{"id":1483,"date":"2020-12-14T21:53:17","date_gmt":"2020-12-14T21:53:17","guid":{"rendered":"https:\/\/sectigostore.com\/blog\/?p=1483"},"modified":"2020-12-17T10:59:21","modified_gmt":"2020-12-17T10:59:21","slug":"what-is-a-certificate-authority-certification-authorities-explained","status":"publish","type":"post","link":"https:\/\/sectigostore.com\/blog\/what-is-a-certificate-authority-certification-authorities-explained\/","title":{"rendered":"What Is a Certificate Authority? Certification Authorities Explained"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"certificate-authority-regardless-of-whether-you-them-certification-authorities-certificate-authorities-or-cas-were-here-to-answer-your-top-questions-about-these-third-party-entities-and-how-they-work\">Certificate Authority &#8211; Regardless of whether you them certification authorities, certificate authorities, or CAs, we&#8217;re here to answer your top questions about these third-party entities and how they work<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">What is a certificate authority? Well, before I can answer that, let&#8217;s back up a second and let me ask you something. Would you hand over your banking information, banking information, or social security number to a stranger on the street? Probably not. But people do the digital equivalent of this all the time through their favorite websites. They enter their personal details on ecommerce, banking, and credit bureau websites without knowing whether they\u2019re secure, safe, or trustworthy. Moreover, they do this without having any real understanding of <em>what makes them <\/em>secure, safe, or trustworthy.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But how do you know whether a website is any of these things? For example, how do you know whether you\u2019re shopping on a legitimate ecommerce website or banking on the legitimate banking website? And how do you know that your info is transmitting securely? This is where something known as a certificate authority comes into play.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We\u2019ve put together a list of the top questions people ask about certification authorities to help you better understand their role in internet security. You can either choose to read through all of the content or you can simply pick and choose which questions you want answers to from the table of contents below. &nbsp;<\/p>\n\n\n\n<div class=\"wp-block-advanced-gutenberg-blocks-summary\"><p class=\"wp-block-advanced-gutenberg-blocks-summary__title\">Table of contents<\/p><div class=\"wp-block-advanced-gutenberg-blocks-summary__fold\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"24\" viewbox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"feather feather-chevron-up\"><polyline points=\"18 15 12 9 6 15\"><\/polyline><\/svg><\/div><ol role=\"directory\" class=\"wp-block-advanced-gutenberg-blocks-summary__list\"><li><a href=\"#certificate-authority-regardless-of-whether-you-them-certification-authorities-certificate-authorities-or-cas-were-here-to-answer-your-top-questions-about-these-third-party-entities-and-how-they-work\">Certificate Authority &#8211; Regardless of whether you them certification authorities, certificate authorities, or CAs, we&#8217;re here to answer your top questions about these third-party entities and how they work<\/a><ol><\/ol><\/li><li><a href=\"#what-is-a-certification-authority-certificate-authority\">What Is a Certification Authority (Certificate Authority)?<\/a><ol><\/ol><\/li><li><a href=\"#what-does-a-certificate-authority-do\">What Does a Certificate Authority Do?<\/a><ol><li><a href=\"#public-cas-are-the-identification-card-issuers-of-the-internet\">Public CAs Are the Identification Card Issuers of the Internet<\/a><ol><\/ol><\/li><\/ol><\/li><li><a href=\"#a-real-world-example-of-how-a-public-ca-works\">A Real-World Example of How a Public CA Works<\/a><ol><\/ol><\/li><li><a href=\"#certificate-authority-validation-levels\">Certificate Authority Validation Levels<\/a><ol><li><a href=\"#domain-validation\">Domain Validation<\/a><ol><\/ol><\/li><li><a href=\"#organization-validation\">Organization Validation<\/a><ol><\/ol><\/li><li><a href=\"#extended-validation\">Extended Validation<\/a><ol><\/ol><\/li><\/ol><\/li><li><a href=\"#why-do-we-need-certification-authorities\">Why Do We Need Certification Authorities?<\/a><ol><li><a href=\"#cas-provide-verification-and-help-you-to-establish-trust-with-others\">CAs Provide Verification (and Help You to Establish Trust with Others)<\/a><ol><\/ol><\/li><li><a href=\"#what-makes-a-public-ca-trustworthy\">What Makes a Public CA Trustworthy?<\/a><ol><li><a href=\"#it\u2019s-all-about-trust\u2026\">It\u2019s All About Trust\u2026<\/a><ol><\/ol><\/li><\/ol><\/li><\/ol><\/li><li><a href=\"#what-is-an-example-of-a-certification-authority\">What Is an Example of a Certification Authority?<\/a><ol><li><a href=\"#private-certificate-authorities\">Private Certificate Authorities<\/a><ol><\/ol><\/li><li><a href=\"#public-certificate-authorities\">Public Certificate Authorities<\/a><ol><\/ol><\/li><\/ol><\/li><li><a href=\"#what-is-the-role-of-a-certificate-authority-in-public-key-infrastructure\">What Is the Role of a Certificate Authority in Public Key Infrastructure?<\/a><ol><\/ol><\/li><li><a href=\"#what-is-a-digital-certificate-and-what-does-it-do\">What Is a Digital Certificate and What Does It Do?<\/a><ol><li><a href=\"#the-different-types-of-x509-digital-certificates\">The Different Types of X.509 Digital Certificates<\/a><ol><\/ol><\/li><\/ol><\/li><li><a href=\"#how-certificate-authorities-issue-digital-certificates-for-websites\">How Certificate Authorities Issue Digital Certificates for Websites<\/a><ol><\/ol><\/li><li><a href=\"#tldr;-a-quick-overview-of-certification-authorities\">TLDR; A Quick Overview of Certification Authorities<\/a><ol><\/ol><\/li><\/ol><\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"what-is-a-certification-authority-certificate-authority\">What Is a Certification Authority (Certificate Authority)?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>A certificate authority is a third-party entity that\u2019s trusted by web browsers and operating systems to create and issue digital certificates.<\/strong> But their job is to do this for organizations and websites that they vet, which makes CAs integral to digital security (and internet security) as we know it<strong>.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A \u201ccertification authority\u201d is the original term for what we now commonly refer to as a certificate authority or a CA. So, you\u2019ll sometimes see them referred to by these different names.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"what-does-a-certificate-authority-do\">What Does a Certificate Authority Do?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Basically, a public certificate authority is a publicly trusted entity that issues digital certificates to individuals, businesses, and other organizations. These certificates are basically small data files that contain vetted identifying information about the organization. So, CAs are a way to prove yourself to people who don\u2019t know you (or your organization) personally by having a reputable third party vouch for you.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But what does all of this mean when it comes to website security?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Before issuing a certificate, the certification authority checks out the requesting organization. They look at documents and records from official sources to make sure that the company is legitimate. After that, the CA issues a digital certificate that the organization can use to secure their websites, software, and email communications using encryption and <a href=\"https:\/\/sectigostore.com\/blog\/what-is-a-digital-signature-and-how-does-the-digital-signature-process-work\/\">digital signatures<\/a>.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So, if you\u2019re someone who requests a certificate for your organization, here\u2019s what a certification authority helps you to achieve:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Prove your organizational identity.<\/strong> You can run around screaming \u201cI\u2019m me!\u201d all you want \u2014 but this is a way for you to <em>prove<\/em> your identity to the rest of the world.<\/li><li><strong>Validate that your <a href=\"https:\/\/sectigostore.com\/blog\/how-to-tell-if-a-website-is-legit-in-10-easy-steps\/\">organization is legit<\/a> (and that your site isn\u2019t operated by hackers).<\/strong> Hackers are crafty individuals who are always looking for ways to trick users into providing their personal information and clicking on malicious links. What better way to do that than by pretending to be you by creating a fake website that resembles your real one?<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">In a roundabout way, CAs also help you to <strong>create secure, encrypted connections between your web servers and your users\u2019 browsers.<\/strong> By issuing an SSL\/TLS certificate for your website, for example, you can then use a secure transport layer security (TLS) protocol to send and receive encrypted data. As a site owner, this helps you to protect the information that travels to and from your servers. This prevents eavesdropping and man-in-the-middle (MitM) attacks that can result in stolen data.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Certificate authorities are also frequently responsible for maintaining <a href=\"https:\/\/www.thesslstore.com\/blog\/crl-explained-what-is-a-certificate-revocation-list\/\" target=\"_blank\" rel=\"noreferrer noopener\">certificate revocation lists<\/a> (CRLs) that tell the world when certificates are invalidated prior to their assigned expiration dates.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"public-cas-are-the-identification-card-issuers-of-the-internet\">Public CAs Are the Identification Card Issuers of the Internet<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">To put it another way, certificate authorities are the identity verification authorities of the internet. They\u2019re kind of like the identity card issuers for your state or country of residence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In the United States, each state has its own equivalent of a Department of Motor Vehicles (DMV), which is responsible for issuing driver\u2019s licenses. These licenses are government-issued cards that you can use to prove your identity to drive, buy alcohol, get a job, and perform other business and tasks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When you apply for your driver\u2019s license, in addition to having to pass a driver\u2019s test, you\u2019re also required to provide different types of official documents that prove your identity. This includes everything from social security cards and birth certificates to green cards and various proofs of residence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Once you verify your information with a third party (in this case, the DMV), the DMV worker then takes your picture, which displays on the card along with your official signature. They then print the card with holographic markings that indicate your card is real and isn\u2019t a realistic forgery (think of this like a digital signature). You can then use this documentation to prove your identity.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"a-real-world-example-of-how-a-public-ca-works\">A Real-World Example of How a Public CA Works<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Of course, the best way to understand what a certification authority is, is to consider a real-world example of what they do in terms of website security.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s say you\u2019re someone who dabbles in investing and you use vanguard.com for your transactions. How do you know that you\u2019re on the official website for The Vanguard Group, Inc.? After all, the site appears to be legitimate and uses logos and branding that are consistent with the company. But it <em>could<\/em> be a really well-designed phishing website\u2026 this is why it\u2019s important to know what to look for.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"623\" src=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/vanguard-padlock-icon-1024x623.png\" alt=\"The padlock icon appears because a certificate authority issued a cert that enables encrypted communication\" class=\"wp-image-1484 addshadow\" srcset=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/vanguard-padlock-icon-1024x623.png 1024w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/vanguard-padlock-icon-300x183.png 300w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/vanguard-padlock-icon-560x341.png 560w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/vanguard-padlock-icon-940x572.png 940w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/vanguard-padlock-icon.png 1412w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption>You can see the padlock security icon in the Google Chrome browser web address field. This indicates that the browser has a secure, encrypted connection to the site\u2019s server.<\/figcaption><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">See the padlock symbol in the address bar? That means that your browser is connected to the site\u2019s server using a secure, encrypted connection. Okay, cool. So now you know your info is transmitting via a secure, encrypted channel \u2014 but that still doesn\u2019t mean your info is <em>safe<\/em>. That\u2019s because even phishing websites can get domain validated (DV) SSL\/TLS certificates from less-than-stringent CAs. The <a href=\"https:\/\/docs.apwg.org\/reports\/apwg_trends_report_q1_2020.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">Anti-Phishing Working Group\u2019s (APWG) Phishing Activity Trends Report for Q1 2020<\/a> shows that as of the end of Q1 2020, nearly 75% of phishing websites used SSL\/TLS certificates!<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is why it\u2019s crucial that you know whether you\u2019re connecting to a real web server and not a hacker\u2019s imposter website. After all, a cybercriminal can get a free DV certificate and slap it on their website to make the secure padlock icon appear. But this is why it\u2019s important to know the difference between a secure site and a safe site. I say that because you can have a secure site \u2014 meaning that it\u2019s communicating using an encrypted communication channel \u2014 that isn\u2019t safe because you don\u2019t know who you\u2019re connecting to on the other end of that encrypted connection. &nbsp;&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You can verify the site\u2019s legitimate by checking the site\u2019s SSL\/TLS certificate organizational information (see the screenshot below):<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"539\" src=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/vanguard-security-padlock-icon-1024x539.png\" alt=\"A screenshot of the security icon that appears in the browser from certificates issued by a certificate authority\" class=\"wp-image-1485 addshadow\" srcset=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/vanguard-security-padlock-icon-1024x539.png 1024w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/vanguard-security-padlock-icon-300x158.png 300w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/vanguard-security-padlock-icon-560x295.png 560w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/vanguard-security-padlock-icon-940x495.png 940w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/vanguard-security-padlock-icon.png 1337w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption>When you click on the padlock security symbol in the address bar, this window displays and shows that the SSL\/TLS certificate for the website was issued to the verified organization The Vanguard Group, Inc. [US].<\/figcaption><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">So long as a website is using a website that validates organizational identity (more on that shortly) as a minimum, you can tell that a site is real.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To view more in-depth information, click on the certificate information and open the <strong>Details<\/strong> tab. Here, you can select the <strong>Subject<\/strong> field to read the organization\u2019s verified information.&nbsp;<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"470\" height=\"624\" src=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/vanguard-ca-certificate-organization-information.png\" alt=\"The certificate details that shows the organizational info of the certificate requestor\" class=\"wp-image-1486 addshadow\" srcset=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/vanguard-ca-certificate-organization-information.png 470w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/vanguard-ca-certificate-organization-information-226x300.png 226w\" sizes=\"auto, (max-width: 470px) 100vw, 470px\" \/><figcaption>This screenshot shows the organizational information and company details of the verified certificate requestor.<\/figcaption><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">All of this is made possible through public key infrastructure, or what\u2019s known as PKI. (We\u2019ll speak more about PKI shortly.)<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"certificate-authority-validation-levels\">Certificate Authority Validation Levels<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Certificate authorities are capable of validating organizations and individuals to make sure they\u2019re real and aren\u2019t posers. There are <a href=\"https:\/\/sectigostore.com\/blog\/understanding-the-ssl-validation-process-with-faqs\/\">three levels of validation<\/a> that they use:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"domain-validation\">Domain Validation<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This is the most basic form of validation. It only requires the CA to ensure that the person or organization requesting the certificate has control of the domain or website. This can be done either by them sending a validation link to your registered email address or by sending one or more files that you&#8217;d need to upload to specific folders of your domain.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Because this process is so basic, it\u2019s typically completed automatically and results in certificate issuance within minutes. So if you&#8217;re looking for more in-depth verification, you&#8217;ll want to use the next type of validation as a minimum.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"organization-validation\">Organization Validation<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This is sometimes referred to as a basic business validation certificate and it\u2019s the next step up from domain validation. The reason why is because it offers greater vetting of an organization than a DV certificate does, yet it\u2019s not as extensive as the next type of certificate we\u2019ll cover.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The <a href=\"https:\/\/www.cancer.org\/\" target=\"_blank\" rel=\"noreferrer noopener\">American Cancer Society\u2019s website<\/a> is an example of a site that uses an OV certificate.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"521\" src=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/american-cancer-society-certificate-1024x521.png\" alt=\"A screenshot of the American Cancer Society website that shows the security padlock and organizational information\" class=\"wp-image-1487 addshadow\" srcset=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/american-cancer-society-certificate-1024x521.png 1024w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/american-cancer-society-certificate-300x153.png 300w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/american-cancer-society-certificate-560x285.png 560w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/american-cancer-society-certificate-940x478.png 940w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/american-cancer-society-certificate.png 1174w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption>When you click on the padlock security symbol in the address bar, this window displays and shows that the SSL\/TLS certificate for the website was issued by COMODO RSA Organization Validation Secure Server CA. But unlike the EV certificate used on the Vanguard website, it doesn\u2019t display the organizational information right here. You have to dig a little deeper (see the next screenshot).<\/figcaption><\/figure><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"470\" height=\"624\" src=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/american-cancer-society-certificate-organization-information.png\" alt=\"A screenshot of the organizational information that a certificate authority vetted and included in the certificate details\" class=\"wp-image-1488 addshadow\" srcset=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/american-cancer-society-certificate-organization-information.png 470w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/american-cancer-society-certificate-organization-information-226x300.png 226w\" sizes=\"auto, (max-width: 470px) 100vw, 470px\" \/><figcaption>This screenshot shows the organizational information and company details of the verified certificate requestor.<\/figcaption><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">This is why organization validation should be the minimum form of validation for businesses that collect, process or use sensitive or personally identifiable information (PII). Ideally, organizations that collect and process these types of information should be using extended validation. But if they don\u2019t, then OV should be the absolute minimum form of validation.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"extended-validation\">Extended Validation<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/sectigostore.com\/page\/what-is-an-ev-certificate\/\">Extended validation<\/a> is the most in-depth form of business validation that certificate authorities offer. This type of certificate requires the most verification about your organization and generally takes up to five days to issue.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Vanguard site is an example of a site that uses an EV certificate.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"why-do-we-need-certification-authorities\">Why Do We Need Certification Authorities?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Why do you need a driver\u2019s license or state ID card? Because it helps you prove that you\u2019re you to third parties who wouldn\u2019t know otherwise. A CA helps you to establish trust with others because <em>they\u2019re<\/em> trusted for issuing valid, reliable certificates \u2014 and that trust is integral to public key infrastructure (PKI). (We\u2019ll speak more to PKI later.)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Trust gives you credibility in the eyes of others. To put it simply, public certificate authorities vouch for you \u2014 they attest to browsers, email clients and operating systems that you\u2019re you and that you\u2019re trustworthy. They do this by vetting you and issuing digital certificates. Without a trusted third party to stand in and vouch for you, how would anyone know whether you are trustworthy? Again, it\u2019s like having the DMV issuing you an official ID card that proves you\u2019re you.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The same thing basically happens when you request an SSL\/TLS certificate for your company\u2019s website. A public CA is responsible for adhering to strict standards and processes when vetting your organization\u2019s information. They do this through a series of set processes and by using official documents and resources. This makes it so that web browsers, email clients, and operating systems trust them to verify that you are who you claim to be.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"cas-provide-verification-and-help-you-to-establish-trust-with-others\">CAs Provide Verification (and Help You to Establish Trust with Others)<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Publicly trusted CAs \u2014 and the digital certificates they issue \u2014 are central to the public key encryption trust model that\u2019s at the heart of <a href=\"https:\/\/sectigostore.com\/blog\/what-is-pki-a-laymans-guide-to-public-key-infrastructure\/\">public key infrastructure (PKI)<\/a>. (We\u2019ll talk more about <a href=\"https:\/\/sectigostore.com\/blog\/what-is-an-x-509-certificate-what-to-know-about-pki-certificates\/\">PKI and digital certificates<\/a> shortly.)<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"what-makes-a-public-ca-trustworthy\">What Makes a Public CA Trustworthy?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Third-party certification authorities are inherently trustworthy for two main reasons:<\/p>\n\n\n\n<ol class=\"wp-block-list\" type=\"1\"><li><strong>Public CAs are autonomous and not controlled by certificate requestors.<\/strong> This is a huge difference between public and private certificate authorities \u2014 public CAs are separate from the entities that request certificates.<\/li><li><strong>Public CAs (and the certificates they issue) have standards to meet as a minimum.<\/strong> For example, the CA\/Browser Forum (CA\/B Forum) has <a href=\"https:\/\/cabforum.org\/baseline-requirements\/\" target=\"_blank\" rel=\"noreferrer noopener\">baseline requirements<\/a>. Because of the way that the certificates are created, they\u2019re unforgeable, meaning that no one can modify them without you knowing it.  &nbsp;<\/li><\/ol>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"it\u2019s-all-about-trust\u2026\">It\u2019s All About Trust\u2026<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">For the authentication framework that a certificate authority helps create to work, it\u2019s essential for the CA to have the trust of third-party organizations. This is where the X.509 standards come into play \u2014 these standards outline the X.509 digital certificates that are central to public key infrastructure (PKI). (We\u2019ll speak more to these certificates shortly.) The latest version of the standards is X.509 (10\/19), which was approved in October 2019 but requires payment to access.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The <a href=\"https:\/\/www.itu.int\/rec\/T-REC-X.509-201610-S\/en\" target=\"_blank\" rel=\"noreferrer noopener\">X.509 (10\/2016) standards document<\/a> \u2014 the latest free version of the standards \u2014 refers to trust in a CA as the:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>\u201cBelief that the certification authority (CA) will act reliability and truthfully in the management of its public-key certificates and will comply with its published certification practise statement and relevant legislation.\u201d<\/em><\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Yes, I know there\u2019s a typo in there \u2014 it should say <em>reliably<\/em> instead of <em>reliability<\/em>, but what can you do? Typos happen. That aside, the main take away here is that the CA is expected to behave a certain way and serve as a reliable \u2014 trustworthy \u2014 certification entity.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The original <a href=\"https:\/\/www.itu.int\/rec\/T-REC-X.509-198811-S\/en\" target=\"_blank\" rel=\"noreferrer noopener\">X-509 (11\/1988) standards document<\/a> talks about the importance of trust:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>\u201cThe key role of trust in the authentication framework is to describe the relationship between an authenticating entity and a certification authority; an authenticating entity must be certain that it can trust the certification authority to create only valid and reliable certificates.\u201d<\/em><\/p><\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"what-is-an-example-of-a-certification-authority\">What Is an Example of a Certification Authority?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Sectigo is an example of a publicly trusted certificate authority. In fact, Sectigo ranks among the world\u2019s largest commercial CAs. There are a few hundred CAs, but the truth of the matter is that only around a dozen or so are ones that the majority of organizations and individuals rely upon for issuing their digital certificates.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So far, we\u2019ve only discussed public CAs (and, frankly, that\u2019s going to be what we focus on in this article). But did you know that there\u2019s actually more than one type of CA? There are two types of certificate authorities: public and private CAs.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"private-certificate-authorities\">Private Certificate Authorities<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">A private CA (or private certification authority) is an internal CA that\u2019s controlled by the organization that it issues certificates for. It\u2019s essentially the equivalent of you signing your own driver\u2019s license to prove your identity. While using something that\u2019s self-signed may work within your own organization, needless to say, that kind of approach just ain\u2019t gonna fly with third parties who don\u2019t know you.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"public-certificate-authorities\">Public Certificate Authorities<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Public certificate authorities, on the other hand, are separate entities that aren\u2019t controlled by the organizations they issue certificates to. This is why when people talk about CAs, they typically are talking about public CAs.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"what-is-the-role-of-a-certificate-authority-in-public-key-infrastructure\">What Is the Role of a Certificate Authority in Public Key Infrastructure?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Public key infrastructure is defined by the X.509 standards as the following: \u201cThe infrastructure able to support the management of public keys able to support authentication, encryption, integrity or non-repudiation services.\u201d Basically, PKI is the framework \u2014 the policies, procedures, and technologies \u2014 that the foundation of website security is built upon.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Without PKI, data would only be able to transmit across the internet in plaintext form without the use of encryption to disguise it. And no one would know for certain whether the entities they\u2019re communicating with on the other end of websites or emails are legitimate.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Certification authorities are one of the core components of the overarching&nbsp;public key infrastructure. This infrastructure involves:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>A variety of entities (certificate authorities, web browsers, operating systems, etc.)<\/li><li>Regulatory standards, processes and procedures (as outlined by the <a href=\"https:\/\/cabforum.org\/\" target=\"_blank\" rel=\"noreferrer noopener\">CA\/B Forum<\/a>)<\/li><li>PKI digital certificates (which securely ties your distinguished organizational name and key to your identity),<\/li><li>Digital signatures (which sign the digital certificates), and<\/li><li>Public-private key pairs.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">If you\u2019re interested in reading more about PKI specifically, check out our other article that breaks down <a href=\"https:\/\/sectigostore.com\/blog\/what-is-pki-a-laymans-guide-to-public-key-infrastructure\/\">what PKI is and how it works<\/a>. But, basically, these PKI certificates are known as X.509 digital certificates or X.509 public key certificates.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"what-is-a-digital-certificate-and-what-does-it-do\">What Is a Digital Certificate and What Does It Do?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Remember earlier when we said that a public CA is like the DMV of the internet? Well, a <a href=\"https:\/\/sectigostore.com\/blog\/what-is-a-pki-certificate\/\">PKI digital certificate<\/a> is like your government-issued ID card or passport \u2014 it\u2019s a form of documentation that shows others who don\u2019t know you that you are who you claim to be. But in this case, instead of your picture and other license information, it\u2019s a digital file that contains the following crucial data:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Your organization\u2019s name and information<\/strong> \u2014 The subject field shows that your organization is legitimate and owns the certificate.<\/li><li><strong>Your public key<\/strong> \u2014 This is the half of your public-private key pair that\u2019s publicly known.<\/li><li><strong>The certificate issuer\u2019s name<\/strong> \u2014 This is the name of the certificate authority (such as Sectigo) that issues the certificate.<\/li><li><strong>The CA\u2019s digital signature<\/strong> \u2014 This shows that the certificate was, in fact, issued by a reputable CA.<\/li><li><strong>A serial number<\/strong> \u2014 This is a code that\u2019s unique to your individual SSL\/TLS certificate.<\/li><li><strong>Your certificate\u2019s issuance and expiration dates<\/strong> \u2014 These certificates are only valid for a set amount of time \u2014 up to 398 days starting Sept. 1, 2020).<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">This information helps you to validate your organizational identity to others. For example, you validate to website users\u2019 browsers that your website\/server actually belongs to your organization.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"the-different-types-of-x509-digital-certificates\">The Different Types of X.509 Digital Certificates<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Of course, CAs can issue more than just website security certificates (SSL\/TLS certificates). They also issue:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/sectigostore.com\/code-signing\">Code signing certificates<\/a><\/li><li><a href=\"https:\/\/sectigostore.com\/id\/document-signing-certificate\">Document signing certificates<\/a><\/li><li><a href=\"https:\/\/sectigostore.com\/secure-email-document-signing\">Email signing certificates<\/a> (also known as S\/MIME certificates)<\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"how-certificate-authorities-issue-digital-certificates-for-websites\">How Certificate Authorities Issue Digital Certificates for Websites<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The process of how a third-party certification authority issues SSL\/TLS certificates is a bit long. So, we\u2019ve included this graphic to help illustrate the process:<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"629\" height=\"732\" src=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/how-certificate-authority-works-website.png\" alt=\"An illustration that breaks down the role of a certificate authority in issuing a website security certificate\" class=\"wp-image-1489 addshadow\" srcset=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/how-certificate-authority-works-website.png 629w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/how-certificate-authority-works-website-258x300.png 258w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/how-certificate-authority-works-website-560x652.png 560w\" sizes=\"auto, (max-width: 629px) 100vw, 629px\" \/><figcaption>An illustration of what happens when you request an SSL\/TLS certificate for your website &amp; the role the CA plays in the process.<\/figcaption><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">As you can see in the illustration above, it starts with you requesting an SSL\/TLS certificate for your domain from a public CA. Before the certificate authority can issue the cert, they first need to verify your identity and that you also control the domain in question. Once they do this, they can then issue your certificate, which they apply their digital signature to prove that they issued it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Once you have the certificate, you can then install it on your web server. This allows you to verify your identity and to establish secure, encrypted communication channels with site users\u2019 browsers.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"tldr;-a-quick-overview-of-certification-authorities\">TLDR; A Quick Overview of Certification Authorities<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Yeah, that was a lot of information to slog through. So, to make this easy for those of you who want to just skim or need a quick recap, here are the big takeaways about public certificate authorities:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Certificate authorities are the equivalent of an ID card-issuing authority like the Department of Motor Vehicles.<\/li><li>They enable you (your organization) to authenticate yourself to third parties who don\u2019t know you. They do this by issuing digital certificates that they digitally sign that prove that you\u2019re legitimate.<\/li><li>Public CAs are integral to public key infrastructure and internet security as a whole. They\u2019re what make it possible to establish trust.<\/li><li>Sectigo is an example of a publicly trusted CA.<\/li><li>The X.509 digital certificates that they issue can help you to authenticate yourself or your organization to others via websites, emails, software and documents.<\/li><li>There are three levels of validation that they can use to verify your information: domain validation, organizational validation and extended validation.<\/li><\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Certificate Authority &#8211; Regardless of whether you them certification authorities, certificate authorities, or CAs, we&#8217;re here to answer your top questions about these third-party entities and how they work What&#8230;<\/p>\n","protected":false},"author":8,"featured_media":1490,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[13],"tags":[128,126,127],"class_list":["post-1483","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cyber-security","tag-ca","tag-certificate-authority","tag-certification-authority","post-with-tags"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.0 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>What Is a Certificate Authority? Certification Authorities Explained - InfoSec Insights<\/title>\n<meta name=\"description\" content=\"A certificate authority (aka a certification authority or CA) is a third party that helps you prove your organizational identity online.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/sectigostore.com\/blog\/what-is-a-certificate-authority-certification-authorities-explained\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"What Is a Certificate Authority? Certification Authorities Explained - InfoSec Insights\" \/>\n<meta property=\"og:description\" content=\"A certificate authority (aka a certification authority or CA) is a third party that helps you prove your organizational identity online.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/sectigostore.com\/blog\/what-is-a-certificate-authority-certification-authorities-explained\/\" \/>\n<meta property=\"og:site_name\" content=\"InfoSec Insights\" \/>\n<meta property=\"article:published_time\" content=\"2020-12-14T21:53:17+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-12-17T10:59:21+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/what-is-a-certificate-authority.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1600\" \/>\n\t<meta property=\"og:image:height\" content=\"1000\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Casey Crane\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Casey Crane\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"18 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/what-is-a-certificate-authority-certification-authorities-explained\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/what-is-a-certificate-authority-certification-authorities-explained\\\/\"},\"author\":{\"name\":\"Casey Crane\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/#\\\/schema\\\/person\\\/559abd5fa4d9d651eaf18d9b9e91a64c\"},\"headline\":\"What Is a Certificate Authority? Certification Authorities Explained\",\"datePublished\":\"2020-12-14T21:53:17+00:00\",\"dateModified\":\"2020-12-17T10:59:21+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/what-is-a-certificate-authority-certification-authorities-explained\\\/\"},\"wordCount\":3607,\"image\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/what-is-a-certificate-authority-certification-authorities-explained\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/09\\\/what-is-a-certificate-authority.png\",\"keywords\":[\"CA\",\"certificate authority\",\"certification authority\"],\"articleSection\":[\"Cyber Security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/what-is-a-certificate-authority-certification-authorities-explained\\\/\",\"url\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/what-is-a-certificate-authority-certification-authorities-explained\\\/\",\"name\":\"What Is a Certificate Authority? Certification Authorities Explained - InfoSec Insights\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/what-is-a-certificate-authority-certification-authorities-explained\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/what-is-a-certificate-authority-certification-authorities-explained\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/09\\\/what-is-a-certificate-authority.png\",\"datePublished\":\"2020-12-14T21:53:17+00:00\",\"dateModified\":\"2020-12-17T10:59:21+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/#\\\/schema\\\/person\\\/559abd5fa4d9d651eaf18d9b9e91a64c\"},\"description\":\"A certificate authority (aka a certification authority or CA) is a third party that helps you prove your organizational identity online.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/what-is-a-certificate-authority-certification-authorities-explained\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/sectigostore.com\\\/blog\\\/what-is-a-certificate-authority-certification-authorities-explained\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/what-is-a-certificate-authority-certification-authorities-explained\\\/#primaryimage\",\"url\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/09\\\/what-is-a-certificate-authority.png\",\"contentUrl\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/09\\\/what-is-a-certificate-authority.png\",\"width\":1600,\"height\":1000,\"caption\":\"Certificate authority feature image of a padlock and text\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/what-is-a-certificate-authority-certification-authorities-explained\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"What Is a Certificate Authority? Certification Authorities Explained\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/\",\"name\":\"InfoSec Insights\",\"description\":\"SectigoStore.com Blog\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/#\\\/schema\\\/person\\\/559abd5fa4d9d651eaf18d9b9e91a64c\",\"name\":\"Casey Crane\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/c18d819d34a1995e91a4aa7518e9048df7856f336a1ede2262a572db7b1c2506?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/c18d819d34a1995e91a4aa7518e9048df7856f336a1ede2262a572db7b1c2506?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/c18d819d34a1995e91a4aa7518e9048df7856f336a1ede2262a572db7b1c2506?s=96&d=mm&r=g\",\"caption\":\"Casey Crane\"},\"description\":\"Casey is a writer and editor with a background in journalism, marketing, PR and communications. She has written about cyber security and information technology for several industry publications, including InfoSec Insights, Hashed Out, Experfy, HackerNoon, and Cybercrime Magazine.\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"What Is a Certificate Authority? Certification Authorities Explained - InfoSec Insights","description":"A certificate authority (aka a certification authority or CA) is a third party that helps you prove your organizational identity online.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/sectigostore.com\/blog\/what-is-a-certificate-authority-certification-authorities-explained\/","og_locale":"en_US","og_type":"article","og_title":"What Is a Certificate Authority? Certification Authorities Explained - InfoSec Insights","og_description":"A certificate authority (aka a certification authority or CA) is a third party that helps you prove your organizational identity online.","og_url":"https:\/\/sectigostore.com\/blog\/what-is-a-certificate-authority-certification-authorities-explained\/","og_site_name":"InfoSec Insights","article_published_time":"2020-12-14T21:53:17+00:00","article_modified_time":"2020-12-17T10:59:21+00:00","og_image":[{"width":1600,"height":1000,"url":"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/what-is-a-certificate-authority.png","type":"image\/png"}],"author":"Casey Crane","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Casey Crane","Est. reading time":"18 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/sectigostore.com\/blog\/what-is-a-certificate-authority-certification-authorities-explained\/#article","isPartOf":{"@id":"https:\/\/sectigostore.com\/blog\/what-is-a-certificate-authority-certification-authorities-explained\/"},"author":{"name":"Casey Crane","@id":"https:\/\/sectigostore.com\/blog\/#\/schema\/person\/559abd5fa4d9d651eaf18d9b9e91a64c"},"headline":"What Is a Certificate Authority? Certification Authorities Explained","datePublished":"2020-12-14T21:53:17+00:00","dateModified":"2020-12-17T10:59:21+00:00","mainEntityOfPage":{"@id":"https:\/\/sectigostore.com\/blog\/what-is-a-certificate-authority-certification-authorities-explained\/"},"wordCount":3607,"image":{"@id":"https:\/\/sectigostore.com\/blog\/what-is-a-certificate-authority-certification-authorities-explained\/#primaryimage"},"thumbnailUrl":"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/what-is-a-certificate-authority.png","keywords":["CA","certificate authority","certification authority"],"articleSection":["Cyber Security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/sectigostore.com\/blog\/what-is-a-certificate-authority-certification-authorities-explained\/","url":"https:\/\/sectigostore.com\/blog\/what-is-a-certificate-authority-certification-authorities-explained\/","name":"What Is a Certificate Authority? Certification Authorities Explained - InfoSec Insights","isPartOf":{"@id":"https:\/\/sectigostore.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/sectigostore.com\/blog\/what-is-a-certificate-authority-certification-authorities-explained\/#primaryimage"},"image":{"@id":"https:\/\/sectigostore.com\/blog\/what-is-a-certificate-authority-certification-authorities-explained\/#primaryimage"},"thumbnailUrl":"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/what-is-a-certificate-authority.png","datePublished":"2020-12-14T21:53:17+00:00","dateModified":"2020-12-17T10:59:21+00:00","author":{"@id":"https:\/\/sectigostore.com\/blog\/#\/schema\/person\/559abd5fa4d9d651eaf18d9b9e91a64c"},"description":"A certificate authority (aka a certification authority or CA) is a third party that helps you prove your organizational identity online.","breadcrumb":{"@id":"https:\/\/sectigostore.com\/blog\/what-is-a-certificate-authority-certification-authorities-explained\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/sectigostore.com\/blog\/what-is-a-certificate-authority-certification-authorities-explained\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/sectigostore.com\/blog\/what-is-a-certificate-authority-certification-authorities-explained\/#primaryimage","url":"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/what-is-a-certificate-authority.png","contentUrl":"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/what-is-a-certificate-authority.png","width":1600,"height":1000,"caption":"Certificate authority feature image of a padlock and text"},{"@type":"BreadcrumbList","@id":"https:\/\/sectigostore.com\/blog\/what-is-a-certificate-authority-certification-authorities-explained\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/sectigostore.com\/blog\/"},{"@type":"ListItem","position":2,"name":"What Is a Certificate Authority? Certification Authorities Explained"}]},{"@type":"WebSite","@id":"https:\/\/sectigostore.com\/blog\/#website","url":"https:\/\/sectigostore.com\/blog\/","name":"InfoSec Insights","description":"SectigoStore.com Blog","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/sectigostore.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/sectigostore.com\/blog\/#\/schema\/person\/559abd5fa4d9d651eaf18d9b9e91a64c","name":"Casey Crane","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/c18d819d34a1995e91a4aa7518e9048df7856f336a1ede2262a572db7b1c2506?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/c18d819d34a1995e91a4aa7518e9048df7856f336a1ede2262a572db7b1c2506?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/c18d819d34a1995e91a4aa7518e9048df7856f336a1ede2262a572db7b1c2506?s=96&d=mm&r=g","caption":"Casey Crane"},"description":"Casey is a writer and editor with a background in journalism, marketing, PR and communications. She has written about cyber security and information technology for several industry publications, including InfoSec Insights, Hashed Out, Experfy, HackerNoon, and Cybercrime Magazine."}]}},"_links":{"self":[{"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/posts\/1483","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/comments?post=1483"}],"version-history":[{"count":0,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/posts\/1483\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/media\/1490"}],"wp:attachment":[{"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/media?parent=1483"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/categories?post=1483"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/tags?post=1483"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}