Skip to content

SSL certificate

the encryption behind the https

The credential that makes sure the connection to your website is encrypted and the browser shows no warning.

  1. Browser requests the page
  2. Server presents its certificate
  3. An encrypted connection is established
  4. Padlock instead of a warning

What does SSL certificate mean?

Without encryption, everything exchanged between visitor and website travels across the network in plain text. Anyone on the same Wi-Fi — in a café, a hotel, a waiting area — can read along with freely available means and see what was typed into a form. On a purely informational page that is unpleasant; on a contact form with a name, phone number and enquiry it is a problem.

A certificate is exactly what prevents this. It is a file on your server, issued by a recognised body, and it confirms two things: that this server really does belong to your address, and which key is to be used for encryption. Where it is present, the address begins with https instead of http, and the browser shows a padlock instead of a notice.

The terms have grown historically and they confuse. SSL is the old name of the procedure, TLS the one actually used today. In everyday speech everyone still says SSL certificate, and the same thing is meant. More important than the name is that it is current and valid.

Cost: a certificate can be free. The Let's Encrypt initiative issues them without charge, and the encryption is the same as with a paid one. What more expensive certificates additionally provide is a more thorough check of the company behind the address — for a trade business, a law firm or a hotel that brings no visible advantage as a rule. Anyone selling you a certificate as an annual line item and talking of stronger encryption while doing so is describing it wrongly.

The most common failure has nothing to do with attacks but with a date. Certificates expire, free ones often after 90 days. If renewal does not happen in time, the browser shows a full-page warning and the visitors are gone — usually at the weekend, because nobody is looking. Renewal therefore has to be automated and monitored; that is part of proper hosting, not a special request.

The warning is no small matter. Chrome has expressly marked pages without encryption as "Not secure" since July 2018, and other browsers do something similar. A visitor who sees that does not distinguish between an expired certificate and a genuine attack — they go back. We have seen businesses that received no enquiries for weeks and looked for the cause in their copy.

There is a legal dimension too. Article 32 of the General Data Protection Regulation requires appropriate technical measures reflecting the state of the art and names encryption expressly as an example. A form transmitting names and contact details unencrypted is hard to reconcile with that. This is no reason to panic, but it is a reason not to put it off.

For you that means: the certificate is not a product you acquire once but an ongoing process. The three questions to put to your provider are: is it renewed automatically, am I warned if that fails, and is every variant of my address covered — with and without www. If one of those is missing, the problem is not settled, only postponed.

Check the numbers

Over 90 per cent of pages loaded in Chrome arrive encrypted — the browser has marked unencrypted pages as "Not secure" since July 2018.

Encryption is therefore no longer the exception but the normal case — what stands out now is its absence. For a business that means: an expired certificate produces not an inconspicuous footnote but a full-page warning about your own website. Because free certificates often expire after 90 days, automatic renewal is the actual point, not the price.

Source: Google Transparency Report, section on HTTPS encryption on the web; the marking of unencrypted pages as "Not secure" was introduced by Google with Chrome 68 in July 2018. Both publicly documented.

Common questions

Do I have to pay for an SSL certificate?

No. The Let's Encrypt initiative issues certificates free of charge, and the encryption is the same as with paid ones. More expensive certificates additionally check the company behind the address — for most businesses with no visible benefit.

Do I need this even without an online shop?

Yes. As soon as there is a form anywhere, personal data is transmitted, and Article 32 GDPR names encryption expressly as a measure. Quite apart from that, browsers show a warning on unencrypted pages that puts visitors off.

A term missing? Send it to us

We explain every term calmly and without tech-speak — and tell you honestly what makes sense for you and what doesn't.

ProvenExpert