name\":\"What if the CA makes any errors in the validation process?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"If that happens, the SSL warranty comes handy. The below is Sectigo\u2019s policy for warranty:<br\\\/><br\\\/><em>\u201cShould we fail to properly validate the information contained in a digital certificate and our failure causes the end-user to lose money (in connection with a fraudulent online credit card transaction), then the end-user may have a claim to recovery under our certificate warranty.\u201d<\\\/em><br\\\/><br\\\/>For more details, check out <a href=\\\"https:\\\/\\\/support.sectigo.com\\\/Com_KnowledgeDetailPage?Id=kA01N000000zFS5\\\" target=\\\"_blank\\\" rel=\\\"noreferrer noopener\\\">Sectigo\u2019s Warranty Guidelines<\\\/a>.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#faq-question-1592850043577\",\"position\":11,\"url\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#faq-question-1592850043577\",\"name\":\"Is SSL validation compulsory? Can I omit the authentication step?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"According to the CA\\\/B Forum's regulations, SSL authentication is mandatory, and hence, no legit CA can issue you an SSL certificate before you complete the validation process.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#faq-question-1592850056837\",\"position\":12,\"url\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#faq-question-1592850056837\",\"name\":\"What role does SSL validation play in website security?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Anyone can buy an SSL certificate for any domain they want! It\u2019s the SSL authentication process where you have to prove that you actually control the domain and represent a genuine business to the CA.<br\\\/><br\\\/>When a CA issues an SSL certificate to your domain name, it ties your server's public key to a hostname (i.e., a domain name). So, for example, when a CA issues an SSL certificate for amazon.com, it attaches Amazon's server's public to the certificate and writes \\\"hostname\\\" as \\\"amazon.com\\\" on it. Now, when someone tries to open amazon.com, their browser simply checks the website's SSL certificate and redirects all the traffic to amazon\u2019s server. Only Amazon\u2019s server can decrypt the traffic because it has the unique corresponding private keys.<br\\\/><br\\\/>As you can see, attaching the right public key to the right hostname is a crucial thing. If the CA ties the wrong server's public key, all the traffic will be redirected to the wrong server. Now how would the CA know your domain\u2019s public key? Because you\u2019ll send it to the CA during the CSR generation process.<br\\\/><br\\\/>So, how would CA know whether the public key provided by you actually belongs to the domain you control? Here\u2019s where the SSL validation comes into the play. It's only through the validation process that the CA gets an idea of whether you are providing them the right public key.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#faq-question-1592850092073\",\"position\":13,\"url\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/understanding-the-ssl-validation-process-with-faqs\\\/#faq-question-1592850092073\",\"name\":\"What is the CA\u2019s risk in the SSL validation process?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Once the CA attaches the public key to a hostname, it signs the SSL certificate with its own intermediate root certificate's private key. This means that the CA vouches for the authenticity of the SSL certificate. The web browser simply checks the CA's signature from its trusted root store and trusts the certificate and the details it contains.<br\\\/><br\\\/>Hence, if the CA makes a mistake in attaching the keys, and if someone suffers from the financial loss due to such a mistake, the CA must reimburse the legal penalty up to the warranty amount to the victim.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Understanding the SSL Validation Process with FAQs - InfoSec Insights","description":"What is SSL validation? How do you verify your site's certificate validation was successful? Here's what to know about how to validate your SSL certificate.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/","og_locale":"en_US","og_type":"article","og_title":"Understanding the SSL Validation Process with FAQs - InfoSec Insights","og_description":"What is SSL validation? How do you verify your site's certificate validation was successful? Here's what to know about how to validate your SSL certificate.","og_url":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/","og_site_name":"InfoSec Insights","article_published_time":"2020-06-23T08:56:00+00:00","article_modified_time":"2020-06-23T13:13:09+00:00","og_image":[{"width":1600,"height":1000,"url":"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/06\/ssl-validation-sectigostore-website.jpg","type":"image\/jpeg"}],"author":"Medha Mehta","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Medha Mehta","Est. reading time":"15 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#article","isPartOf":{"@id":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/"},"author":{"name":"Medha Mehta","@id":"https:\/\/sectigostore.com\/blog\/#\/schema\/person\/41d095943b7798ade1bc3683c8822f15"},"headline":"Understanding the SSL Validation Process with FAQs","datePublished":"2020-06-23T08:56:00+00:00","dateModified":"2020-06-23T13:13:09+00:00","mainEntityOfPage":{"@id":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/"},"wordCount":3141,"image":{"@id":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#primaryimage"},"thumbnailUrl":"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/06\/ssl-validation-sectigostore-website.jpg","keywords":["SSL validation"],"articleSection":["Cyber Security"],"inLanguage":"en-US"},{"@type":["WebPage","FAQPage"],"@id":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/","url":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/","name":"Understanding the SSL Validation Process with FAQs - InfoSec Insights","isPartOf":{"@id":"https:\/\/sectigostore.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#primaryimage"},"image":{"@id":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#primaryimage"},"thumbnailUrl":"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/06\/ssl-validation-sectigostore-website.jpg","datePublished":"2020-06-23T08:56:00+00:00","dateModified":"2020-06-23T13:13:09+00:00","author":{"@id":"https:\/\/sectigostore.com\/blog\/#\/schema\/person\/41d095943b7798ade1bc3683c8822f15"},"description":"What is SSL validation? How do you verify your site's certificate validation was successful? Here's what to know about how to validate your SSL certificate.","breadcrumb":{"@id":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#breadcrumb"},"mainEntity":[{"@id":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#faq-question-1592848512065"},{"@id":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#faq-question-1592849257496"},{"@id":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#faq-question-1592849339966"},{"@id":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#faq-question-1592849376962"},{"@id":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#faq-question-1592849407043"},{"@id":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#faq-question-1592849456138"},{"@id":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#faq-question-1592849502163"},{"@id":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#faq-question-1592849950886"},{"@id":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#faq-question-1592849983634"},{"@id":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#faq-question-1592849999989"},{"@id":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#faq-question-1592850043577"},{"@id":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#faq-question-1592850056837"},{"@id":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#faq-question-1592850092073"}],"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#primaryimage","url":"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/06\/ssl-validation-sectigostore-website.jpg","contentUrl":"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/06\/ssl-validation-sectigostore-website.jpg","width":1600,"height":1000},{"@type":"BreadcrumbList","@id":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/sectigostore.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Understanding the SSL Validation Process with FAQs"}]},{"@type":"WebSite","@id":"https:\/\/sectigostore.com\/blog\/#website","url":"https:\/\/sectigostore.com\/blog\/","name":"InfoSec Insights","description":"SectigoStore.com Blog","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/sectigostore.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/sectigostore.com\/blog\/#\/schema\/person\/41d095943b7798ade1bc3683c8822f15","name":"Medha Mehta","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a1e5b5025e87d4e1acfd683fbede8c366e652e9ddb2164b7a0d0a77e2d9da727?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a1e5b5025e87d4e1acfd683fbede8c366e652e9ddb2164b7a0d0a77e2d9da727?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a1e5b5025e87d4e1acfd683fbede8c366e652e9ddb2164b7a0d0a77e2d9da727?s=96&d=mm&r=g","caption":"Medha Mehta"},"description":"Medha is a regular contributor to InfoSec Insights. She's a tech enthusiast and writes about technology, website security, cryptography, cyber security, and data protection.","sameAs":["https:\/\/sectigostore.com\/"]},{"@type":"Question","@id":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#faq-question-1592848512065","position":1,"url":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#faq-question-1592848512065","name":"Which type of SSL certificate should I buy?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"<strong>Domain validation<\/strong>: <a href=\"https:\/\/sectigostore.com\/ssl-types\/dv-ssl-certificates\">DV SSL validation certificates<\/a> are ideal for blogs, personal websites, small-business websites, and informative sites. Basically, any website that doesn\u2019t deal with customers\u2019 financial information (payment card numbers) or sensitive details.<br\/><br\/><strong>Organizational validation<\/strong>: <a href=\"https:\/\/sectigostore.com\/ssl-types\/ov-ssl-certificates\">OV SSL validation certificates<\/a> are best suited for non-profits, educational institutes, medium scale businesses, and ecommerce websites as a minimum. Basically, any businesses or organizations that deal with their users\u2019 sensitive information.<br\/><br\/><strong>Extended validation<\/strong>: <a href=\"https:\/\/sectigostore.com\/ssl-types\/ev-ssl-certificates\">EV SSL validation certificates<\/a> are best suited for healthcare institutions, eCommerce websites, military\/government websites, large scale enterprises with high traffic, etc. If you\u2019re dealing with your customers' financial information or sensitive healthcare information, transferring internal information such as trade secrets, employee's personally identifiable information (PII), sensitive political and government-related information, then you should be using an EV SSL certificate to provide the highest level of validation and authentication.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#faq-question-1592849257496","position":2,"url":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#faq-question-1592849257496","name":"What if I\u2019m running an online store but don\u2019t qualify for an OV or EV SSL certificate?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"These days, people start and operate their online businesses from home. It\u2019s quite common for businesses that deal in homemade products, designer clothes, artwork, accessories, etc. These businesses frequently have neither an office nor registration with the government. If that is the case, you have to go for domain validated (DV) SSL certificates only. It would be risky, but it's not illegal (yet) to use DV certs for websites handling users' financial information. But as soon as you register your business, don't forget to switch your SSL certificate from DV to OV.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#faq-question-1592849339966","position":3,"url":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#faq-question-1592849339966","name":"What is the price difference among all three SSL authentications?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"DV SSL certificates are the cheapest. They cost as little as <a href=\"https:\/\/sectigostore.com\/ssl-certificates\/positivessl\">$8.78\/year<\/a>.<br\/><br\/>OV has a medium-priced range, with a starting price of <a href=\"https:\/\/sectigostore.com\/ssl-certificates\/instantssl\">$30.80\/year<\/a>.<br\/><br\/>EV SSL certificates are the most expensive ones, which starts from <a href=\"https:\/\/sectigostore.com\/ssl-certificates\/positivessl-ev\">$79.84<\/a>.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#faq-question-1592849376962","position":4,"url":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#faq-question-1592849376962","name":"Is there any hidden SSL authentication cost for business validated SSL certificates?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"No. CAs aren\u2019t going to charge you anything extra for the validation process. The cost of SSL authentication is, by default, included in the certificate\u2019s price. That\u2019s why they are more expensive than DV SSL certificates. Even if your data is not up to date on the online government directories and the CA needs to go the extra mile to request and vet the physical documents, there\u2019s no additional charges or penalties. This responsibility is just par the course for CAs, and they understand that and calculate that in their SSL certificate prices.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#faq-question-1592849407043","position":5,"url":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#faq-question-1592849407043","name":"How much time does SSL validation take?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"<strong>Domain validation<\/strong>: Within minutes. (Basically, as soon as you click on the verification link or place the files on the root directory.)<br\/><br\/><strong>Organization Validation<\/strong>: 1-3 days.<br\/><br\/><strong>Extended Validation<\/strong>: 1-5 days.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#faq-question-1592849456138","position":6,"url":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#faq-question-1592849456138","name":"How long is SSL authentication valid?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"You must renew your SSL certificate after two years and go through the SSL validation process again at the time of renewal \u2014 although this <a href=\"https:\/\/www.thesslstore.com\/blog\/ssl-certificate-validity-will-be-limited-to-one-year-by-apples-safari-browser\/\">changes to one year<\/a> starting Sept. 1, 2020. So, for example, even if you have bought an SSL certificate for five years, according to the <a rel=\"noreferrer noopener\" href=\"http:\/\/cabforum.org\" target=\"_blank\">CA\/B Forum<\/a>'s guidelines, you must reissue it after two years (i.e., you must go through CSR generation, SSL validation, and installation process once again).<br\/><br\/>However, it\u2019s important to note that if you haven't changed your certificate authority and business information (physical address, phone numbers, etc.), this second OV\/EV process will be way quicker than the first time around. Of course, using a <a href=\"https:\/\/sectigostore.com\/enterprise\">reliable certificate manager also can help enterprises<\/a> with managing all of their SSL certificates (and other digital certificates) at scale.<br\/><br\/>Also, the same rule applies to all the CAs regardless of which brand you choose. So, if a CA, reseller, or hosting site tells you different, they\u2019re providing you with the wrong information that can <a href=\"https:\/\/www.thesslstore.com\/blog\/what-happens-when-your-ssl-certificate-expires\/\" target=\"_blank\" rel=\"noreferrer noopener\">result in downtime or costly non-compliance penalties<\/a>.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#faq-question-1592849502163","position":7,"url":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#faq-question-1592849502163","name":"Will I get a green address bar with an extended validated SSL certificate?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"Yes and no! Some browsers, such as Internet Explorer, Safari, Microsoft Edge, and Opera, are still showing a green bar (organization's legally registered name on the address bar in the green color).<br\/><br\/>Google Chrome and Firefox have recently changed their policies for the green bar, and now they are showing the organization's name on the certificate itself. Anyone can see it after clicking on the padlock sign:<br\/>","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#faq-question-1592849950886","position":8,"url":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#faq-question-1592849950886","name":"What happens if my business can\u2019t pass the business validation process?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"If a CA finds anything fishy while validating your company\u2019s information, they won\u2019t issue an SSL certificate to your website. But that happens only in rare cases for legitimate businesses. If your business is genuine and all the information you have provided is accurate, you don\u2019t need to worry about anything.<br\/><br\/>The general rule is that if a CA denies issuing you the certificate, you generally lose your money. <strong>But<\/strong> <strong>if you have bought your certificate from SectigoStore, we will give you 100% money-back if you encounter any issues within 30 days of the purchase.\u00a0<\/strong>","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#faq-question-1592849983634","position":9,"url":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#faq-question-1592849983634","name":"Who should I contact if I run into some issues during the SSL validation process?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"If you have bought a Sectigo SSL certificate from SectigoStore.com, you can either contact our <a href=\"https:\/\/sectigostore.com\/contact\">customer care<\/a> team or <a href=\"https:\/\/sectigo.com\/support\">Sectigo CA<\/a> directly. At SectigoStore.com, we provide 24\/7 live customer support via chat, phone, and emails.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#faq-question-1592849999989","position":10,"url":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#faq-question-1592849999989","name":"What if the CA makes any errors in the validation process?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"If that happens, the SSL warranty comes handy. The below is Sectigo\u2019s policy for warranty:<br\/><br\/><em>\u201cShould we fail to properly validate the information contained in a digital certificate and our failure causes the end-user to lose money (in connection with a fraudulent online credit card transaction), then the end-user may have a claim to recovery under our certificate warranty.\u201d<\/em><br\/><br\/>For more details, check out <a href=\"https:\/\/support.sectigo.com\/Com_KnowledgeDetailPage?Id=kA01N000000zFS5\" target=\"_blank\" rel=\"noreferrer noopener\">Sectigo\u2019s Warranty Guidelines<\/a>.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#faq-question-1592850043577","position":11,"url":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#faq-question-1592850043577","name":"Is SSL validation compulsory? Can I omit the authentication step?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"According to the CA\/B Forum's regulations, SSL authentication is mandatory, and hence, no legit CA can issue you an SSL certificate before you complete the validation process.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#faq-question-1592850056837","position":12,"url":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#faq-question-1592850056837","name":"What role does SSL validation play in website security?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"Anyone can buy an SSL certificate for any domain they want! It\u2019s the SSL authentication process where you have to prove that you actually control the domain and represent a genuine business to the CA.<br\/><br\/>When a CA issues an SSL certificate to your domain name, it ties your server's public key to a hostname (i.e., a domain name). So, for example, when a CA issues an SSL certificate for amazon.com, it attaches Amazon's server's public to the certificate and writes \"hostname\" as \"amazon.com\" on it. Now, when someone tries to open amazon.com, their browser simply checks the website's SSL certificate and redirects all the traffic to amazon\u2019s server. Only Amazon\u2019s server can decrypt the traffic because it has the unique corresponding private keys.<br\/><br\/>As you can see, attaching the right public key to the right hostname is a crucial thing. If the CA ties the wrong server's public key, all the traffic will be redirected to the wrong server. Now how would the CA know your domain\u2019s public key? Because you\u2019ll send it to the CA during the CSR generation process.<br\/><br\/>So, how would CA know whether the public key provided by you actually belongs to the domain you control? Here\u2019s where the SSL validation comes into the play. It's only through the validation process that the CA gets an idea of whether you are providing them the right public key.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#faq-question-1592850092073","position":13,"url":"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/#faq-question-1592850092073","name":"What is the CA\u2019s risk in the SSL validation process?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"Once the CA attaches the public key to a hostname, it signs the SSL certificate with its own intermediate root certificate's private key. This means that the CA vouches for the authenticity of the SSL certificate. The web browser simply checks the CA's signature from its trusted root store and trusts the certificate and the details it contains.<br\/><br\/>Hence, if the CA makes a mistake in attaching the keys, and if someone suffers from the financial loss due to such a mistake, the CA must reimburse the legal penalty up to the warranty amount to the victim.","inLanguage":"en-US"},"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/posts\/1121","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/comments?post=1121"}],"version-history":[{"count":5,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/posts\/1121\/revisions"}],"predecessor-version":[{"id":1135,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/posts\/1121\/revisions\/1135"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/media\/1130"}],"wp:attachment":[{"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/media?parent=1121"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/categories?post=1121"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/tags?post=1121"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}