TERM · SECURITY

SSL certificate

What is an SSL certificate?

An SSL certificate is the electronic document that proves which domain a site belongs to and lets the connection run encrypted over HTTPS, with the padlock in the address bar. A certificate authority issues it for a fixed period, and it has to be renewed before it expires. It encrypts what passes between browser and server, so passwords and submitted forms cannot be read on the way.

Example

A company site’s certificate expires on a Saturday morning. From that moment every visitor meets a full-page warning that the connection is not private, with a button they have to click deliberately to go on. Most people do not go on. The form is not filled in, and in the analytics it looks like a sudden drop in traffic rather than a technical fault.

The fix takes minutes; the loss is in the hours before anyone notices. So a certificate is either renewed automatically or watched as a date — not discovered by a customer ringing to ask why their browser is stopping them. Who issued the certificate on a domain, and how long it runs, takes seconds to read in the domain check.

The types, briefly. Domain validation (DV) proves only that you control the domain and is issued automatically; for most sites that is enough. Organisation validation (OV) and extended validation (EV) add checks on the company itself; browsers stopped showing them differently years ago, so the difference is in what the other side trusts, not in the interface. A wildcard certificate covers subdomains as well.

Validity is being shortened on an industry schedule: since 15 March 2026 a new certificate lasts at most 200 days, from 15 March 2027 that becomes 100, and from 15 March 2029 it becomes 47. Renewing by hand stops being practical; issuing has to be automatic.

Why it matters for a business

HTTPS is not an extra. Browsers mark pages without it as not secure and warn inside password and payment fields. Google has used HTTPS as a ranking signal since 2014. And a form collecting personal data over an unencrypted connection is hard to defend against the requirement to protect that data by appropriate technical means.

A certificate protects the route, not the site. It stops nothing about a stolen password, a vulnerable module or malicious code in a theme. The name is historical too: SSL is the protocol TLS replaced, but the certificates are still called SSL.

Renewing certificates runs together with platform and module updates in monthly website maintenance.

What to ask

  • Who issues the certificate, and does it renew automatically?
  • Who receives the warning thirty days before it expires?
  • Does http redirect to https, and is HSTS switched on?
  • Is there mixed content — images or scripts still loaded over http — removing the padlock?
  • Does it cover the www variant and any subdomains you use?
  • What happens if it expires on a Saturday: who is called, and how fast is it fixed?

A term you do not recognise? Write to us and we will add it.

The glossary grows with the questions we are asked.