What Is a Digital Certificate?

Laptop, security key, and blurred certificate document illustrating digital certificate validation

A digital certificate is a signed electronic record that connects a public cryptographic key with an identified subject, such as a website domain, organization, person, or device. It does not contain the subject’s private key and is not itself an encryption algorithm. Instead, it supplies information that another system can validate before trusting the public key. On the web, certificates help a browser determine whether the server presenting a key is authorized to use the requested domain name. That verified key then participates in establishing the encrypted HTTPS connection used for the session.

Most web certificates follow the X.509 format profiled for Internet use. A certificate includes the subject name, public key, issuing authority, serial number, validity period, permitted uses, and a digital signature made by the issuer. Modern website certificates also list the domain names they cover in a subject alternative name field. The issuer’s signature protects the certificate data from undetected alteration. Anyone with the issuer’s public key can verify that signature, but the signature is meaningful only if the verifier already has a reason to trust the issuer.

That trust is organized as a chain. Operating systems and browsers carry stores of selected root certificate authorities. A root authority may sign an intermediate authority’s certificate, and that intermediate may sign a website certificate. When a server sends its certificate and supporting intermediates, the browser builds a path toward a trusted root. It checks each signature, ensures the requested domain appears in the certificate, confirms the current time falls within the validity period, and verifies that key-usage and policy constraints allow the intended purpose. Failure at any essential step produces a certificate warning.

Before issuing a public website certificate, a certificate authority validates that the applicant controls the named domain. Some certificate types also include validated organizational information, but a certificate does not guarantee that a website is honest, safe, or free of malware. It establishes a particular identity or control claim according to the authority’s process. Attackers can obtain valid certificates for domains they control, including deceptive look-alike names. Users still need to evaluate the actual address, and applications must handle names and validation results correctly.

Certificates expire so keys and identity claims are reviewed and replaced regularly. They can also be revoked when a private key is compromised or the certificate was issued incorrectly. Browsers may consult revocation information, use short-lived certificates, or rely on other ecosystem controls such as public certificate-transparency logs. Revocation is difficult because checks must be reliable, fast, and privacy-conscious, and clients may not always receive a current answer. Automated renewal reduces outages, but operators must still protect private keys and monitor deployments for incorrect or missing certificate chains.

A valid certificate is one part of secure communication. The server must keep its private key secret, use current protocols, and configure the correct certificate for every hostname. The client must have an accurate clock, an updated trust store, and validation code that does not ignore errors. Private organizations may operate their own certificate authorities for internal systems, but their roots must be distributed securely to participating devices. For readers, the key distinction is simple: the certificate makes a public key accountable to an identity claim; cryptographic protocols use that verified key to protect later communication. Certificate validation also depends on exact name matching. A certificate issued for one domain does not automatically cover a similar spelling or every subdomain, and wildcard certificates have defined limits. Servers commonly send intermediate certificates along with their own so clients can build the chain efficiently. When those supporting certificates are omitted or ordered incorrectly, one browser may recover by fetching a missing issuer while another client fails, producing inconsistent results that careful deployment testing should catch.

No. A certificate distributes a public key and identity information; the corresponding private key must remain secret with its owner.

Browsers and operating systems maintain trusted root stores. A presented certificate must build a valid signature chain to one of those selected roots.

No. It confirms a defined identity or domain-control claim and supports encryption, but it does not guarantee honest content or freedom from malware.

Explore more "Explainers"

Discover additional explainers across politics, science, business, technology, and other fields. Each explainer breaks down a complex idea into clear, everyday language—helping you better understand how major concepts, systems, and debates shape the world around us.