Podcast

Root Causes 637: Is It Time to Get Rid of EV SSL?

Hosted by
Tim Callan
Tim Callan
Chief Compliance Officer
Original broadcast date
July 6, 2026

The Baseline Requirements, CT logs, the Bugzilla Bloodbath, shortening certificate lifespans, all these trends serve to enforce a high level of quality and predictability across WebPKI certificates.  Nearly twenty years after the introduction of EV SSL, we ask if it has served its purpose and should be retired.

Podcast Transcript

Tim CallanTim CallanSo Jason, I have an important question for you.
Jason SorokoJason SorokoI'm all ears.
Tim CallanTim CallanIs it time to get rid of EV SSL?
Jason SorokoJason SorokoOh my God - we've asked that question. "Get rid of" are big words. I think that - Tim, the way that I formulated in my head the answer to that in the past, and I think the answer is still the same right now, is this: what is it offering, above and beyond? Because of the fact that, hey, we all know the green bar is gone - in other words, it doesn't reflect in the browser. So is there something to that extended validation process that is making the end user more secure? No, I don't think so. Is it making the subscriber of the cert more secure? I don't think so. And I will tell you this - this is something I think we said before to each other, and then I'm going to let you rip.
Tim CallanTim CallanWhat, you think I have thoughts on this?
Jason SorokoJason SorokoMaybe. I'm just trying to get my words in now, which is: if you combine CT Logs with the Web PKI ecosystem, you combine it with CA/Browser Forum rules, not the EV rules, the CA/Browser Forum standard rules, the BRs - you combine all that, you combine the fact that we're ratcheting down DCV, you combine the fact that we're shortening [certificate] lifespans, add it all up, and my God, DV and OV are really well supported by that entire Web PKI ecosystem.
Tim CallanTim CallanI think that is exactly right, and that's the key point. So if you go back to when EV SSL was introduced in 2007, none of those things you listed - not a one of them - was in place. And so I think it would be easy to say EV SSL failed, but I think that would be entirely incorrect. I don't think that's what happened. What happened is EV SSL succeeded, because what it did was it pulled the floor up to its level. And now EV SSL and OV are sitting at the same level - but that isn't because EV got weak or EV didn't work. It's because OV went from nonexistence, to existent but a pale brother to EV, up to an equivalently secure and trustworthy level. And this happened because of a bunch of things. It absolutely was things like CT Logs. And absolutely one of those things was the reduction in maximum term. One thing that most people don't remember was that the EV Guidelines were the first time that a term max was ever introduced to public certificates. They were capped at two years. That was new. So now we're down to well under two years. The codified rules for how to do authentication of all forms - not only OV authentication, but DV authentication - those were introduced in the EVGs as concepts. Prior to that, those literally were concepts that didn't exist. Those same concepts made their way into the BRs, and then were evolved and strengthened over the next nearly fifteen years in the BRs. And in the process of so doing, the level came up. So I'm not sure quite what the analogy is. If you imagine an award-winning race car from the 1930s, and then you compare that to anything you and I can buy today, the thing we're driving today is faster than that race car. And that isn't because that race car got worse, it's because the level of everything else came up. And so when I look at that, and I look at the complete deprecation of the EV indicators, I say there is no meaningful difference between EV SSL and OV SSL. There are differences - there are letter-of-the-law differences - but they're not differences that are important. And by the way, this is even more extreme in the code signing. Where you have EV code signing and standard code signing, and there's just no difference at all. And so when I look at it this way, I say this is a meaningless distinction. You can get an EV cert, you can get a non-EV cert, and they both do the same thing. And they both, again, for any meaningful purpose, represent the same attestation about the user of that certificate - about the subscriber. So then I go, like, why do we have two? Why do we have two things with different names, with different sets of rules, where the difference between them is not of any material value, or just any material meaning? And so then I start to say, why don't we just collapse them to one?
And so, obviously, as long as both of these certificate types are... let me put my Sectigo hat on real quick. As long as both of these certificate types are available, we have to make them both available. If someone wants EV, we have to give them EV. If someone wants OV, we have to give them OV. We couldn't just decide to do one, because the subscribers are going to demand access to whatever they demand access to. However, if the CA/Browser Forum decided to collapse on one of them - and which one it is is not so important. Probably it would be OV
Jason SorokoJason SorokoWe've seen how this redundancy created ambiguities, which created bad conditions. So it's been bad - it has caused bad.
Tim CallanTim CallanI think this is a bit of a hot take. I think there are people out there, they've had their EV for their whole career - both subscribers and CAs - who don't want to give up this thing that they've been using since they got out of college. And they wouldn't be happy with this suggestion. But if you just put your emotion aside, or the specifics of your one situation - where "I care about this because I'm a guy who sells EV and I don't want to be out of business" - if you put that aside and you just think at the macro level, for the global Web PKI, and you apply the criteria I just walked through, I don't see how you come to another conclusion.
Jason SorokoJason SorokoI don't see how you come to another conclusion. Look, Tim, I think that we've been debating putting out this episode for quite a long time. And it has to do with the fact that, hey, nobody ever got fired for buying an EV.
Tim CallanTim CallanAnd there's nothing wrong with buying an EV. One of the things, being - from a brass-tacks perspective - for most of the buying in the world (not if you go to someone's website
Jason SorokoJason SorokoNo, no, no, no. When we conclude, I wanted to say something kind of pithy and funny.
Tim CallanTim CallanDo it. I'm ready.
Jason SorokoJason SorokoTim, by the way, for search engine optimization purposes, I did want to say that every time you say EV, I know that somebody's system is trained to think that we're talking about electric vehicles.
Tim CallanTim CallanThat is true. So I should say the full word at least once - extended validation SSL. Or technically, if we're going to be technical, it's extended validation TLS.
Jason SorokoJason SorokoThere you go. That is the correct term.
Tim CallanTim CallanThat's right.
Jason SorokoJason SorokoThank you, Tim.
Tim CallanTim CallanThanks, Jay.

Stay informed with expert insights

Subscribe to Root Causes for engaging discussions on PKI, digital security, and best practices for protecting your organization's critical assets. Don’t miss an episode!

Listen on Apple PodcastsListen on SpotifyListen on SoundCloud