Confirmation about PCI Compliance

The certificates are signed by a publicly trusted root CA, so they’re not self-signed (or self-certified).

The validation levels are about the kind of validation a CA performs on the information included on a certificate.

Domain validation means a CA has verified you have full control over a domain name. OV means you can also include your organization’s name in the certificate details, and that the CA has checked that’s actually you. This is a manual process which cannot be fully automated, so it’s not really something that can be provided for free. EV is basically the same, except that the check is more thorough. EV gets special treatment in some browser UIs (generally, the organization’s name is shown next to the lock). OV isn’t really treated any different; users won’t notice the difference between DV and OV unless they click through various browser dialogs to look at the certificate details.

1 Like