Skip to content

Glossary

Short, citation-friendly definitions for ACME, CA, CSR, validation methods and certificate types.

ACME

Automatic Certificate Management Environment, RFC 8555, the protocol Let’s Encrypt uses to issue DV certificates.

Certificate authority

An organization that signs certificates after validating a request. Examples: Let’s Encrypt, DigiCert, Sectigo.

CSR

Certificate Signing Request. Contains the public key and names. The private key never needs to leave the applicant.

DNS-01

ACME challenge that publishes a TXT record at _acme-challenge to prove zone control. Required for wildcards.

HTTP-01

ACME challenge that serves a token at /.well-known/acme-challenge on port 80.

DV

Domain Validation. The CA checks control of the name only. Not weaker encryption than OV/EV.

OV

Organization Validation. Adds checks on the legal organization. Same TLS cryptography as DV.

EV

Extended Validation. Additional organizational checks. Browsers no longer give EV a unique address-bar treatment.

SAN

Subject Alternative Name. Extra hostnames on one certificate.

Wildcard certificate

A certificate for *.example.com covering one label under that zone. Requires DNS-01.

TLS

Transport Layer Security, the protocol HTTPS uses. SSL is the historical name.

SSL

Secure Sockets Layer. Obsolete protocol name still used colloquially for TLS certificates.

Private key

The secret half of the certificate key pair. Never log it. Prefer CSR mode or encrypted platform storage.

Certificate chain

Leaf plus intermediates needed to reach a trusted root.

Root CA

A trust-anchor certificate. Browsers and OSes ship root stores. Do not store unprotected roots in the app database.

Intermediate CA

A CA certificate signed by a root, used to sign leaf certificates.

mTLS

Mutual TLS. Both sides present certificates.

OCSP

Online Certificate Status Protocol. A way to check revocation without downloading a full CRL.

CRL

Certificate Revocation List. A signed list of revoked serials.

Certificate Transparency

Public logs of issued certificates used for monitoring unexpected issuance.