Extended Validation SSL Certificates on Heroku

Heroku is now using Extended Validation SSL Certificates for most of our Heroku-owned applications. This allows you to tell at a glance if an URL belongs to Heroku itself, or is merely hosted on us.

Fancy Pants cert in action


Applications in our legacy “Bamboo” stack are hosted under the heroku.com DNS domain, which has historically made it difficult for people to differentiate between Heroku-owned apps (e.g., id.heroku.com, dashboard.heroku.com) and customer applications. We believe the extra UI indication will prove useful in solving this problem.

For more information, see "EV SSL Certificates and Heroku-owned Applications" on Heroku DevCenter.

-Tom Maher
Heroku Security Team

Browse the blog archives or subscribe to the full-text feed.