Understanding SSL Certificates
SSL (Secure Sockets Layer) certificates encrypt data transmitted between your website and users, ensuring privacy, data integrity, and secure communications.
Types of SSL Certificates
Choose the right type of certificate depending on your website and security needs:
- Domain Validated (DV) – Quick and basic encryption
- Organization Validated (OV) – Verified organization identity
- Extended Validation (EV) – Highest trust, green address bar in browsers
Benefits of SSL
- Data encryption to protect sensitive information
- Boosts customer trust and confidence
- Improves SEO rankings (Google favors HTTPS)
- Prevents phishing and man-in-the-middle attacks
Implementing SSL Correctly
Install the certificate properly on your server, redirect HTTP to HTTPS, and monitor expiration dates to ensure continuous protection.
Best Practices:
- Renew certificates before expiry
- Use strong encryption algorithms
- Enable HSTS (HTTP Strict Transport Security)
- Test SSL installation with online tools for errors
Pro tip: Always back up your private keys securely and never share them publicly.
Conclusion: SSL certificates
SSL certificates are essential for any website that values security, trust, and compliance. Implement them properly to protect your data and your users.
What has changed for digital certificates
Two points in older SSL guides are now out of date. Browsers no longer show a green bar or company name for Extended Validation certificates; Chrome and Firefox removed that indicator in 2019. And certificates are getting shorter lives. Under the CA/Browser Forum's ballot SC-081v3, public certificates issued from March 15, 2026 may be valid for at most 200 days, falling to 100 days in March 2027 and 47 days in March 2029. Let's Encrypt, whose certificates last 90 days, plans to reach 45 days by February 2028. Manual renewal cannot keep up, so automation is now part of website security.
A short Let's Encrypt guide for Linux servers
- Point the domain's DNS at the server and open ports 80 and 443.
- Install an ACME client such as Certbot from your distribution's packages.
- Request the certificate with the Apache or Nginx plugin, which also writes the HTTPS configuration.
- Confirm that automatic renewal is scheduled, and run a dry-run renewal to prove it works.
- Add monitoring that warns well before expiry in case renewal fails silently.
SSL best practices beyond installation
- Allow only TLS 1.2 and TLS 1.3; versions 1.0 and 1.1 were formally deprecated by RFC 8996 in 2021.
- Serve the full certificate chain, not just the site certificate.
- Redirect every HTTP address to HTTPS in a single 301 step, then fix mixed content so images and scripts also load securely.
- Publish a CAA record in DNS naming the certificate authorities allowed to issue for your domain.
- Enable HSTS only after the HTTPS setup works everywhere, including any subdomains it will cover.
Frequently asked questions: SSL certificates
Is TLS the same as SSL?
TLS is the modern successor to SSL. Every current "SSL certificate" is actually used with TLS encryption; the old name simply stuck.
Why does my site say "Not secure" after installing SSL?
Usually some images or scripts still load over HTTP, the certificate does not cover that exact hostname (such as the www version), the chain is incomplete, or the certificate has expired.
Do I need separate certificates for www and subdomains?
No. One certificate can list several names, such as the bare domain, www and a shop subdomain. A wildcard certificate covers one level of subdomains; with Let's Encrypt it requires DNS-based validation, so automated renewal needs API access to your DNS provider.
Need help with this? Our SSL certificate installation and HTTPS fixes service sets up automated renewal, DNS configuration covers CAA records, and website maintenance plans keep an eye on expiry. Request a quote.





