A CA certificate is a digital document that proves a website or service is who it claims to be
A CA certificate (or certificate authority certificate) is a file that your browser or device uses to verify that the person running a website is legitimate. When you visit a website with "https://" in the address bar, your device checks a CA certificate to confirm the site hasn't been impersonated by someone else trying to steal your information.
The certificate contains a public key — a long string of characters — and is signed by a trusted organization called a certificate authority. That signature is what makes it trustworthy. If a hacker tries to create a fake certificate to impersonate a bank or email service, your device will reject it because the signature won't match.
You don't install or manage CA certificates yourself in most cases. Your operating system (Windows, macOS, iOS, Android) comes with a built-in list of trusted certificate authorities. When you connect to a secure website, the verification happens automatically in the background.
Key Takeaways
- A CA certificate proves that a website is run by the organization it claims to be, not by an imposter.
- Your device checks the certificate automatically when you visit a site with "https://" — you don't need to do anything.
- Certificate authorities are trusted third parties that sign certificates; your operating system comes with a list of trusted ones built in.
- If a certificate is expired, self-signed, or from an untrusted authority, your browser will show a warning before you connect.
- Businesses and organizations that run websites or services must obtain a CA certificate from a certificate authority to enable secure connections.
How your device verifies a CA certificate
When you type a web address into your browser, your device performs a handshake with the website's server. The server sends back its certificate, which includes the website's public key and a signature from a certificate authority. Your device checks three things: whether the certificate authority is on its trusted list, whether the signature is valid, and whether the certificate has expired.
If all three checks pass, the connection is secure and you see a padlock icon in the address bar. If any check fails — for example, if the certificate was signed by an unknown authority or has expired — your browser displays a warning. You can usually still proceed, but doing so means you're accepting the risk that the connection might not be secure.
This verification happens in milliseconds. You won't see the details unless something goes wrong, which is by design. The system works silently when it's working correctly.
The difference between CA certificates and self-signed certificates
A self-signed certificate is one that an organization creates and signs itself, rather than having a certificate authority sign it. Self-signed certificates are free and quick to set up, which is why developers often use them for testing or internal networks.
The problem is that your device has no way to verify a self-signed certificate. When you visit a site using one, your browser can't confirm that the server is actually who it claims to be — it could be an imposter. Your browser will show a warning like "Your connection is not private" or "Certificate not trusted."
Self-signed certificates are fine for internal use or development, but any website that handles sensitive information (passwords, payment details, personal data) should use a CA-signed certificate instead. Visitors will trust the connection more, and search engines rank sites with proper certificates higher.
Who issues CA certificates and how they work
Certificate authorities are organizations that have been vetted and trusted by operating system makers like Microsoft, Apple, and Google. Major CAs include DigiCert, Sectigo, GlobalSign, and Let's Encrypt. When a business wants to secure its website, it requests a certificate from one of these authorities.
The CA verifies that the business actually owns the domain name it's requesting a certificate for. This verification can be as simple as checking an email address or as thorough as reviewing business documents, depending on the type of certificate. Once verified, the CA signs the certificate with its own private key, creating a signature that proves the certificate is legitimate.
Your device trusts the CA's signature because the CA's own certificate is already installed on your system. It's a chain of trust: you trust the CA, the CA trusts the website, so you can trust the website.
Why websites need CA certificates
Without a CA certificate, anyone could set up a fake website that looks identical to a real one and intercept data sent to it. A hacker could create a copy of your bank's login page, and without certificate verification, you might not notice the difference. The CA certificate prevents this by proving that the website you're visiting is actually run by the bank, not by an imposter.
CA certificates also enable encryption. The public key in the certificate is used to encrypt data sent from your device to the server, and only the server's private key can decrypt it. This means even if someone intercepts your data in transit, they can't read it.
Search engines also favor websites with CA certificates. Google and other search engines rank sites with "https://" higher than those without, which gives businesses a reason to obtain certificates beyond just security.
What happens when a CA certificate expires
Every CA certificate has an expiration date, usually one to three years from the date it was issued. When a certificate expires, it's no longer valid, and your browser will show a warning when you try to visit the site. The website owner must renew the certificate before it expires to keep the connection secure.
Expired certificates don't mean the website is unsafe — it just means the owner hasn't renewed it. The website might still be legitimate, but you can't verify that without a current certificate. Most website owners set up automatic renewal so they don't have to remember to do it manually.
CA certificates on internal networks and devices
Organizations sometimes create their own certificate authority for internal use. A company might issue certificates for its internal email server, file storage, or employee portal. Employees' devices are configured to trust the company's CA, so they can connect to these internal services securely without warnings.
This is different from a public CA certificate. An internal CA certificate only works for people whose devices have been configured to trust it. If you tried to visit an internal company website from your personal phone without that configuration, you'd see a warning.
Some organizations also use CA certificates to monitor or filter network traffic on their devices. They install their own CA certificate on employee computers so they can inspect encrypted connections for security threats. This is a legitimate use in corporate environments, though it does mean the organization can technically see encrypted data on those devices.
Frequently Asked Questions
Why does my browser say a certificate is not trusted?
Your device doesn't recognize the certificate authority that signed it. This happens with self-signed certificates, expired certificates, or certificates from authorities your system doesn't trust. Check the website address to make sure you're on the right site, and contact the website owner if you believe the certificate should be trusted.
Can I see what information is in a CA certificate?
Yes. In most browsers, you can click the padlock icon in the address bar and view certificate details. You'll see the organization name, the domain it covers, the expiration date, and the certificate authority that signed it. This information is public and designed to be visible.
Do I need to do anything to use a CA certificate?
No. Your device handles CA certificate verification automatically. You only need to be aware of warnings your browser shows — if you see a certificate warning, it's a sign something might be wrong with the connection.
What's the difference between a CA certificate and an SSL certificate?
An SSL certificate is the certificate a website uses to secure connections. A CA certificate is the certificate that proves the SSL certificate is legitimate. The terms are sometimes used interchangeably, but technically a CA certificate is what validates an SSL certificate.
Can a hacker create a fake CA certificate?
A hacker can create a certificate, but they can't create one that your device will trust unless they compromise a certificate authority or trick your device into trusting their own CA. This is why keeping your operating system updated is important — updates include new trusted CAs and remove ones that have been compromised.