Jump to content

Tab Stop

Straight answers for everyday tech

Web, security and privacy

Choosing an SSL certificate provider

· 6 min read

Short answer

Every certificate trusted by browsers encrypts traffic the same way. What you pay for is the level of identity checking, the support around it, and sometimes only the brand name on the invoice.

A certificate lets a browser check that it is talking to the real server for a domain and then set up an encrypted connection with it. The protocol doing the work today is TLS. “SSL” is the name of its retired predecessor, and it survives mostly in product names. Since Chrome 68 in July 2018, any page loaded over plain HTTP is labeled “Not secure” in the address bar, so a certificate is no longer optional for a site that wants visitors to stay.

Validation levels

The certificate authority (CA) that signs your certificate checks something about you before issuing it. How much it checks is the main thing that separates cheap certificates from expensive ones.

  • Domain Validation (DV) confirms only that the applicant controls the domain, usually by email, a DNS record or a file placed on the server. It is issued in minutes.
  • Organization Validation (OV) adds a check that the company named in the certificate exists at the stated address. It takes a day or more.
  • Extended Validation (EV) runs a longer set of checks on the legal entity and used to put the company name in green in the browser bar.

The encryption is identical across all three. The EV display is also on its way out: Chrome 77, released on September 10, 2019, moved the company name out of the address bar and into the panel behind the padlock, and Firefox is making the same change. EV still records a verified identity, but most visitors will never see it.

The free option

Let’s Encrypt is a nonprofit CA that has issued free DV certificates since the end of 2015. Its certificates last 90 days and are meant to be renewed automatically by software on the server using the ACME protocol. Certbot is the best-known client, and many hosting control panels now include a one-click Let’s Encrypt button that handles renewal for you. Browsers treat these certificates exactly like paid DV certificates.

Cloudflare also gives a free certificate to every site that routes traffic through its network. That certificate covers the connection between the visitor and Cloudflare. The link from Cloudflare back to your server needs its own certificate if it is to be encrypted as well.

For a blog, a portfolio or a small business site on a host that supports it, Let’s Encrypt is usually all that is needed.

When paying makes sense

A paid certificate is worth it in a few situations. Your host may not support automated renewal, and manual renewal every 90 days is easy to forget. You may need OV or EV because a client, a bank or an internal policy requires a verified company name. Some paid products bundle a warranty, a site seal and phone support. Longer validity also matters to some teams: industry rules set by the CA/Browser Forum’s Baseline Requirements currently allow a certificate to last up to 825 days, so one purchase covers a little over two years without any renewal software.

Coverage: one name, several, or a wildcard

Validation level is one axis. Coverage is the other, and it often matters more to the price.

  • A single-name certificate covers one hostname. Most CAs include both the bare domain and its www version at no extra cost.
  • A multi-domain certificate, also sold as SAN or UCC, lists several different hostnames on one certificate, such as a main site, a shop on another domain and a mail server. It suits small businesses running a handful of names.
  • A wildcard covers every first-level subdomain of one domain, written as *.example.com. It does not cover deeper levels such as a.b.example.com. Wildcards cost several times more than single-name DV certificates when bought for cash, while Let’s Encrypt has issued them free since March 2018 through a DNS-based check.

Who actually issues certificates in 2019

The market looks crowded, but most brand names lead back to a handful of CAs.

DigiCert

DigiCert bought Symantec’s website security business in 2017. It now owns the GeoTrust, Thawte and RapidSSL brands along with the old Symantec line. Chrome 70, released in October 2018, stopped trusting certificates issued under Symantec’s old infrastructure, so anything carrying the Symantec name today is DigiCert under the hood. DigiCert itself sells mainly to larger companies, with OV and EV products and management tools. RapidSSL is its low-cost DV brand, and GeoTrust and Thawte sit between the two.

Sectigo

Comodo’s certificate authority renamed itself Sectigo in November 2018. Its PositiveSSL and EssentialSSL products are among the cheapest DV certificates on the market, and they are what many resellers and hosting companies bundle.

GlobalSign

A Belgian-founded CA that is now part of Japan’s GMO group. It sells DV, OV and EV certificates and has a strong enterprise and device business.

GoDaddy

Best known for domains and hosting, GoDaddy also runs its own CA. Buying a certificate there is convenient for customers already hosting with it. First-year prices are discounted and renewals cost noticeably more.

Entrust Datacard

A long-running CA focused on OV and EV certificates for companies, sold alongside its other identity products.

IdenTrust

IdenTrust issues certificates to banks and government bodies. It also cross-signed Let’s Encrypt’s intermediate certificate, which is how Let’s Encrypt was trusted by browsers from its first day.

SSL.com

A smaller CA that sells directly at lower prices than the large brands and offers multi-year bundles.

Resellers

Namecheap, SSL2BUY, The SSL Store, ClickSSL and Network Solutions do not issue certificates themselves. They buy them in bulk from the CAs above, mostly Sectigo and DigiCert brands, and resell them for less than the CA’s own list price. A DV certificate from a reseller can cost a few dollars a year, while the same class of certificate bought directly from a brand-name CA often runs past $100. The certificate is the same file either way. What differs is support, how smoothly reissues go if you change servers, and whether a promotional first-year price jumps at renewal.

Getting ready to buy

Whatever the source, the steps are similar:

  1. Generate a certificate signing request (CSR) and private key on your server or in your hosting panel. Keep the private key on the server.
  2. Decide the coverage: a single name (with and without www), several names on one certificate, or a wildcard covering every subdomain of one domain.
  3. For DV, make sure you can receive mail at an address such as admin@example.com on your own domain, or can add a DNS record.
  4. For OV or EV, have the company’s registration details ready and make sure the WHOIS record and business listings match them.
  5. Install the certificate with its intermediate chain, then check the result with an SSL testing tool.

Common mistakes after buying

Most trouble comes after the purchase. Installing the certificate without its intermediate chain works in some browsers and fails in others, especially on older Android phones. Forgetting the renewal date takes the site down behind a full-page browser warning, so put the expiry in a calendar or use a monitoring service that emails you. A site that loads over HTTPS but still pulls images or scripts over plain HTTP shows a mixed-content warning; fix the links in the page or theme, then redirect all HTTP traffic to HTTPS.

Distrusted names

In 2017 the major browsers stopped trusting WoSign and its subsidiary StartCom after repeated issuance problems. StartSSL, once a popular source of free certificates, closed as a result. Old tutorials still recommend it, and its certificates no longer work.

Since then, Chrome stopped trusting new certificates from Entrust in November 2024, and Entrust sold its public certificate business to Sectigo in early 2025.