Websites and Tech

SSL and TLS Certificate

Also called SSL certificate, TLS certificate

A file installed on a server that proves a domain's identity and lets browsers encrypt the connection to it.

Quick facts: SSL and TLS Certificate

Category
Websites and Tech
Also called
SSL certificate, TLS certificate
Level
Beginner
Affects
Browser trust warnings, form security, HTTPS, conversion
Where to see it
Hosting control panel SSL section, browser address bar, Search Console
In this article4
  1. How a certificate works
  2. Why certificates matter
  3. Where certificates go wrong
  4. What to do about it

How a certificate works

A certificate is a small file installed on your server that does two jobs. It contains the public half of a cryptographic key pair, which lets a browser establish an encrypted connection, and it carries a statement from a certificate authority confirming that the key belongs to your domain. Without the second part, the encryption would be private but anonymous.

SSL and TLS are the protocols themselves. SSL is the older family and has been retired; TLS replaced it and is what every current browser uses. The industry kept saying SSL certificate out of habit, so today the two names describe the same purchase.

When a visitor arrives, the browser checks that the certificate matches the domain, has not expired, and traces back to an authority it trusts. If all three hold, the connection is encrypted and the page loads over HTTPS. If any one fails, the browser shows a full-page warning instead of the site.

Why certificates matter

Encryption protects anything a visitor types — an enquiry form, a login, card details — from being read or altered in transit. On public wifi that is not theoretical; unencrypted pages can be modified before they ever reach the browser.

The visible consequence is trust. Browsers mark pages without a valid certificate as not secure, and an expired one produces an interstitial warning that most people will not click past. An expired certificate does not reduce traffic gradually. It stops it.

Where certificates go wrong

Expiry is the most common failure, and it usually happens because a certificate was issued manually and then forgotten. Free automated certificates renew themselves; paid ones often do not, and the reminder goes to an email address nobody monitors any more.

Coverage is next. A certificate issued for one hostname does not cover others, so a shop that also runs a subdomain for a blog or a booking system can secure one and warn on the other. Wildcard certificates exist for exactly that situation.

Then there is a certificate that is valid while the pages are not. Images, scripts or fonts still requested over plain HTTP produce mixed content, and browsers block or downgrade the page even though the certificate is fine.

What to do about it

Use an automatically renewing certificate wherever your host supports one, and check that the renewal actually runs rather than assuming it does. Put an expiry reminder in a shared calendar rather than one person’s inbox.

After any installation, load the site and confirm three things: every hostname you use is covered, every internal link and asset points at the secure address, and old insecure URLs redirect once to their secure equivalent rather than through a chain of hops. Paid certificates earn their cost only when you need wider coverage, validated organisation details or a warranty; for the encryption itself, a free automated certificate does the same work.

Do and do not

Do

  • Use an automatically renewing certificate where the host offers it
  • Cover every subdomain the business actually uses
  • Set an expiry reminder in a shared calendar

Do not

  • Rely on a renewal notice sent to one inbox
  • Leave assets loading over plain HTTP afterwards
  • Assume a paid certificate encrypts better than a free one

Questions people ask about this

Do I need to pay for an SSL certificate?

Usually not. Free automated certificates provide the same encryption and are trusted by every mainstream browser, and most hosts now issue them from the control panel. Paid certificates are worth considering when you need coverage across many subdomains, organisation details validated and displayed, or a warranty and support commitment that a business or its insurer requires.

What is the difference between SSL and TLS?

They are successive versions of the same idea. SSL is the original protocol family and has been retired for security reasons; TLS replaced it and is what browsers actually use to encrypt connections today. The term SSL certificate survived as an everyday name. When you buy one now, you are buying a certificate used with TLS.

What happens when a certificate expires?

Browsers stop loading the site and show a full-page security warning instead. Most visitors leave rather than click through it, so traffic and enquiries drop sharply and immediately, while paid clicks continue to be charged even though nobody reaches the page. Automatic renewal, plus a reminder in a shared calendar, prevents an entirely avoidable outage.

Related terms

Found this useful?

Share it, or ask an AI to summarise it

Back to the glossary

Knowing the term is the easy part

Applying it to your own site and budget is the work. Book a call and I will tell you what actually applies to you.