security / ssl / tls / certificate issuer
SSL / TLS

Certificate issuer

The issuer is the certificate authority that vouched for your certificate. Browsers only trust certificates from recognised authorities.

Severity if missing
Low
Category
SSL / TLS
Standard
RFC 5280

What it is

Every certificate is signed by a certificate authority (CA) — an organisation browsers have agreed to trust, such as Let's Encrypt or DigiCert. The issuer field records which CA that was.

As long as the issuer is a trusted authority, the browser accepts the certificate. Pentrawl reports the issuer so you can see who stands behind your certificate.

Why it matters

The issuer confirms your certificate comes from a recognised, trusted authority rather than a self-signed or untrusted source. It's mostly informational, but an unexpected issuer can be a sign that something about your setup isn't what you thought.

The risk
A certificate from an untrusted or unexpected issuer may not be trusted by browsers, or may indicate a misconfiguration.

How Pentrawl checks it

Pentrawl reads the issuer from your certificate and reports which certificate authority issued it. A recognised, trusted issuer passes the check.

How to fix it

There is usually nothing to fix — this check is informational. If the issuer is unexpected or untrusted, reissue your certificate through a recognised authority such as Let's Encrypt.

Check your domain's Certificate issuer in seconds
Pentrawl scans this and 20+ other security checks in one automated pass.
Scan your website →