WEBINVEST.IT
Glossary

HTTPS

HTTPS is the HTTP protocol transported over TLS, the mechanism that secures the connection between browser and server. When a URL beginning with https:// is accessed, the client negotiates an encrypted session and verifies that the presented certificate is valid for the requested name and linked to a trusted certificate chain. Encryption reduces the likelihood that third parties can read or alter data in transit. However, HTTPS does not certify that a site is trustworthy or that its content is accurate: even a fraudulent site can obtain a certificate for its domain.

Certificate and Name

A TLS certificate associates a public key with one or more names and is issued after validation checks that vary by type. Browser verification includes expiration, covered name, chain, revocation according to available mechanisms, and CA reliability. A certificate valid for example.it may not cover www.example.it unless that name is included. Therefore, configuration must include all used hostnames, with controlled and monitored renewals. Automated certificates reduce manual effort, but a failed renewal can leave the site displaying a security warning.

During the connection, TLS negotiates cryptographic parameters and creates session keys to encrypt data. The browser shows a secure connection indicator, though interface details vary by product. Information sent, such as passwords or payments, is protected in transit when the link is properly established. However, servers and endpoints remain responsible for securely storing data. Malware on devices, application vulnerabilities, misconfigurations, or credential theft can bypass the benefits of in-transit encryption.

HTTPS, HTTP, and DNS

A website can redirect from HTTP to HTTPS, but the initial HTTP contact may occur before the redirect. HSTS allows browsers that have stored the policy to proceed directly to HTTPS; it is not a substitute for the certificate. DNS indicates which endpoint to connect to, while TLS secures and authenticates the connection to the requested name. A DNS change can direct visitors to a different server, but the certificate and virtual host configuration must still be valid. The lock icon does not mean DNS, hosting, or domain ownership are immune from compromise.

HTTPS is essential for protecting privacy and integrity and is required by many modern web features. However, “secure” should be understood within the specific scope of transport. It does not prove that content is free of fraud, that a merchant is trustworthy, or that the cited company owns the domain. Users must verify name and context, not just the certificate icon.

Implementation and Maintenance

Migrating to HTTPS requires a certificate, consistent redirects, internal link updates, sitemap adjustments, canonical tags, cookie settings, and embedded resources. Mixed content—HTTP resources loaded within an HTTPS page—can be blocked or degrade protection. Sensitive cookies should use appropriate attributes, and TLS configurations should exclude obsolete protocols per current guidelines. Every hostname, including APIs and support subdomains, must be checked. Redirects should avoid loops or unnecessary chains.

Monitoring includes certificate expiration, handshake errors, name coverage, and availability after DNS or hosting changes. In summary, HTTPS protects web connections via TLS and verifies certificate names, but does not guarantee site reliability or overall infrastructure security. It is a necessary technical foundation, maintained alongside application security, DNS, and identity management.

← Full glossary