3 ms·
The difference is in the certificate chain. One of the conditions for being a CA is verifying domain ownership before signing a certificate. In return for this,
by johnsoft 12y ago
The difference is in the certificate chain. One of the conditions for being a CA is verifying domain ownership before signing a certificate. In return for this, browsers will trust their cert. As long as a CA keeps this promise, they get to keep their cert and use it to sign certs for others. If they break this promise, their cert will be revoked and browsers will start showing warnings on sites that used them as a CA.
A green padlock indicates this additional level of trust, i.e. authenticity (verified through any method any trusted CA may choose), which a self-signed cert can't provide.