
Some certificate authorities only do domain validation, while others only do organisation validation. Some authorities do both, and add a rider to domain control certs, for example by entering "Domain Control Validated" in the organisation unit field of the certificate. Most certificate authorities only put a real organisation name on the certificate if they have validated this, and conversely put the hostname or domain name in the organisation field if it is a domain-only certificate. Netcraft distinguish domain-validated certificates by looking for a list of known strings in the subject organisation unit field. Netcraft only perform this categorisation for certificate authorities with a significant number of certificates — for the smaller authorities, it is often difficult to find information about the level of validation performed.
Most browsers do not yet differentiate between the different types of assurance implied by different types of certificate checking, but a user viewing the detail of the site certificate would be able to see the difference (if they knew what to look for). In future browsers may start to make this distinction — if only by showing the organisation field of the certificate more prominently.
Copyright © Netcraft 1996-2006