What certificate signing does
Certificate signing is the process that proves a website or software is who it claims to be. When you visit a website, your browser receives a digital certificate — a file that contains the site's identity and a public key for encryption. That certificate has been signed by a trusted authority, which means someone verified the website owner's identity before issuing it. The signature is cryptographic proof that the certificate has not been tampered with and that the authority really did issue it.
Without certificate signing, a criminal could create a fake website that looks identical to your bank's site, and your browser would have no way to know the difference. The signature solves this by creating a chain of trust: your browser trusts certain certificate authorities (CAs), so when it sees a certificate signed by one of those authorities, it knows the website is legitimate.
Key Takeaways
- A certificate authority signs a website's certificate to prove the site's identity and prevent imposters from intercepting your connection.
- Your browser comes pre-loaded with a list of trusted certificate authorities and checks their signatures automatically when you visit a website.
- If a certificate is not signed by a trusted authority, your browser displays a warning and may block the connection.
- Certificate signing is the foundation of HTTPS connections and protects you from man-in-the-middle attacks where someone intercepts your data in transit.
How the signing process works
The process begins when a website owner generates a certificate request and sends it to a certificate authority. The CA verifies that the person requesting the certificate actually owns or controls the domain name — usually by checking DNS records, sending an email to the domain owner, or asking for other proof of ownership. Once verified, the CA signs the certificate using its own private key.
The signature is a mathematical function that proves two things: that the CA created the certificate, and that no one has changed it since. Your browser has a copy of the CA's public key built in, so it can verify the signature without contacting the CA every time you visit a website. If the signature is valid, the browser trusts that the certificate is genuine.
Why your browser trusts certain authorities
Your browser comes with a pre-installed list of root certificates from major certificate authorities like DigiCert, Let's Encrypt, Sectigo, and others. These are organizations that have met strict security standards and agreed to verify website owners' identities before signing their certificates. When you see a green lock icon in your address bar, it means the website's certificate was signed by one of these trusted authorities.
If a website presents a certificate signed by an authority your browser does not recognize, or if the signature is invalid, your browser will display a warning. This might happen if you visit a site with an expired certificate, a certificate for a different domain, or one signed by a self-signed authority (where the website signed its own certificate instead of having a CA do it).
The difference between self-signed and CA-signed certificates
A self-signed certificate is one where the website owner signs their own certificate using their own private key. This is technically valid encryption, but your browser has no way to verify that the certificate actually belongs to the site you think you are visiting. Self-signed certificates are common in internal company networks or for testing, but they trigger browser warnings on the public internet.
A CA-signed certificate has been signed by a trusted third party that verified the website owner's identity first. This creates the chain of trust: you trust the CA, the CA verified the website owner, so you can trust the website. This is what protects you when you enter a password or credit card number — the signature proves you are talking to the real website, not an impostor.
Certificate signing and HTTPS connections
Every HTTPS connection relies on certificate signing. When you visit a website with HTTPS, your browser checks the certificate's signature before establishing an encrypted connection. If the signature is invalid or missing, the browser will not complete the handshake. This prevents a criminal on your network from intercepting your traffic by pretending to be the website.
The signature does not encrypt your data — that is what the certificate's public key does. Instead, the signature proves that the public key belongs to the website you intended to visit. Without it, encryption alone would not protect you, because you would not know whether you were encrypting your data for the real website or for an attacker's fake one.
What happens when a certificate signature fails
If your browser detects a problem with a certificate's signature, it will display a warning before allowing you to proceed. Common reasons include: the certificate was signed by an authority your browser does not trust, the certificate has expired, the certificate is for a different domain than the one you are visiting, or the certificate has been revoked by the CA.
In most cases, you should not ignore these warnings. They usually mean either the website has a configuration problem, or someone is trying to intercept your connection. Some browsers allow you to proceed anyway, but doing so means you are no longer protected by the chain of trust — you are accepting the risk that the site might not be what it claims to be.
Why certificate authorities need to verify identity
The entire system depends on certificate authorities actually verifying that the person requesting a certificate owns the domain. If a CA signed a certificate for your bank's domain without checking who requested it, a criminal could get a valid certificate for that domain and your browser would trust it.
Different types of certificates require different levels of verification. A basic domain validation certificate only requires proof that you control the domain's DNS or email. An organization validation certificate requires additional proof that the organization exists and is legitimate. An extended validation certificate requires the most thorough checks, including legal documents and phone calls. The level of verification is usually reflected in the certificate details your browser displays.
Frequently Asked Questions
Why does my browser warn me about a certificate even though the website works?
The website may work, but the certificate signature is invalid or missing. This usually means the certificate was signed by an authority your browser does not trust, or the certificate does not match the domain you are visiting. The warning exists because encryption alone does not protect you — you also need proof that you are talking to the real website.
Can I use a website with a self-signed certificate safely?
A self-signed certificate provides encryption, but not proof of identity. Your data is scrambled in transit, but you have no way to know whether you are sending it to the real website or to an attacker. Self-signed certificates are acceptable for internal networks where you control both ends, but not for public websites where you need to verify identity.
What does it mean if a certificate is revoked?
A revoked certificate is one the certificate authority has invalidated before its expiration date, usually because the private key was compromised or the domain ownership changed. Your browser checks a revocation list to see if a certificate has been revoked, and will warn you if it has. A revoked certificate means you should not trust that website.
Do I need to do anything to verify a certificate signature myself?
No. Your browser checks the signature automatically every time you visit a website. You only need to pay attention if your browser displays a warning. If you see a green lock and no warnings, the signature is valid and the certificate is trusted.
How long does a certificate signature last?
Certificates are typically valid for one to three years from the date they are signed. When a certificate expires, the website owner must request a new one from the certificate authority, which will sign it again. Your browser will warn you if you visit a website with an expired certificate, even if the signature was valid when it was issued.