Frequently Asked Questions
A TLS certificate (Transport Layer Security certificate) is a digital certificate used to secure communication over the internet. It ensures that data transmitted between a client (like a web browser) and a server is encrypted and protected from eavesdropping or tampering.
Key Functions
Encryption – TLS certificates enable encrypted connections using protocols like HTTPS, so sensitive data (passwords, credit card info) cannot be intercepted.
Authentication – They verify the identity of the server (and sometimes the client), ensuring you're communicating with the legitimate website and not an imposter.
Data Integrity – TLS ensures that data sent and received hasn't been altered during transmission.
Validation Level
DV Certificates – Validate only that the applicant controls the domain. No identity verification of the organization or individual.
OV Certificates – Validate both domain ownership and the organization's identity (legal existence, physical address, etc.). Requires documentation or verification through official records.
Trust Level
DV – Provides basic encryption but minimal assurance to users. Browser shows a padlock, but no organizational details. Suitable for blogs, personal websites, or non-sensitive sites.
OV – Higher trust because the certificate includes verified organization details. Users can view company name in certificate details. Recommended for business websites, e-commerce, and sites handling sensitive data.
Cost
DV – Cheapest option.
OV – More expensive due to additional validation steps.
Use Cases
DV – Personal sites, test environments, small projects.
OV – Corporate websites, portals, and applications where user trust matters.
Telia CA TLS certificate billing is changing to "pay-per-use model"
Telia ceases offering prepaid TLS certificates. New pay-per-use model is flexible and based on following principles:
• Unique dnsSAN names or dnsIPAddresses used in active TLS certificates will be calculated daily.
• Wildcard name, fully qualified domain name and IPAddress have daily cost that is close to the value of current annual_price/365
• Aggregated sum of active Unique SANs is used in Telia's customer invoicing monthly.
• Customers are invoiced according to agreed intervals by Telia. Invoice reports will detail all Unique SANs for verification. Invoice itself has only sum of daily counts and partial info.
Pay-per-use model has many benefits compared to the prepaid model:
• Only unique SAN names are calculated. All SAN name copies are free of charge.
• Certificates may be changed at any time without any additional costs. Only used days are charged.
• At the end of month all daily SAN counts are aggregated to generate monthly bill that is then delivered to be paid using normal Telia billing
• By revoking a certificate effectively ends charging.
• When renewing previous certificate, the remaining days of the old certificate are not lost
e.g. If you create a wildcard certificate on the first day of a calendar year, then at the end of the year it has generated bills of 365 * daily price which is about the same price than traditional prepaid model was using. If you generate wildcard copy during the year it won't have any effect on pricing.