SSL/TLS glossary

What is a certificate authority?

A certificate authority is an organisation trusted to verify that whoever requests a certificate for a domain actually controls it, and to sign certificates recording that fact. Browsers and operating systems ship a list of trusted CA roots; everything the web calls "a valid certificate" reduces to a signature chain ending at one of them.

The accountability structure is unusual: CAs answer not to their customers but to the root programs — Mozilla, Google, Apple, and Microsoft — that decide whose roots ship. The CA/Browser Forum, where CAs and browser vendors vote jointly, publishes the Baseline Requirements every public CA must follow: how domain control is validated, how quickly revocations must happen, what audits are mandatory. A CA that fails badly enough gets distrusted, and it has happened to large CAs, with browsers announcing dates after which the CA's new certificates simply stop working.

The direction of travel is automation and shorter lifetimes. ACME turned issuance into an API call, and free CAs — Let’s Encrypt above all — made certificate cost a solved problem. Maximum certificate lifetime, 398 days for years, began stepping down in March 2026 under a CA/Browser Forum ballot and is scheduled to reach 47 days in March 2029. The practical meaning is blunt: renewal is becoming a monthly event, manual renewal is becoming impossible, and the interesting question about any CA is no longer price but how well your automation talks to it.

Choosing a CA therefore comes down to operational fit: ACME support, issuance reliability, rate limits that match your issuance pattern, and a track record with the root programs. The certificate itself is a commodity; the issuance pipeline is not.

Source: CA/Browser Forum Baseline Requirements

Common questions

Does it matter which CA issues my certificate?

Browsers treat all trusted CAs identically, so not for compatibility. It matters operationally: ACME support, reliability, and rate limits differ, and a CA in conflict with the root programs is a risk you inherit.

Why are certificate lifetimes getting shorter?

Shorter lifetimes shrink the window in which a stolen key or stale validation stays useful, and they force automation, which fails less than humans. The CA/Browser Forum schedule steps maximums down from 200 days now to 47 in March 2029.

Reading up because something broke? Check the certificate you actually serve — 3 monitored free, no card.

One check now, or every day from now on.

3 certificates free forever · No agent · No credit card