Understanding the legal requirements for SSL certificates helps you choose the right certificate for your website and prepare the necessary verification documents. This guide explains the validation process for DV, OV, and EV SSL certificates in a simple and structured way.
Key Takeaways
- Validation Levels – Understand DV, OV, and EV certificate requirements.
- Security Purpose – SSL certificates encrypt data and verify identity.
- Legal Checks – Higher validation requires stricter business verification.
- CA/B Forum – Industry standards govern SSL certificate issuance.
- Trustname Support – Simplifies the SSL verification process.
TABLE OF CONTENTS
- Key Takeaways
- What Roles Do SSL Certificates Play In Online Security?
- SSL Certificate Validation Tiers
- The CA/Browser Forum - Guiding SSL Certificate Issuance
- Legal Requirements For The Different SSL Certificate Tiers
- Trustname Simplifying The Legal Side Of SSL Certificates
DV SSL certificates can be issued with a simple domain control check; however, certificate authorities must follow specific legal guidelines and carry out comprehensive checks before issuing OV and EV SSL certificates.
Want to find out the legal side of SSL certificates? This piece is for you.
SSL certificates are classified into different tiers based on how much verification is needed. And why the need for extra validation? It's simple not every SSL enabled website is legit.
Premium OV and EV SSL certificates make it incredibly hard for phishing websites to get certified, and when visitors see a website with either of these, customers can rest assured that they're in safe hands.
Ready to learn the legal requirements for SSL certificates? Let's see them. But first…
What Roles Do SSL Certificates Play In Online Security?
It's important to understand that SSL certificates play two roles in online security first, they encrypt your website browser communication, and second, they verify the identity and legitimacy of the entity that owns a website address.
Focusing on the second point, a premium SSL certificate allows businesses to establish more credibility online and proves the domain owner's right to represent their brand online.
SSL Certificate Validation Tiers
Many webmasters don't know much about SSL certificates and usually don't need to since most web hosting providers give you a free SSL certificate on every hosting plan you buy.
However, while this free SSL certificate may be great for a blog or small eCommerce website, premium SSL certificates are essential for websites of businesses and organizations that collect sensitive data.
SSL certificates are classified according to two main criteria: based on the number of domains they protect and based on the extent of verification required before they are issued to you as a webmaster.
Let's see the different validation tier SSL certificates…
- DV SSL Certificates
Domain validation (DV) SSL certificates are the most basic SSL certificates on the market. All you need to do to get one is prove that you have admin access to the domain in question, and you can get a DV SSL certificate.
Ever bought a web hosting plan and had an SSL certificate added on for free? That was a basic DV SSL certificate. Purchase a hosting plan from Trustname, and you won't need to prove your own domain.
- OV SSL Certificates
Organization validation (OV) SSL certificates are the first premium tier of SSL certificates. Think of it like this: DV SSL certificates are focused on the webmaster's convenience. OV SSL certificates have the web visitor's security in mind.
To get an OV SSL certificate, the business requesting it must prove its legitimacy. OV SSL certificates are the least recommended SSL tier for eCommerce businesses that collect payment information and other sensitive data.
- EV SSL Certificates
Extended Validation (EV) SSL certificates provide the highest level of credibility for online businesses and require more stringent checks than OV SSL certificates.
In addition to all the checks required with an OV SSL certificate, the certificate issuer will also verify the business's contact details, check the brand's history and past reputation, and reach out via phone call.
Large enterprises, businesses, and Fortune 500 companies typically use premium EV SSL certificates for their websites. The vetting process associated with EV SSLs makes it incredibly hard for illegitimate websites to get them.
The CA/Browser Forum - Guiding SSL Certificate Issuance
Before we get into the fine print on the legal requirements for the different SSL certificate tiers, it is important to mention the organization that sets these regulations in the first place.
Enter the Certificate Authority Browser Forum (CA/Browser Forum). The CA/B forum is a group founded in 2005 and is made up of certificate issuers, suppliers of internet browser software.
Other applications that use SSL/TLS certificates, which defines regulations for the certificate authority industry to ensure the highest security on the internet.
These regulations must be adhered to by all certificate authorities, even those that are not members of the group.
Legal Requirements For The Different SSL Certificate Tiers
And now, onto the main event. What are the legal requirements before SSL certificates can be issued? Let's see them!
- DV SSL Certificates
According to the CA/B Forum, the legal requirements for a DV SSL certificate are only that the certificate authority validates that the applicant owns or controls the domain. Here are some of the allowed validation methods for DV SSL certificates.
[+] [List] Green Unordered - Email, FAX, SMS, or postal mail
The CA can confirm the applicant's control of the domain by sending a random value to an email address, fax/SMS number, or postal mail identified as a domain contact. The email contacts can be those in the DNS CAA and TXT records.
- Constructed Email
The CA can confirm the applicant's control by sending an email to one or more addresses using 'admin', 'webmaster', 'administrator', 'hostmaster' or 'postmaster' followed by the at sign '@' and then the authorization domain name.
- DNS Change
The applicant's control over the domain can also be verified by the CA by confirming the presence of a random value in the domain's DNS CNAME, TXT, or CAA records.
- Validating The Applicant As The Domain Contact
The CA may also confirm the requester's control over the domain by verifying that the applicant is a domain contact. This, however, applies only if the CA is also the domain registrar or an affiliate of the registrar.
This is why at Trustname, whenever you buy a hosting plan for a domain you manage on our platform, you get a free SSL certificate without needing to do the domain control verification since we are also your registrar.
- Phone Contact
The CA may also verify the requester's control over the domain by calling the domain contact's phone number to validate the authorized domain name (ADN). The CA can also source the domain contact from the DNS TXT and CAA phone contacts.
- Agreed-upon Change To The Website
And finally, the domain control may be verified by the CA confirming that a random value is contained in a file on the authorized domain that is uploaded to a specific location by the domain owner.
Check out the baseline SSL issuance requirements as specified by the CA/B Forum for more information.
- Email, FAX, SMS, or postal mail
- V SSL Certificates
OV SSL certificates require additional verification on top of the domain verification process. According to the CA/B Forum, the issuer must verify the company name and domain name through the use of public databases. Some of the legal requirements associated with OV SSL certificates include:
[+] [List] Green Unordered - Organizational Verification
The very essence of an OV SSL certificate is to verify the identity of your organization. Most CAs will request documents that show your business is verified in your jurisdiction.
To confirm your organization's identity, a simple method is for the CA to require your business to be listed in a government directory of businesses in your jurisdiction. They may also check for your business in a third-party database that is trusted.
[+] [Callout] Info Insert title here [+] [Callout] Title/Title with Icon -> Some popular ones include: Dun & Bradstreet, Hoovers, Better Business Bureau, and the GOV. UK Companies House.
Other CAs will require an official business license, an article of incorporation, or a registration application document to verify your organization's identity.
- Requester Identity Verification
Some certificate authorities also require that the requester verify their identity. For this step, you'd need to upload a government-issued ID and a photo of you holding the same ID.
- Physical Address Or Local Presence Verification
The next requirement is that the CA verify the business's physical address and local presence in its specified jurisdiction. Similar to your business's identity verification, the CA will confirm your organization's physical presence using public databases or by requesting documents.
Verifying your organization's physical address adds an extra layer of credibility for your business.
- Phone Number Verification
Most CAs will require contact information for the domain name to be verified. This could be the domain contact email address or phone number. By sending a confirmation prompt to the contact details, the CA can be assured of reliable communication for other steps.
- Decision-maker Verification/Callback
Another important verification is confirming that the person making the request is authorized to do so and has legal control over the domain name. To initiate the callback, the issuer will typically send a callback email to your business's official email.
In the email, you will find instructions on how to receive an automated call to the verified phone number of your business. Once the callback is initiated, you will receive a call and be told a one-time verification code to be uploaded to the verification portal.
The certificate authority then notifies you how long it will take for your SSL certificate to be ready.
- Organizational Verification
- EV SSL Certificates
And at the highest level of the spectrum - EV SSL certificates. The CA/B Forum sets standards for the verification of EV SSL certificates.
[+] [List] Green Unordered - Applicant's Legal Existence And Identity
The CA/B Forum sets requirements to verify the applicant's legal existence based on whether they are a private organization, government entity, business entity, or non-commercial entity.
For businesses, the CA must verify that the business is under the specified name, verify the organization name in the jurisdiction's registration agency, and verify the identity of the principal individual.
- Verification Of Applicant's Physical Existence
For the next phase, the CA will verify the organization's physical existence and business presence with a QGIS, QIIS, or QTIS and may also request photos of the establishment.
And for businesses not in the place of incorporation, the CA will request a verified professional letter that indicates the address of the requester's place of business.
- Verified Method Of Communication
Next, the CA must verify a method of communication with the applicant - a telephone number, fax, email address, or postal address.
First,t the CA will verify that the method of communication actually belongs to the applicant. And secondly, the CA will verify the method specified by receiving an affirmative response that makes it clear that the applicant can be contacted reliably using the method of communication.
- Verification Of Applicant's Operational Existence
Next, the CA confirms that the applicant can do business and verifies their operational existence.
The CA can confirm the business's operational existence by checking that they have been in business for at least 3 years, is listed in a current QIIS or QTIS, by verifying the existence of a current business bank account, or through a verified professional letter.
- Verification Of Name, Title, And Authority Of Contract Signer And Certificate Approver
Next, the CA must verify the name and title of the contract signer and
the certificate approver, and that they represent the applicant. The CA must also confirm the signing authority of the contract signer and the EV authority of the certificate approver.
- Verification Of Signature On Subscriber Agreement And EV Certificate Requests
Next, the CA/B Forum requires that the subscriber agreement and each non‐pre authorized EV certificate request must be signed.
The EV certificate request form must also be signed by the entity submitting the document.
All applicable signatures relating to an EV certificate request must be legally valid and include an enforceable seal or handwritten signature, or a legally valid and enforceable electronic signature that shows that the applicant acknowledges the terms of the document.
- Verification Of Approval Of EV Certificate Request
The CA/B Forum also states that in cases where an EV certificate request is sent in by a certificate requester (e.g a web hosting company/domain registrar like Trustname), before the CA issues the requested EV Certificate.
The CA MUST verify that an authorized certificate approver (you or a decision maker at your company) reviewed and approved the EV certificate request.
- Verification Of Certain Information Sources
According to the CA/B Forum, for legal opinions submitted, the CA must verify the status of the author, the basis of the opinion, and its authenticity.
Other documents like accountant letters, or a face-to-face valuation, independent validation from the applicant, a qualified independent information source, or a qualified government information source must be verified.
- Other Verification Requirements
The CA/B Forum has also laid out verifications for high-risk businesses (a core part of our target market at Trustname). The CA must also confirm whether the business belongs to a denied list or legal block list in the CA's jurisdiction(s) of operation.
The CA must also verify the applicant's relationship to a parent, subsidiary, or affiliate organization if they are verifying the applicant using information from the affiliated company.
Check out the guidelines for issuing and managing EV SSL certificates as specified by the CA/B Forum for more information.
- Applicant's Legal Existence And Identity
Trustname Simplifying The Legal Side Of SSL Certificates
Want to save yourself the hassle of getting a DV, EV, or EV SSL certificate? Use Trustname. In legal terms, Trustname is your certificate requester, and many of the backend processes will be handled by us.
You'll only need to provide your business verification documents (for OV SSL certificates) and any extra documents (for EV SSL certificates) when requested.
Check out our complete guide for purchasing an SSL certificate on Trustname and get your website secured today.
Ciao!
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article