# Question about the certificate authority

**URL:** <https://community.letsencrypt.org/t/question-about-the-certificate-authority/226220>\
**Category:** Issuance Tech\
**Created:** [September 20, 2024, 8:12pm UTC](https://community.letsencrypt.org/t/question-about-the-certificate-authority/226220 "2024-09-20T20:12:32Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![lauren.oregan](https://avatars.discourse-cdn.com/v4/letter/l/f475e1/32.png) [@lauren.oregan](https://community.letsencrypt.org/u/lauren.oregan)\
**Post date:** [September 20, 2024, 8:12pm UTC](https://community.letsencrypt.org/t/question-about-the-certificate-authority/226220/1 "2024-09-20T20:12:32Z")

</div>

Does this CA validate the identity of the domains owner?

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [September 20, 2024, 8:17pm UTC](https://community.letsencrypt.org/t/question-about-the-certificate-authority/226220/3 "2024-09-20T20:17:16Z")

</div>

No.  
Only "control" is validated [automatically].

See: [FAQ - Let's Encrypt (letsencrypt.org)](https://letsencrypt.org/docs/faq/)

 ![image](https://global.discourse-cdn.com/letsencrypt/original/3X/1/9/19716c1884d1bd4c15a7d6a5ba6c941f39128379.png)  
 ![image](https://global.discourse-cdn.com/letsencrypt/original/3X/7/3/73e97d6e8b63da17622ef08e1cb966ddc4e67483.png)

---

<div class="post-metadata">

**Author:** ![Rip](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rip/32/70863_2.png) [@Rip](https://community.letsencrypt.org/u/Rip)\
**Post date:** [September 26, 2024, 2:53am UTC](https://community.letsencrypt.org/t/question-about-the-certificate-authority/226220/4 "2024-09-26T02:53:44Z")

</div>

> [@lauren.oregan](#):
>
> Does this CA validate the identity of the domains owner?

That is the GIG. Ownership is paramount. Why do you ask?

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [September 26, 2024, 3:23am UTC](https://community.letsencrypt.org/t/question-about-the-certificate-authority/226220/5 "2024-09-26T03:23:13Z")

</div>

> [@Rip](#):
>
> Ownership is paramount

Ownership is meaningless 🤷‍♂️ It is all about who _controls_ the public DNS and/or webservers pointed to by the DNS

In addition to the FAQ @rg305 linked there is also this

> **[How It Works - Let's Encrypt](https://letsencrypt.org/how-it-works/)**
>
> The objective of Let’s Encrypt and the ACME protocol is to make it possible to set up an HTTPS server and have it automatically obtain a browser-trusted certificate, without any human intervention. This is accomplished by running a certificate...

---

<div class="post-metadata">

**Author:** ![jvanasco](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jvanasco/32/55900_2.png) [@jvanasco](https://community.letsencrypt.org/u/jvanasco)\
**Post date:** [September 26, 2024, 4:18pm UTC](https://community.letsencrypt.org/t/question-about-the-certificate-authority/226220/6 "2024-09-26T16:18:33Z")

</div>

> [@rg305](#):
>
> No.  
> Only "control" is validated [automatically].

Clarifying this response a bit:

LetsEncrypt only offers DV (Domain Validation) Certificates.

With DV Certificates _"Only 'control' is validated [automatically]"_, **regardless of the CA**. No CA will validate the identity of a Domain's owner for a DV Certificate.

The identity of the owner is validated for OV (Organization Validation) and EV (Extended Validation) Certificates. A CA that offers OV or EV Certificates will validate domain owners for those certificates, but will not validate domain owners for DV certificates they offer.

---

<div class="post-metadata">

**Author:** ![Rip](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rip/32/70863_2.png) [@Rip](https://community.letsencrypt.org/u/Rip)\
**Post date:** [September 27, 2024, 12:18am UTC](https://community.letsencrypt.org/t/question-about-the-certificate-authority/226220/7 "2024-09-27T00:18:47Z")

</div>

> [@MikeMcQ](#):
>
> Ownership is meaningless

Ok. I get it. Control is paramount. In my world ownership = control. But in the wild (real world) that doesn't exactly line up. I capitulate. ;@)  
Thanks Mike.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [September 27, 2024, 12:24am UTC](https://community.letsencrypt.org/t/question-about-the-certificate-authority/226220/8 "2024-09-27T00:24:31Z")

</div>

There may be many individual points of control [various FQDNs].  
There should only be one owner [of the domain].

---

<div class="post-metadata">

**Author:** ![Rip](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rip/32/70863_2.png) [@Rip](https://community.letsencrypt.org/u/Rip)\
**Post date:** [September 27, 2024, 12:30am UTC](https://community.letsencrypt.org/t/question-about-the-certificate-authority/226220/9 "2024-09-27T00:30:01Z")

</div>

Owners can and do delegate. However there really is only one owner even if he/she shares management of a domain.  
IMHO it is a mistake. And it can lead to "loss of control".  
Consider a business website. The Business sells and the new "owners" claim control of the assets including the website.  
I have experienced it and it has motivated me to post terms/conditions and claim of owership on some domains I own yet "lease" to client businesses.

---

<div class="post-metadata">

**Author:** ![JimPas](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jimpas/32/33270_2.png) [@JimPas](https://community.letsencrypt.org/u/JimPas)\
**Post date:** [September 27, 2024, 4:47pm UTC](https://community.letsencrypt.org/t/question-about-the-certificate-authority/226220/10 "2024-09-27T16:47:12Z")

</div>

When someone purchases a domain, their registration details can remain private (Private Registration) and only contact details of the registrar are shown with the dates of creation & expiry, etc.. So no, ownership cannot be validated.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [October 27, 2024, 4:47pm UTC](https://community.letsencrypt.org/t/question-about-the-certificate-authority/226220/11 "2024-10-27T16:47:53Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
