SSL certificates classes 

CA uses the concept of classes for different types of digital certificates, but these classes are not specified in any SSL/TLS RFC. Let's try to understand what different classes mean to SSL end users.

  • Class 1: Class 1 certificates are delivered without any prior verification. This is also known as a Domain Validation (DV) certificate and relies on the WHOIS information database (you must prove you own the domain). A DV certificate is a low authentication product which does not guarantee the identity of the website's owner nor the actual existence of the organization. This simply refers to two entities talking over an encrypted channel without knowing each other.
Note: This can be heavily misused by attackers by ...

Get Practical Network Scanning now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.