What Is SSL/TLS and How Does HTTPS Work?
How SSL/TLS certificates and HTTPS protect visitors, what happens during a TLS handshake, what the padlock does and does not prove, and why certificate lifetimes are getting shorter.

Table of Contents
- What HTTPS protects
- What the padlock does not prove
- How the TLS handshake works (simplified)
- Certificates and certificate authorities
- Certificates are getting shorter-lived
- Why every site needs HTTPS
- Reading a browser's certificate warning
- TLS versions in practice
- Making HTTPS work properly
- Frequently Asked Questions
- Related reading
- Sources
HTTPS is HTTP, the protocol browsers use to load web pages, sent over an encrypted TLS connection. TLS (Transport Layer Security) is the modern successor to SSL; people still say "SSL certificate" out of habit. A TLS certificate proves that the server is allowed to use your domain name, and the encrypted connection stops anyone between the visitor and the server from reading or changing what is sent, such as passwords, form data and payment details.
Every website should use HTTPS, including sites without logins or shops.
What HTTPS protects
- Confidentiality: data in transit is encrypted, so people on the same Wi-Fi network or along the network path cannot read it.
- Integrity: data cannot be modified in transit without detection, so nobody can inject ads or malware into your pages on the way.
- Authentication: the certificate shows the visitor's browser that it is talking to a server authorised for that domain.
What the padlock does not prove
The padlock means the connection is encrypted and the certificate is valid for the domain. It does not mean:
- the business is legitimate or trustworthy (phishing sites can have valid certificates);
- the website itself is free of malware;
- data is stored securely once it reaches the server.
How the TLS handshake works (simplified)
- The browser connects and says which TLS versions and cipher suites it supports.
- The server replies with its choices and its certificate.
- The browser checks that the certificate is valid, unexpired, issued by a trusted certificate authority (CA) and matches the domain name.
- Both sides agree on session keys using key exchange, so only they can decrypt the traffic.
- Encrypted communication begins.
Modern TLS 1.3 completes this in fewer round trips than older versions, so the overhead is small.
Certificates and certificate authorities
A certificate contains the domain name(s), the public key, the issuing CA, and validity dates. Browsers trust a set of CAs; certificates from other sources show warnings.
Certificate types differ in how much the CA verifies about the requester (domain only, or the organisation too). See types of SSL certificates.
Certificates are getting shorter-lived
Under a CA/Browser Forum decision, the maximum validity of publicly trusted TLS certificates is being reduced in stages: 200 days from 15 March 2026, 100 days from March 2027, and 47 days from March 2029. Free certificates from authorities such as Let's Encrypt already have short lifetimes. In practice this means automatic renewal is essential. Hosting control panels with AutoSSL or ACME-based tools handle it for you; see how to install a free SSL certificate in cPanel.
Why every site needs HTTPS
- Browsers mark HTTP pages as "Not secure", especially on pages with forms.
- Many modern browser features only work over HTTPS.
- Google uses HTTPS as a lightweight ranking signal.
- Without it, visitors' data and your pages can be intercepted or modified.
Reading a browser's certificate warning
Browsers show warnings when they cannot trust a connection. The most common messages and what they usually mean:
| Warning | Typical cause | Fix (site owner) |
|---|---|---|
| Certificate has expired | Renewal failed | Fix the renewal (often DNS or validation) and reissue |
| Certificate is for a different name | www or a subdomain not included |
Reissue covering all names visitors use |
| Certificate not trusted / unknown issuer | Self-signed or missing intermediate certificate | Install a publicly trusted certificate with the full chain |
| Clock is ahead/behind | Visitor's device time is wrong | Nothing on the server; the user corrects the time |
| Mixed content / "Not secure" on an HTTPS page | Page loads HTTP resources | Change resources to HTTPS |
Visitors should never be told to click through these warnings; they exist to stop exactly the attacks HTTPS prevents.
TLS versions in practice
- TLS 1.3 is the current version: faster handshakes and only modern cryptography.
- TLS 1.2 remains widely supported and acceptable with good settings.
- TLS 1.0 and 1.1 are deprecated and disabled by modern browsers; servers should not offer them.
- SSL 2.0 and 3.0 are long obsolete and insecure.
On shared hosting, the provider sets these; on a VPS, configure your web server to offer TLS 1.2 and 1.3 only.
Making HTTPS work properly
- Redirect all HTTP traffic to HTTPS.
- Fix mixed content: pages loaded over HTTPS that still pull images or scripts over HTTP. See how to force HTTPS and fix mixed content.
- Enable HSTS once HTTPS works reliably, so browsers always use HTTPS. See HTTP security headers explained.
- Use current TLS versions (TLS 1.2 and 1.3) and disable outdated ones.
- Monitor certificate expiry.
Frequently Asked Questions
Are free certificates as secure as paid ones?
The encryption is the same. Paid certificates may add organisation validation, warranties or support, but they do not encrypt better.
Does HTTPS slow down a website?
Negligibly with modern TLS, and HTTPS enables HTTP/2 and HTTP/3, which often make sites faster overall.
What does "Your connection is not private" mean?
The browser could not validate the certificate: it may be expired, issued for a different name, or not trusted. Check the certificate details in the browser.
Related reading
HTTPS is one of the essentials in website security basics. Free SSL is included with the ServerNeed shared hosting plans.
Sources
Last updated 7 October 2026



