An SSL certificate—more accurately, a TLS certificate—is a digital credential that links a cryptographic key to a website identity. A browser checks that credential when it connects, while TLS protects information sent between the browser and server. HTTPS helps secure the connection; it does not prove the site itself is trustworthy.
What an SSL certificate does
A certificate is a digital file that associates a public cryptographic key with an identity, such as a website hostname. A certificate authority (CA) issues it after performing the relevant identity checks. When a browser connects to a site, the server presents its certificate and the browser checks whether it covers the requested hostname and whether it can build a trusted path from that certificate to a CA it recognizes.
That path is called the certificate chain: an ordered set of certificates containing the site’s certificate and one or more CA certificates. The certificate helps authenticate the server’s identity; TLS then protects the connection. A useful analogy is that the certificate is an identity credential checked as communication is set up, while TLS is the protected channel used for the conversation. The certificate itself does not encrypt every piece of information on the site.
Is SSL the same as TLS?
SSL (Secure Sockets Layer) is the older name people still commonly use when talking about website certificates. The current protocol is TLS (Transport Layer Security), which protects information sent between a web server and browser by providing confidentiality and integrity. Google Trust Services describes TLS as “formerly known as Secure Sockets Layer or SSL” in its official documentation, updated April 29, 2026. In technical writing, “TLS certificate” is more current; “SSL certificate” remains a familiar search and everyday term.
#1 Best Overall
Does HTTPS mean a website is safe?
No. HTTPS indicates that the browser and server have established a protected connection, helping prevent others from reading or altering data in transit. It does not certify that the site’s operator is honest, its claims are accurate, or its pages are free of malware. Treat HTTPS as a connection-security signal, not a guarantee about the business or content.
Google recommends HTTPS for websites. Its Search Central guidance also notes that issues such as an invalid certificate, insecure dependencies, or redirects through HTTP can affect HTTPS canonicalization. This is a technical site-management recommendation, not a promise of a particular search ranking.
Rank #2
Certificate validation and hostname coverage are different
Validation describes what identity checks the CA performs. Hostname coverage describes which website names the certificate applies to. Those are separate choices: a certificate can have a particular validation type and cover one or several names, subject to its configuration.
Validation types
- Domain Validation (DV): The CA checks control of the domain. DV alone does not establish that the applicant is a legitimate business.
- Organization Validation (OV): The CA checks information about the organization as well as domain control. The exact checks depend on the issuer and its policy.
- Extended Validation (EV): This has historically involved more extensive organization checks. Browser presentation varies, so do not expect a universal green address bar or another consistent visual distinction.
These labels describe identity validation, not a higher or lower level of TLS encryption. Paying for an OV or EV certificate does not, by itself, make the connection more strongly encrypted than one using DV. See the CA/Browser Forum for industry materials on certificate requirements and validation practices.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Hostname coverage
- Single-name: Covers the hostname or names specified for that certificate; check that every hostname visitors use is included.
- Multi-SAN: A certificate can list multiple hostnames in its Subject Alternative Name (SAN) field. Google’s certificate guidance recommends standard multi-SAN certificates where possible.
- Wildcard: Covers matching subdomains under a specified domain, according to the wildcard name. It can simplify deployment across subdomains, but the private key has broader impact: if compromised, it can affect all covered subdomains. Google recommends strict access controls for wildcard private keys when they are used.
Why browsers show certificate warnings
A browser may warn or block access when it cannot verify the connection’s certificate. Common causes include a certificate that does not cover the hostname in the address bar, an expired certificate, or a chain the browser cannot trust. A warning means the browser could not validate the connection as expected; it is not a reliable way to diagnose the exact configuration problem without inspecting certificate details.
You can inspect a site’s certificate from the browser’s site-information or connection controls, but the labels and steps differ by browser and version. Address-bar icons and EV treatment also change over time, so focus on the certificate’s hostname, validity, and chain rather than assuming a particular lock icon proves a site is safe.
Rank #4
What happens when a certificate expires?
A certificate has a validity period. After it expires, browsers may show an error or warning because they can no longer validate it as current. Site operators should renew or replace certificates before expiry and ensure the replacement is deployed with the correct chain.
Google Trust Services recommends ACME clients that support ACME Renewal Information for certificate lifecycle management. Its FAQ, updated April 14, 2026, says that in some circumstances it may need to revoke a certificate within 24 hours or 5 days; those timeframes are Google Trust Services guidance for its stated circumstances, not universal deadlines for every CA.
Quick Recap
Best Value
Certificate maintenance checklist for site owners
- Confirm that every hostname visitors are expected to use is covered, including relevant subdomains.
- Install the certificate with the required CA chain so browsers can validate it.
- Restrict access to private keys, especially wildcard keys that cover multiple subdomains.
- Monitor certificate expiry and automate renewal and deployment where possible.
- After replacement, check the live site and confirm the intended hostnames present a valid certificate and chain.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

