Site AI Auditod Internet Solutions

What Is an SSL Certificate and Why Does Your Website Need One?

1 sierpnia 2026Czas czytania: 8 minBezpieczeństwo i SSL
What Is an SSL Certificate and Why Does Your Website Need One?

Short answer: An SSL certificate is a small data file, issued by a trusted certificate authority, that lets a website use HTTPS. It encrypts the connection between the visitor’s browser and your server and proves that the site really belongs to the domain in the address bar. Without a valid certificate, modern browsers label your site “Not secure” or block it with a full-page warning.

Almost every website owner has heard that they “need SSL”, but few know what the certificate actually does, why it expires, or why a site can have a certificate and still show warnings. This guide explains the whole picture in plain words, so you can check your own site and know what to ask your host or developer.

What an SSL certificate actually is

A certificate is a digitally signed statement. In simple terms it says: “The public key inside this file belongs to the domain example.com, and a certificate authority has checked that.” The certificate authority (CA) signs this statement with its own key. Browsers and operating systems ship with a list of CAs they trust, so when your server presents the certificate, the browser can verify the signature and decide whether to trust the connection.

A certificate contains a few key pieces of information:

The matching private key stays on your server and must never be shared. If it leaks, someone else could impersonate your site, and the certificate should be revoked and replaced.

SSL or TLS: why the name is confusing

SSL (Secure Sockets Layer) was the original protocol from the 1990s. It was replaced by TLS (Transport Layer Security), and all SSL versions are now considered insecure and disabled in modern browsers. Today your site actually uses TLS, usually version 1.2 or 1.3. The certificates, however, are still commonly called “SSL certificates” out of habit. When a host sells you an “SSL certificate”, it is the same thing as a “TLS certificate”. What matters is that your server uses a current TLS version and a valid certificate.

What a certificate does for your website

A valid certificate delivers three things at once.

  1. Encryption. Everything sent between browser and server – passwords, contact form messages, payment details, cookies – is encrypted. Someone on the same public Wi-Fi, or anywhere along the network path, cannot read or change it.
  2. Authentication. The browser checks that the server it is talking to holds a certificate for the domain the visitor typed. This makes it much harder to impersonate your site through network tricks.
  3. Integrity. Data cannot be silently modified in transit. Without HTTPS, some networks inject ads or scripts into pages; with HTTPS they cannot.

There are also practical side effects. Browsers only allow many modern features, such as geolocation, service workers and HTTP/2 in practice, on secure pages. Google has confirmed that HTTPS is a lightweight ranking signal, and Chrome labels every plain HTTP page as “Not secure”. For a business site, that label alone is often enough to lose a customer’s trust.

Types of SSL certificates

Certificates differ in two ways: how much the CA checks about you (validation level) and how many names they cover.

TypeWhat the CA checksTypical use
Domain Validated (DV)Only that you control the domainMost websites, blogs, small shops
Organization Validated (OV)Domain control plus the company’s legal existenceBusinesses that want company details inside the certificate
Extended Validation (EV)A stricter company verification processBanks and large organisations, mostly for compliance reasons
WildcardCovers all first-level subdomains, such as *.example.comSites with many subdomains
Multi-domain (SAN)Covers a list of different namesSeveral domains or subdomains on one server

All of these use the same encryption. A free DV certificate encrypts traffic just as strongly as an expensive EV certificate. Browsers no longer show the company name in the address bar for EV certificates, so for most small and medium websites a DV certificate is the right choice.

Free vs paid certificates

Free certificates from Let’s Encrypt and similar authorities are trusted by all major browsers and are now used by a large share of the web. Many hosting companies and control panels issue and renew them automatically. Paid certificates make sense when you need OV or EV validation, a warranty required by a contract, or support from a vendor. For a typical business website, a free, automatically renewed certificate is perfectly adequate. The more important question is not “free or paid” but “who renews it, and how will I know if renewal fails?”

How the HTTPS connection is set up

When a visitor opens your site, a short exchange called the TLS handshake happens before any page content is sent:

  1. The browser connects and says which TLS versions and encryption methods it supports.
  2. The server replies with its choice and sends its certificate, plus any intermediate certificates.
  3. The browser checks the chain up to a trusted root, the domain name, and the validity dates.
  4. Both sides agree on session keys, and encrypted traffic begins.

With TLS 1.3 this usually takes only one network round trip, so HTTPS adds very little delay. If any of the checks in step 3 fails, the browser stops and shows an error page instead of your site.

Common certificate problems and what visitors see

Having a certificate installed is not the same as having a working one. These are the problems website audits find most often:

How to check your certificate in one minute

You do not need special tools for a first check:

  1. Open your site in a browser and click the icon to the left of the address. Choose the option to view the certificate.
  2. Look at the “Issued to” names. Make sure both the www and non-www versions you use are listed.
  3. Look at the expiry date. Free certificates typically last 90 days, paid ones up to about 13 months; the industry is moving toward shorter lifetimes.
  4. Type your address with http:// and confirm the browser ends up on https://.
  5. Repeat on a phone using mobile data, which sometimes reveals chain problems a desktop hides.

Developers can use the command line as well: openssl s_client -connect example.com:443 -servername example.com shows the certificate chain and dates. The MDN documentation on Transport Layer Security is a good neutral reference if you want the technical details.

Keeping the certificate valid over time

The single biggest risk is not choosing the wrong type of certificate. It is an unnoticed expiry. Follow these rules to avoid it:

How Site AI Audit checks your certificate

The first step of every Site AI Audit check connects to your website and tests the certificate: whether it is valid, when it expires, and whether HTTP visitors are redirected to HTTPS. The same report also covers security headers and exposed software versions, and each finding is explained in plain words with a fix. The free check shows where your site stands today. Paid plans add re-checks and monitoring with an alert when a certificate is about to expire, so renewal failures are found before visitors see a warning. You can run a free check of your website in about two minutes.

Related reading

The bottom line

An SSL certificate is what makes HTTPS possible: it encrypts traffic, proves your site’s identity and keeps browsers from warning your visitors away. For most websites a free, domain-validated certificate with automatic renewal is enough. The real work is making sure it covers every name you use, is installed with its full chain, redirects all HTTP traffic, and never expires unnoticed.

FAQ

Do I need an SSL certificate if my site does not sell anything?

Yes. Browsers mark every HTTP page as not secure, regardless of what the site does. HTTPS also protects contact forms, logins and cookies, and it prevents networks from injecting content into your pages.

Is a free SSL certificate less secure than a paid one?

No. Free and paid certificates use the same encryption standards and are trusted by the same browsers. Paid certificates differ in validation level, warranty and support, not in how well they encrypt traffic.

How long does an SSL certificate last?

Free certificates from Let’s Encrypt are valid for 90 days and are meant to be renewed automatically. Paid certificates are currently issued for up to about 13 months, and the maximum lifetime is being reduced further in the coming years, which makes automatic renewal increasingly important.

What happens when my SSL certificate expires?

Browsers stop trusting the connection and show a full-page security warning instead of your site. Most visitors will not click through it, and some apps and services will refuse to connect at all until the certificate is renewed.

Does one certificate cover both www and non-www?

Only if both names are listed in the certificate. Most hosts include both automatically, but it is worth checking, because a missing name causes an error for everyone who uses that version of your address.

#HTTPS#SSL certificate#Website security
Sprawdź swoją stronę — za darmo.Co poprawić na Twojej stronie — i od czego zacząć.
Zacznij za darmo
Internet Solutions

Więcej od naszego zespołu

Stworzone przez Internet Solutions. Wypróbuj nasze pozostałe produkty — każdy oszczędza czas na swój sposób.

internet-solutions.net ↗
Site AI Audit
Przegląd prywatności

Ta strona używa plików cookie, abyśmy mogli zapewnić Ci jak najlepsze wrażenia. Informacje z plików cookie są przechowywane w Twojej przeglądarce i pełnią funkcje takie jak rozpoznawanie Cię po powrocie na stronę oraz pomagają naszemu zespołowi zrozumieć, które sekcje strony są dla Ciebie najciekawsze i najbardziej przydatne.