SSL/TLS is the cryptographic protocol that secures HTTP traffic as HTTPS. It encrypts data in transit between a client (usually a browser) and a server, and it uses certificates to help the client verify it is talking to the legitimate site for that domain.
People still say “SSL certificate” colloquially; modern sites use TLS. The user-visible outcome is the same: HTTPS with a valid certificate.
What TLS does and does not do
Does: protect passwords, forms, and cookies from easy interception on the network; signal authenticity of the certificate chain for the domain.
Does not: fix SQL injection, weak passwords, or insecure plugins. Application security remains separate—see web application security.
HTTPS connection (simplified)
- Browser connects to the site on HTTPS
- Server presents a certificate
- Browser validates the certificate chain
- Encrypted session keys are established
- Application data flows over the secure channel
Certificates in practice
Certificates are issued by certificate authorities and bound to domain names. Hosting panels often automate issuance and renewal. After DNS changes, ensure certificates cover the right host names (www and apex, staging, etc.).
Certificate lifecycle
Track renewal dates—or better, automate renewal. Expired certificates cause sudden scary browser warnings and lost conversions. Staging and secondary hostnames are common sources of forgotten expiries.
Mixed content
HTTPS pages that load scripts or images over HTTP trigger browser blocks or warnings. After enabling TLS, audit for mixed content.
Beyond the padlock
HSTS, secure cookie flags, and redirecting HTTP to HTTPS strengthen transport security. Still pair with application security practices.
FAQ
Free certificates vs paid?
For many sites, automated public certificates are appropriate. Extended validation marketing claims matter less than correct host coverage, strong configuration, and reliable renewal.