A certificate authority offers domain-validated, organisation-validated and extended-validation certificates: what does each level actually verify?
answer
- all three bind the same key
- control of a name versus existence of an entity
- the higher levels add, they do not replace
- jurisdiction and registration identifier in the subject
- the interface treatment was retired
basics
~20 sDomain validation checks only that the applicant can act on the name. Organisation validation adds checks that a named legal entity exists and the applicant is connected to it, and extended validation does that under a stricter procedure with more identifiers in the subject.
solid answer
~40 sAll three levels bind the same submitted public key to the same names, and the resulting connection is cryptographically identical — the levels differ in what the authority checked about the *requester* before signing. **Domain validation** verifies control of the name: the applicant performs an act only someone controlling the name could perform, which says nothing about who they are. **Organisation validation** keeps that check and adds vetting of a legal entity against official registry records, plus a check that the applicant is connected to it, so the `subject` carries a verified organisation name. **Extended validation** is organisation validation under a stricter specified procedure, with jurisdiction and registration identifiers in the `subject`. The distinction matters much less than it used to, because the distinct interface treatment browsers once gave the highest level was retired.
code
pseudocode · 15 linesdomain validation:
require an act only a party controlling the name could perform
outcome: this key may be bound to this name
established about the applicant: nothing
organisation validation:
everything domain validation requires, and
confirm the named organisation exists in an official registry
confirm the applicant is connected to that organisation
outcome: subject carries a vetted organisation name
extended validation:
everything organisation validation requires, under a stricter procedure
subject also carries jurisdiction and registration identifier
outcome: same key, same names, more vetting behind the subjectgo deeper
Learn the one-line version: the lowest level checks that you can act on the name, the higher levels also check that a real company exists behind the request. The connection itself is the same either way.
Be precise that the higher levels add to the control-of-name check rather than replacing it, and that what actually lands in the certificate is extra identity information in the subject, not stronger cryptography.
Argue the operational side: manual vetting fights short lifetimes and automated renewal, and nothing surfaces the extra assurance to an end user any more, so the level is a procurement decision rather than a security control.
The question a lead owns is what your estate depends on for identity at all. If a counterparty must know which legal entity stood behind a statement, decide where that is proved and who pays the renewal cost for it.
## What all three levels share A validation level is a statement about **how hard the authority looked before signing**, and nothing else. At every level the applicant submits a certification request, the authority verifies the proof of possession, and the certificate binds the submitted public key to the names the authority was willing to vouch for. The key algorithm, the key size and the strength of the resulting connection are chosen independently of the validation level. A connection using a domain-validated certificate is not weaker, slower or more breakable than one using an extended-validation certificate. What differs is the **identity assurance carried in the subject** — and, crucially, how much of that assurance any party downstream can actually act on. ## Domain validation Domain validation answers exactly one question: *can this applicant act on this name?* The authority requires the applicant to perform an act that only someone with control of the name could perform — changing what the name serves or resolves to, or answering at an address published for the domain — and if the act succeeds, the authority is willing to bind a key to that name. Notice what it does **not** establish: - It does not establish who the applicant is. No person or company is identified. - It does not establish ownership. Control is not ownership; whoever operates the name today passes, including someone who has taken it over. - It does not establish that the operator is honest or that the site is safe. This is the level nearly all of the public web runs on, and it is the right level for it: it is exactly what a client needs in order to know the key it is talking to belongs to the name it asked for. ## Organisation validation Organisation validation keeps the control-of-name check — it does not replace it — and adds a second, unrelated investigation into a **legal entity**. The authority checks that the organisation named in the request exists in an official registry, confirms details such as its registered address through independent sources, and confirms that the applicant is connected to that organisation. The result is that the `subject` carries an organisation name a third party has actually checked, rather than one the applicant typed. ## Extended validation Extended validation is organisation validation performed under a stricter, published procedure with less discretion left to the authority, and with additional identifiers in the `subject` — the jurisdiction of incorporation and the registration number that ties the name in the certificate to a specific entry in a specific registry. That last part is the real technical difference: an organisation name alone is ambiguous across jurisdictions, while a jurisdiction plus a registration number is not. | Level | Control of the name | Legal entity checked | What the subject carries | |---|---|---|---| | Domain validation | yes | no | the name only | | Organisation validation | yes | registry check plus applicant link | a vetted organisation name | | Extended validation | yes | stricter specified procedure | organisation, jurisdiction, registration identifier | ## Why the distinction shrank The higher levels were sold on the idea that a client would surface the vetted identity to a human, who would then make a judgement about it. That interface treatment was retired after it became clear people did not read it and that a correctly obtained certificate for a plausible-looking entity name would pass the same check. Two consequences follow: 1. The extra vetting is now visible only to software that deliberately reads the `subject`, or to a human who inspects the certificate — which almost nobody does during normal browsing. 2. Because higher-level issuance is manual and slow, it works against short lifetimes and automated renewal, which are the operational habits that actually reduce risk. ## Where the levels still earn their place - Where a **relying party is a program you control** and can be made to check the organisation identifiers deliberately — a partner integration, a payment or reporting interface, a regulated submission channel. - Where a rule imposed on you by a counterparty or a regulator names the level, which is common where a named legal entity must be provable to an auditor. - Where the certificate is the evidence trail rather than the transport: a statement whose value lies in naming which legal entity stood behind it years later. For everything else, the honest answer in an interview is that the level does not change what the connection guarantees, and that operational habits — short lifetimes, automated renewal, controlling who can obtain a certificate for your names at all — buy more than the vetting tier does.
- Does a domain-validated certificate make a connection weaker than an organisation-validated one?No. The validation level is a statement about what the authority checked before signing, not about cryptography. Key algorithm, key size and the parameters negotiated on the connection are chosen independently of the level. Two certificates for the same name at different levels bind the same kind of key and give a client the same assurance that the key belongs to the name; only the identity information in the subject differs.
- An attacker takes over a lapsed domain name and obtains a domain-validated certificate for it. Has anything gone wrong with validation?No — and that is the uncomfortable part of the answer. Domain validation verifies control, and the attacker genuinely controls the name. The certificate correctly states what it states. The failure is upstream, in losing the name, and the defences are correspondingly upstream: keeping registrations current, and constraining which authorities may issue for your names at all.
- Where does organisation validation still buy something real?Where a relying party is a program you control and can be made to read the organisation identifiers deliberately, or where a counterparty or regulator requires a named legal entity to be provable. The value is in the jurisdiction and registration identifier, which disambiguate an organisation name across registries. For a browser-facing public site it buys little, because nothing surfaces the vetting to the person looking at the page.
saying these in an interview costs you the question
- Says extended validation means stronger encryption on the connection.
- Thinks domain validation proves the applicant owns the domain.
- Believes organisation validation skips the control-of-name check.
- Claims the browser still shows a distinct indicator for the top level.
- Treats the validation level as something a client can check automatically.
- Says a domain-validated certificate is untrusted by default.