The Top 5 Most Popular SSL Certificate Authorities Reviewed

As the internet moves towards a more secure and privacy-respecting web with HTTPS a standard feature of all websites, it’s more important than ever that site admins get a hold of an SSL certificate from a registered certificate authority.

Let’s Encrypt is probably the most well-known certificate authority right now since it’s issuing certificates for free for the public’s benefit. But there are plenty more certificate authorities out there providing similar services.

So which one is the best?

To help you decide on the right certificate authority for you, in this post, we’ll cover how to choose the right one for your needs and provide a side-by-side comparison of the top five certificate authorities.

What to Look Out for in a Certificate Authority

When it comes to choosing a Certificate Authority (CA), it comes down to knowing what you need and which CA has it.

To help you decide, here are the main types of SSL certificates to choose from:

  • Domain Validation (DV) – Certificates that are quick to be issued since only the domain is verified for legitimacy.
  • Wildcard – The root domain and its sub-domains can be included in a single certificate.
  • Extended Validation (EV) – Distinguishable by the browser’s address bar being colored green as opposed to only the https text. Both the legal identity of the business or organization and domain needs to be verified for legitimacy.
  • Unified Communications (UC) – Used for encrypting the connection for use with email and other communication software. Multiple domains can be included in one certificate, and it’s also a type of Subject Alternative Name certificate.
  • Subject Alternative Name (SAN) – The root domain and related domains that are linked can be included under one certificate
  • Wildcard – A certificate that includes the root and its sub-domains.
  • Organization Validation (OV) – Similar to extended validation certificates where both the legal identity of the business or organization and the domain is verified for authenticity, except it doesn’t include a green address bar.

There are also different kinds of encryption that you may come across when searching through different Certificate Authorities:

The higher the bit rate of encryption, the better the security. Although, ECC is stronger than RSA, so an ECC 256-bit certificate is stronger than an RSA 2048-bit certificate.

The difference between RSA and DSA is that the former is faster at validating signatures, which are encrypted keys that are used in the process of issuing an SSL certificate. RSA is also slower at creating signatures. DSA encryption is the opposite since it’s faster at creating signatures, but it’s slower when validating them.

Knowing the difference between the most common types of certificates is a start, but now it’s time to determine which kind of certificate you need.

Which Certificate Do I Need?

As a general rule of thumb, here are the types of sites that commonly need each kind of certificate mentioned above:

  • Domain Validation – Any WordPress site, any site that has a form or basic sites
  • Extended Validation – eCommerce, business or organization sites or any site that wants to present themselves as extremely trustworthy
  • Unified Communications – For email servers and it’s also a requirement for Microsoft Exchange
  • Subject Alternative Name – You have multiple domains that are all related but aren’t necessarily sub-domains and can include email or IP addresses, DNS name or URL
  • Wildcard – For WordPress Multisite networks set up with sub-domains
  • Organization Validation – Business or organization sites which need to appear as trustworthy

Now that you have a better idea of the kind of SSL certificate you need, let’s take a look at which of the top Certificate Authorities can fill your encryption requirements.

Top 5 Certificate Authorities Reviewed

There are many Certificate Authorities on the market, but these are the top five most popular options. Below is a review of each of them based on five categories: price, the variety of the certificates offered, the warranty that’s included with certificates, compatibility across browsers and mobile devices and the included features.

All of these Certificate Authorities issue certificates that work and that are secure. That’s why there isn’t a category in the review for security. It all comes down to your needs and the specific features and capabilities that are included when a certificate is issued from these five options.

Note: The details and warranty dollar amounts included for each Certificate Authority are accurate at the time this review was published.

Let’s Encrypt

Let's Encrypt site

Let’s Encrypt is an open source Certificate Authority that’s backed by companies such as Automattic, Mozilla, Sucuri, SiteGround, Facebook, Chrome and many more. It offers RSA 2048-bit encryption with ECDSA encryption currently in development.

Getting a DV certificate and renewal is free for everyone and you can have as many as you want. With the Certbot installer, you can also have multiple certificates up and running in seconds. Issuing a SAN or UC certificate can also be done by adding multiple names to an otherwise DV certificate.

Even though certificates are free, it doesn’t mean it’s not secure. As I mentioned earlier, It’s just as secure as most other Certificate Authorities so it’s a suitable option if you’re on a budget. Unfortunately (and understandably), free certificates don’t come with any kind of warranty or extra features.

It’s not the kind of certificate you can use for any given situation, but it’s a viable option for many sites that only require domain validation.

The Good

  • You can have as many certificates as you want for free
  • All renewals are free and can be automated
  • Certificates are issued instantly
  • Compatible with most major browsers and devices

The Bad

  • Only DV, SAN and UC certificates are available
  • There are obscure devices and browser versions that aren't compatible
  • No warranty is available
  • There aren't any additional features

Our Verdict

  • Price:
  • Certificate variety:
  • Warranty:
  • Compatibility:
  • Features:
  • Overall:

Comodo

Comodo's site

Comodo offers an RSA 2048-bit encryption for DV, wildcard and EV certificates. UC certificates have 128-bit or 256-bit encryption. It’s also the only Certificate Authority included in this review that offers premium SSL certificates with a free trial, though, the trial is only for a DV certificate.

Other than the free trial, there are four different types of certificates: DV, wildcard, EV and UC.

When you get an SSL certificate, it also comes with a warranty no matter which one you choose, but the amount varies between certificates.

One of the best features of Comodo is that you can choose to upgrade your certificate’s warranty if the largest amount isn’t already included. You can also get a Comodo logo to place on your site to build your visitors’ trust, but it’s only available for wildcard and EV certificates.

Other than that and customer support, there aren’t other additional features, but that’s reasonable given that it’s the most affordable option directly after Let’s Encrypt.

The Good

  • There's a free 90-day trial for a DV certificate
  • PCI and site scanning is free for one certificate
  • Warranties are available of $250,000 to $1,750,000 for certain certificates
  • You can upgrade the warranty on some of the certificates
  • It's the second most affordable option
  • Compatible with all major browsers and mobile devices

The Bad

  • Scanning features are only available for one certificate per account
  • A trust logo for your site is only included for wildcard and EV certificates
  • May not be compatible for less popular browser versions and mobile devices

Our Verdict

  • Price:
  • Certificate variety:
  • Warranty:
  • Compatibility:
  • Features:
  • Overall:

Symantec

Symantec's SSL page

Symantec is the most expensive Certificate Authority in this review, but it also comes with the most features. Each certificate includes ECC 256-bit encryption, a Symantec logo to place on your site, daily malware scanning as well as UC and DSA support for your certificates.

There are also five different types of certificates: Secure Site (DV), Secure Site Pro (DV), Secure Site Wildcard, Secure Site with EV and Secure Site Pro with EV.

Vulnerability scanning is an option, but only for Secure Site Pro, Secure Site with EV and Secure Site Pro with EV certificates. Symantec is also one of the Certificate Authorities that offer the highest warranties.

Although each certificate has a higher price point, they’re necessary for anyone who requires an SSL certificate that complies with certain standards of government agencies. It’s also a good option for high-profile or high-traffic sites.

The Good

  • All certificates come with a Symantec logo to place on your site
  • Nearly 100% compatibility with all browsers and mobile devices
  • DSA certificates are a core feature and meet certain government agency standards
  • Includes high warranties of $1,500,000 or $1,750,000.
  • Every certificate comes with daily malware scans and UC support

The Bad

  • Vulnerability scans are included with only certain certificates
  • The most expensive option of the Certificate Authorities in this post

Our Verdict

  • Price:
  • Certificate variety:
  • Warranty:
  • Compatibility:
  • Features:
  • Overall:

Digicert

Digicert's site

Digicert has mid-range pricing since it offers features for every certificate including a warranty of $1,000,000, free re-issues and a logo you can add to your site to built visitor confidence. It also supports RSA 2048-bit, 128-bit and 256-bit encryption.

There are five different types of certificates that are available: SSL Plus (DV), EV, Multi-Domain (UC/SAN), EV Multi-Domain and Wildcard Plus.

While Digicert’s certificates are compatible with all major browsers and mobile devices, there may be some versions or devices that aren’t supported but are also not widely used.

If you require a warranty rate that’s higher than the base amount that’s offered by some other Certificate Authorities and you also need a logo to place on your site for the type of certificate you need and it’s not supported elsewhere that’s within your price range, then it’s worth taking a closer look at Digicert.

The Good

  • Free certificate re-issues
  • Warranty of $1,000,000 for all certificate types
  • Compatible with all major browsers and mobile devices
  • All certificates include unlimited server licences

The Bad

  • May not be compatible with less popular browser versions and mobile devices
  • You need to sign on for multiple years to get a certificate discount

Our Verdict

  • Price:
  • Certificate variety:
  • Warranty:
  • Compatibility:
  • Features:
  • Overall:

GeoTrust

GeoTrust's site

GeoTrust is similar to Digicert as it also has mid-range prices for their certificates with features that set it apart from other Certificate Authorities such as unlimited server licences, free re-issues of certificates and you can issue up to 24 names per certificate and it doesn’t matter which one you choose.

GeoTrust also has five different certificate types: EV, wildcard, OV, wildcard with OV, and DV. Each certificate supports 2048-bit encryption for root domains and 256-bit encryption for all other names.

While GeoTrust certificates are compatible with over 99% of browsers, only major mobile devices are supported.

While most Certificate Authorities issue their own certificate for their site, the GeoTrust site has a Symantec certificate installed, despite selling certificates for businesses.

GeoTrust is a suitable certificate authority for businesses, but at the same time, they don’t seem to trust their own certificates on their own site so it raises a few questions and eyebrows. Still, they offer certificates suitable for small to medium-sized businesses and you can’t exactly fault them for knowing what they are and wanting a higher level of encryption than what they offer.

The Good

  • Free certificate re-issues
  • Compatible with major mobile devices and over 99% of browsers
  • All certificates include unlimited server licences
  • Warranties of $500,000 to $1,500,000 are available

The Bad

  • The GeoTrust site has has an issued certificate from Symantec
  • Can only issue up to 24 UC/SAN certificates
  • May not be compatible with all mobile devices and versions

Our Verdict

  • Price:
  • Certificate variety:
  • Warranty:
  • Compatibility:
  • Features:
  • Overall:

Comparing the Top 5 Certificate Authorities

Now that the five most popular Certificate Authorities have been reviewed, you can check out each of them compared side-by-side in each category.

Price

  • Let’s Encrypt Certificate Authority:
  • Comodo Certificate Authority:
  • Symantec Certificate Authority:
  • Digicert Certificate Authority:
  • GeoTrust Certificate Authority:

Certificate Variety

  • Let’s Encrypt Certificate Authority:
  • Comodo Certificate Authority:
  • Symantec Certificate Authority:
  • Digicert Certificate Authority:
  • GeoTrust Certificate Authority:

Warranty

  • Let’s Encrypt Certificate Authority:
  • Comodo Certificate Authority:
  • Symantec Certificate Authority:
  • Digicert Certificate Authority:
  • GeoTrust Certificate Authority:

Compatibility

  • Let’s Encrypt Certificate Authority:
  • Comodo Certificate Authority:
  • Symantec Certificate Authority:
  • Digicert Certificate Authority:
  • GeoTrust Certificate Authority:

Features

  • Let’s Encrypt Certificate Authority:
  • Comodo Certificate Authority:
  • Symantec Certificate Authority:
  • Digicert Certificate Authority:
  • GeoTrust Certificate Authority:

Overall

  • Let’s Encrypt Certificate Authority:
  • Comodo Certificate Authority:
  • Symantec Certificate Authority:
  • Digicert Certificate Authority:
  • GeoTrust Certificate Authority:

Choosing the Best Certificate Authority

As mentioned earlier, each Certificate Authority in this comparative review offers secure SSL certificates and choosing one is dependent on your needs.

To aid in your decision-making process, here are some recommendations based on each Certificate Authority’s best features:

  • If you’re on a budget or run a basic site such as a personal WordPress blog, portfolio site or small business site, check out Let’s Encrypt or Comodo.
  • Symantec is the best option if you need DSA, ECC or the highest level of encryption.
  • If you need site scanning for vulnerabilities or malware, take a look at Comodo or Symantec.
  • Comodo, Symantec and GeoTrust all have the highest warranties
  • If you need a fairly high warranty at a reasonable cost for DV, wildcard or SAN certificates, check out Digicert.
  • For unlimited server licenses or free certificate re-issues, consider Digicert or GeoTrust.
  • Comodo, Symantec and Digicert all offer their logos to place on your site to help increase your visitors’ trust.

Overall, you need to decide which kind of certificate fits your specific needs and which features you require. Then, you can choose a Certificate Authority that includes everything you need at a price that fits into your budget.

Jenni McKinnon
Were you able to choose a Certificate Authority based on these reviews? Are you having troubles deciding on one? Have you chosen an SSL certificate from a different Certificate Authority and which one? Feel free to share your experience in the comments below.