Skip to content
lesson Websites, hosting and domains Beginner 2 min read

What is an SSL certificate?

An SSL certificate proves a website belongs to its domain name and lets browsers encrypt the connection. Who issues one, and why it expires.

An SSL certificate is a small data file on a web server that proves the site belongs to the domain name in the address bar. With it, a browser can set up an encrypted connection to the site, and the address starts with https.

Why it is still called SSL

SSL stands for Secure Sockets Layer, the old standard for encrypting the link between a browser and a server. It has been replaced by Transport Layer Security (TLS), and the Australian Signals Directorate says SSL itself should no longer be used. The old name stayed on the product. When a host sells an “SSL certificate”, what you get is a certificate used with TLS.

What a certificate proves

The certificate holds the domain name it was issued for and a public key, and it is signed by the organisation that issued it. When a browser connects, the server sends the certificate and shows that it holds the matching private key. The browser then checks that the certificate:

  • was issued by an organisation the browser trusts
  • is still valid
  • was issued for the domain the visitor is trying to reach.

If any check fails, the browser shows an error page and will not connect until the visitor chooses to accept the risk.

Who issues them

Certificates are issued by certificate authorities. Each browser keeps its own list of the authorities it trusts. To get a certificate, the owner of a site applies to an authority and shows that they control the domain.

There are three types, and they differ in how much the authority checks about the organisation:

  • Domain validation (DV) confirms control of the domain and nothing more.
  • Organisation validation (OV) adds details about the organisation.
  • Extended validation (EV) needs extensive documents and costs the most.

The Australian Signals Directorate’s advice is that a DV certificate suits most websites, that it can be had for free, and that paying for one adds no security. The encryption is the same across all three types. Browsers used to show an extra sign for an EV certificate and no longer do.

Certificates expire

Every certificate has an end date. Once it passes, the “still valid” check fails and visitors see the error page, although nothing on the site has changed. The Australian Signals Directorate recommends automating renewal so that this cannot be forgotten.

Two questions for whoever hosts your site:

  • Is the certificate renewed automatically?
  • If a renewal fails, who is told?

Sources

  1. Implementing certificates, TLS, HTTPS and opportunistic TLS (Australian Signals Directorate) cyber.gov.au
  2. Secure Sockets Layer (SSL) (MDN Web Docs, Mozilla) developer.mozilla.org
  3. Digital certificate (MDN Web Docs, Mozilla) developer.mozilla.org
  4. Certificate authority (MDN Web Docs, Mozilla) developer.mozilla.org
  5. Enable HTTPS on your servers (web.dev, Google) web.dev

Written by Only Tech Solutions.

This is general information, not advice for your situation. See the terms and conditions.

We can sort this for you

More lessons

All lessons

Tell us what needs sorting.

Book a call or send an email. We reply within one business day.