Authentication factors comparison
Here is a comparison chart that will help you understand the server certificates authentication factors and the security level they provide.
Kind of authentication
CHECK POINTS | 1-FACTOR DV: DOMAIN VALIDATION |
2-FACTOR TEST CERTIFICATES |
3-FACTOR OV: ORGANIZATION VALIDATION |
EV: EXTENDED VALIDATION |
---|---|---|---|---|
List of unauthorized countries | no | no | no | yes |
List of websites victim of phishing attacks | no | no | no | yes |
List of unauthorized websites | no | no | no | yes |
List of unauthorized tld | yes | yes | yes | yes |
Existence (registration) of the organization | no | yes, via a qualified database | yes, via a qualified database | yes, via a governmental qualified datdabase |
Trade name (optional) | no | yes | yes, via a qualified database | yes, via a governmental qualified datdabase |
Physical existence (address) | no | yes | yes | yes, via an independent qualified database |
Physical existence (phone) | no | no | yes, via a directory or a qualified database | yes, via a directory or an independent qualified database |
Operational existence (more than 3 years) | no | no | no | yes |
control of the domain | yes (via email) | oui (domain release letter possible or via DCV according to the authority) | oui (domain release letter possible or via DCV according to the authority) | yes (or via DCV according to the authority) |
Vetting of the corporate contact employment | no | no | no | yes |
Vetting of the Certification agreement signature (receive by mail, fax or PDF) | no | no | no | yes |
Vetting of the request | no | no | yes By e-mail, phone call or postal mail to the corporate contact according to the authorities processes and the elements gathered during the audit |
yes |
Inclusion of the organization's registration information in the certificate | no | no | no | yes |
Notes:
- An "independent qualified database" means we use a different base than the one we use for the organization name validation (governmental qualified database).
- A "qualified database" without further specification means it can be either a governmental or an independent one.
Last edited on 08/17/2023 14:39:19 --- [search]