Certificate Authority
- In Turkish
- Sertifika Otoritesi
In short
A certificate authority is a trusted organization that issues digital certificates confirming a public key belongs to a specific website, company, or person.
What is a certificate authority?
A certificate authority, or CA, vouches for identities on the internet. When a website wants to use HTTPS, it creates a key pair and asks a CA for a certificate: a signed document stating that this public key belongs to this domain name. The CA checks that the requester really controls the domain, then signs the certificate with its own private key.
Browsers and operating systems ship with a list of trusted root certificates, known as the trust store. Root CAs rarely sign website certificates directly; instead they sign intermediate certificates, which in turn sign the site's certificate, forming a chain of trust that the browser verifies during the TLS handshake, together with the domain name and the expiry date. Validation is mostly automated today through the ACME protocol, which lets a server prove domain control and renew certificates on its own, and every public website certificate is also recorded in Certificate Transparency logs so that misissued certificates can be spotted.
A CA is like a passport office: the office checks who you are once and issues a document that border guards around the world accept, because they trust the office rather than knowing you personally. Besides websites, CAs issue certificates for code signing, email encryption, and devices, and companies often run their own private CA for internal services and mutual TLS. Certificate lifetimes keep shrinking: industry rules are cutting the maximum validity of public website certificates in steps, down to 47 days by 2029, which makes automated renewal essential.
A certificate authority is often confused with the certificate itself or with TLS. The certificate is the signed document, TLS is the protocol that uses it to set up an encrypted connection, and the CA is the third party whose signature makes the certificate trustworthy. A self-signed certificate works technically but has no CA behind it, so browsers show a warning unless you add it to the trust store yourself.
Key takeaways
- A CA issues and signs certificates that bind a public key to a domain or identity.
- Browsers trust a built-in set of root CAs and verify the chain of trust through intermediates.
- Domain validation and renewal are commonly automated with the ACME protocol.
- Certificate Transparency logs publicly record issued certificates to catch misuse.
- Self-signed certificates have no trusted CA behind them and trigger browser warnings.
Example
# Show the certificate chain a site presents, from its own certificate upward
openssl s_client -connect example.com:443 -servername example.com -showcerts < /dev/null
# Print who the certificate is for, which CA issued it, and when it expires
echo | openssl s_client -connect example.com:443 -servername example.com 2>/dev/null | openssl x509 -noout -subject -issuer -datesReaders ask
What does a certificate authority do?
It verifies that whoever requests a certificate controls the domain or is the organization named, then signs the certificate with its own key. Browsers trust sites whose certificates chain back to a CA in their trust store.
What is the difference between a root CA and an intermediate CA?
A root CA's certificate is built into browsers and operating systems, and its key is kept offline for safety. It signs intermediate CA certificates, which do the day-to-day signing of website certificates, so a compromised intermediate can be revoked without replacing the root.
What happens if a certificate authority is compromised?
An attacker could issue valid-looking certificates for any domain and intercept traffic. Browsers respond by distrusting the CA, and Certificate Transparency logs help detect such misissued certificates quickly.
See also
- TLSSecurity, p. 45TLS is the cryptographic protocol that encrypts data sent over a network and verifies the server's identity, securing HTTPS, email, and many other connections.
- HTTPSSecurity, p. 17HTTPS is the secure version of HTTP that encrypts traffic between a browser and a website with TLS, protecting data from eavesdropping and tampering.
- Public-Key CryptographySecurity, p. 30Public-key cryptography is a method that uses a pair of linked keys, a public key anyone can see and a private key kept secret, to encrypt and sign data.
- Digital SignatureSecurity, p. 11A digital signature is a cryptographic value made with a private key that proves who produced a message or file and that it hasn't changed since it was signed.
- Man-in-the-Middle AttackSecurity, p. 21A man-in-the-middle attack happens when an attacker secretly relays, and may alter, messages between two parties who think they are talking directly.
- HSTSSecurity, p. 16HSTS is a security header that tells browsers to connect to a site only over HTTPS for a set period, blocking insecure HTTP connections and downgrade attacks.
Spotted a mistake or something missing on this page?Suggest an edit