A "SSL Certificate" is the common term for the digital certificate a server presents during an HTTPS connection. Technically, modern sites use TLS, the successor to the SSL protocol; the historical name persists in commercial language. The certificate binds a public key to one or more domain names and is signed by a browser-recognized Certificate Authority. During the connection, the browser verifies that the requested name is included, that the certificate is time-valid, and that the trust chain is acceptable. If checks pass, TLS negotiates keys to encrypt traffic between browser and server.
Encryption protects the confidentiality and integrity of data in transit: a network observer should not be able to easily read or modify communication without detection. HTTPS, however, does not guarantee the site’s overall reliability. A fraudster can obtain a valid certificate for their domain and use it to provide an encrypted connection to a deceptive page. The lock icon in the browser indicates that the connection is protected according to TLS checks, not that the seller is trustworthy or that the content is accurate. Users must also verify the domain and context.
Types and Coverage
A certificate can cover a single name, multiple specified names, or, in certain cases, a set of subdomains via wildcard. Validation methods may confirm domain control or, for some certificates, additional organizational information. Modern browsers display different validation levels, which should not be confused with commercial guarantees about the site. The choice depends on the number of hosts, renewal frequency, key management model, and infrastructure requirements. Wildcard certificates simplify certain configurations but a shared key can increase impact if compromised.
Certificates have an expiration date and must be renewed before validity ends. Renewal can be automated using dedicated protocols and tools, but the process must be monitored to ensure the new certificate is properly installed on all servers, proxies, and load balancers. An expired, mismatched, or incomplete chain certificate triggers warnings and may block access. Registration in Certificate Transparency logs and monitoring for new issuances provide additional visibility, but do not replace secure private key management.
Configuration and Maintenance
The public certificate can be copied to servers following controlled procedures; the associated private key must remain confidential and accessible only to components that require it. Protecting it with proper permissions, maintaining encrypted backups, and rotating it in case of suspected exposure reduces risk. TLS configuration should use supported versions and cryptographic suites, redirect HTTP to HTTPS when appropriate, and update any mixed content references on the page. Security also depends on applications, accounts, servers, and content: the certificate is a component, not a substitute for software updates or access controls.
To verify a configuration, one can check name, dates, chain, algorithm, and responses from all hosts serving the site. Auto-renewal and deployment across different environments should also be tested without exposing keys in logs or public archives. In summary, an SSL/TLS certificate allows the browser to authenticate the server through a trust chain and negotiate encrypted communication. HTTPS secures transport but does not validate commercial legitimacy and requires ongoing renewal and maintenance.
← Full glossary