DV vs OV vs EV in the era of shorter SSL lifetimes: Which should you choose?

Shortening SSL lifetimes are set to impact how we manage SSL certificates, but what about the SSL types you choose? Should you be reconsidering your go-to SSL based on these changes?

Let’s take a look at the three main SSL types based on validation level. DV, OV, and EV certificates all offer the same encryption strength. What sets them apart is how much verification is required before you receive your certificate.

Let’s take a closer look at each type and whether or not you should reconsider which you opt for moving forward. 

What is a DV certificate? 

DV is short for domain validation, which reveals the main feature of a DV certificate. Before you receive your certificate, the issuing Certificate Authority (CA) only needs to verify that you own the domain you need an SSL for. This can be done in three ways:

  • The CA sends an email with a confirmation link to the address registered as owning the domain
  • Uploading a specific file to your domain for the CA to check
  • Adding a CNAME record to your domain’s DNS settings

Because validation for DV certificates doesn’t have many requirements, it’s the easiest SSL type to get fast. Once you complete verification, it’s usually issued in minutes. This makes it ideal for automation such as ACME, which can take care of verification for you. You can just leave it running in the background, safe in the knowledge that your site will always be secure. 

This SSL type is a good fit for personal sites, blogs, staging environments, or any other site where visitors won’t want to know information about who is running it. As already mentioned, DV SSL certificates offer the same powerful encryption as other SSL types. However, the certificate itself will only display who controls the domain. If you want to display more information in your SSL, an OV or EV SSL certificate would be better. 

What is an OV certificate? 

Short for organization validation, OV certificates require more extensive verification than DV certificates. CAs will check domain ownership as well as the requesting business itself. This may include:

  • Business registration records to ensure the organization’s legal existence
  • The physical business address
  • Calling up someone in the organization

Because of the added verification, OV certificates can take several days to issue rather than a few minutes. They also tend to cost more and are slightly more awkward to automate, but most major CAs automate OV certificates once they are validated. 

As OV certificates offer the same level of protection as DV, the biggest appeal is assurance. If you run an online store, SaaS, corporate infrastructure, or another business type that requires customer trust, the details within the SSL itself will show that a verified entity is behind it, giving them peace of mind should they check the SSL’s details. 

What is an EV certificate? 

Short for extended validation, EV SSL certificates offer deeper legal-entity verification than OV certificates. In addition to DV and OV requirements, validation also includes looking into the organization’s operating history. An EV also requires authorization and sign-off from a specific, named person at the company. 

Offering the same high-level encryption as the previous certificate types, EV SSLs mostly appeal to organizations operating in high-assurance sectors such as finance, government, or B2B, where a partner may actually want to dive deeper into who they’re dealing with.

Like with OV, EV certificates can be automated, it will just require more human intervention. 

Key differences between DV, OV, and EV SSL certificates

The table below quickly sums up what sets DV, OV, and EV certificates apart from one another. 

FeatureDVOVEV
Domain control verifiedYesYesYes
Organization verifiedNoYesYes
Depth of identity verificationBasicEnhancedExtensive
TLS encryptionYesYesYes
Issuance complexityLowMediumHigher
Automation potentialHighDepends on CA/workflowDepends on CA/workflow
Best suited forSimple/general websitesBusinessesOrganizations requiring stronger identity assurance

How shorter lifetimes will affect DV, OV, and EV 

We’ve discussed the shortening SSL lifetime frequently on the SSLs.com blog, and how it will ultimately shrink to 47 days by 2029. But how will this impact your choice in SSL certificate?

Probably not by much. 

Firstly, each SSL will need to be replaced at the same rate. Roughly every six weeks. That is a lot to keep up with, especially if you have multiple SSL certificates. So if you haven’t adopted automation yet, you likely will before 2029. 

The biggest difference between the three will remain validation. For DV certificates now and in the future, no human intervention is required. For OV and EV certificates, business validation was reduced from every 825 days to every 398 days earlier in the year. There’s no sign that this will drop further just yet. So roughly once per year, a human will be required to validate the existence of the organization. Apart from that, reissuance can be fully automated. 

So whether you choose a DV, OV, or EV SSL will stem from whether or not you need a high-assurance certificate for your particular organization. OV and EV SSL certificates are slightly less convenient, however, if you run an organization that needs them, you’re probably prepared for the extra verification steps. Apart from that, if you can automate, you can set it and forget it for the most part.  

Ultimately, what will change is not your SSL type, but how you choose to manage your SSL inventory. 

Choosing the right SSL certificate

Your choice depends on the purpose of your site and the level of assurance you need. 

If you have a simple website, such as an informational site, portfolio, landing page, or test environment, and need fast issuance, a DV SSL is the way to go. 

If you have an e-commerce site, SaaS platform, or offer professional services, an OV SSL is ideal. The verified business identity will inspire trust in certain customers and partners. 

For higher-stakes organizations such as banking institutions, healthcare platforms, or payment processors, the high-assurance validation of an EV SSL is ideal. 

Answer the questions below to help guide you further on making the right choice. 

  • Do you just need an SSL-secured site, or do you also need business verification?
  • Does your industry, company policy, or a partner ever require OV or EV specifically?
  • How many certificates are you managing, and could you use automation for renewals?
  • How fast do you need the certificate issued?
  • Who’s responsible for renewals, and are they set up to handle it every six weeks?

The takeaway

There is no universal best SSL certificate type, even with the new SSL lifetimes around the corner.  So your best bet is to continue choosing SSL certificates based on your specific needs, such as identity verification requirements and your business type. 

Frequently asked questions

Is EV SSL more secure than DV?

No, both SSL certificate types offer the same level of encryption. The only difference is the amount of verification performed and how much company information is displayed in the SSL itself.

Is DV SSL safe for e-commerce?

Yes, DV SSL certificates offer the same level of encryption as other SSL certificates. You may want to consider upgrading to OV or EV if you ever require deeper company verification. 

Do DV, OV, and EV provide different encryption? 

No, they all provide the same cryptographic strength. 

Is EV SSL still worth it?

Since the sunset of the browser green bar, fewer people are choosing EV SSLs. However, for high-assurance industries like banking or healthcare, EV SSL certificates are still worth it. 

Can OV and EV certificates be automated?

Depending on the Certificate Authority, OV and EV certificates can be partially automated, but human intervention is required for business verification. However, this will only need to be done roughly once a year, and the SSL will be reissued in the meantime.

Share on Twitter, Facebook, Google+