SSL certificate
OV certificate
The certificate contains your verified organisation name. The encryption is the same as the free one; the difference is representation.
How OV differs from the free one
| What we compare | Let’s Encrypt | OV |
|---|---|---|
| Encryption | the same | the same |
| Price | free | — |
| Reissue and install | automatic | automatic, within the subscription |
| Invoice, contract, delivery note | none | yes |
| Trust seal for your site | none | yes |
| Support | community and documentation | ours, we answer for the expiry date |
| Certificate authority warranty | none | yes |
| Compatibility with older systems | modern browsers and systems | wider |
| Where it can be issued | wherever ACME works | also where ACME isn’t available |
| Google rankings | the same | the same |
The Google row is here on purpose: a paid certificate does not lift your site in search, and we do not promise that it will. Google treats HTTPS as a lightweight ranking factor and does not use it for indexing at all; the type and price of the certificate make no difference to search.
OV: when you need it, when you don’t
You need it if
You take payments on your site, you’re a sole proprietor or a company, and counterparties, a bank or a tender want to see a verified organisation in the certificate.
You don’t need it if
If visitors don’t care about seeing the company name in the certificate, and no counterparty requires it.
This is how the organisation will look in the certificate
O = Kava LLC, Kyiv, UAYour organisation details are already filled in from your profile and the state register. Each year you just confirm, nothing to re-enter.
We reissue it without you
Everything that repeats within the subscription is automated.
- 01Domain on our NSWe add the domain validation record ourselves at every reissue.
- 02Domain on other NSYou add a CNAME to our validation zone once. Then it’s automatic too.
- 03FallbackIf nothing else works: an email with a single confirm button.
_acme-challenge.kava.com.ua CNAME k7f2.acme.zrazu.comWhy a subscription, not a “2-year certificate”
Certificate authorities are shortening the life of a single certificate for everyone. So you buy a subscription, and we replace the certificate inside it.
- 200 daysfrom 15.03.2026 — now
- 100 daysfrom 15.03.2027
- 47 daysfrom 15.03.2029
Common questions about OV
Does a paid OV protect better than the free one?
No. The encryption is the same as Let’s Encrypt. The differences are the certificate authority warranty and compatibility with older systems.
Why a subscription and not a 2-year certificate?
A single certificate now lives no longer than 200 days, from 15.03.2027 — 100, from 15.03.2029 — 47. So we sell a subscription: within it we reissue and install the certificate automatically.
What do I need to do at reissue?
Nothing if the domain is on our NS: we add the validation record ourselves. With other NS you add a CNAME once, then everything is automatic.
When don’t I need OV?
When the free certificate works for you and you need neither a certificate authority warranty nor compatibility with older systems.