Services
Industries
Free Tools
Resources
About Book a Consultation (407) 694-2055
Orlando, FL · Working nationwide since 2008
Glossary · Plain-English definitions

SSL certificate

In one sentence: An SSL certificate is a file installed on a website's server, signed by a trusted certificate authority that verified the site controls its domain, and it is what allows a browser to open an encrypted connection to that site, turning the web address from http into https.

Two jobs: proof, and a locked envelope

A certificate does two things at once. It vouches for identity, because a certificate authority checked that whoever requested it actually controls the domain in question. And it carries the key material a browser uses to encrypt everything that follows.

Picture a customer sitting in a coffee shop on public wifi, filling in your estimate form with her name, her street address, and her phone number. Without a certificate, that request travels as readable text through the cafe router and every network between there and your server. With one, what travels is scrambled, and both ends check that nothing was swapped along the way.

You will see tiers of validation on offer, from a basic domain check up through fuller verification of the legal business entity. For a local service business, the domain-validated certificate that modern hosting issues automatically is almost always enough. The pricier tiers mostly buy paperwork and a warranty clause, not a better lock.

It is worth being clear about what a certificate does not do. It secures the connection, not the business on the other end of it. A scam site can obtain a valid certificate in minutes, because the only thing being checked is control of the domain. The padlock means nobody read your customer's form on its way to the server. It has never meant the company behind the site is honest.

Certificates expire on purpose, and the industry keeps shortening how long they stay valid. That means renewal has to be automatic, or a person has to own that date on a calendar. Those are the only two options that work.

The way this actually goes wrong

The failure is not subtle. When a certificate lapses, the browser stops showing your site and shows a full-page warning about the connection not being safe instead. Your pages are fine. Your host is fine. The visitor reads the word insecure, backs out, and you find out about it days later because a customer happened to mention it.

Lapses happen for boring reasons. A card on file expired, so the auto-renewal failed quietly. The site moved to a new host and nobody reissued the certificate there. The domain got pointed somewhere new and the renewal check stopped matching. Or the certificate covers the bare domain but not the www version, so half your inbound links land on a warning screen and the other half work perfectly, which makes the problem hard to believe when a customer reports it.

Expiry is one of the small items worth watching on an ongoing basis, which is part of what website maintenance covers, because a lapse costs nothing to prevent and a long afternoon to explain.

Neighboring terms worth knowing

HTTPS is the result of having a working certificate, not a separate thing you buy. Your domain name is what the certificate gets issued against, and DNS decides which server that name currently points to. Moving either one is the usual moment a certificate gets forgotten, so treat a host change or a domain transfer as a certificate event too.

Related questions

Do I have to pay for an SSL certificate?

Usually not. Most hosting plans and site platforms include a free certificate that installs itself and renews itself. Paid certificates still exist, mainly for organizations that want an issuer to verify the legal entity behind the site or that want the warranty terms attached to it. If a host charges a separate line item just to turn on basic encryption, ask what that fee is actually for.

My certificate expired. Does that mean my site was hacked?

No. Expiry is a calendar event, not a break-in. Your files, your content, your email, and your host account are untouched. The browser is simply refusing to vouch for the connection because the document that proves who you are ran out, and reissuing it puts the site back the way it was.

Related terms and guides

Website maintenance · HTTPS · Domain name · DNS · All glossary terms · Plain-English answers · All services

Want this working on your own site?

Free consultation, plain-English advice. If you don't need us, we'll say so.

Book a free consultation → Or call/text directly: (407) 694-2055

Ready when you are. Start with a free look.

Tell us a little about the business and we will come back with an honest read: what we would fix first, what it costs, and whether you need us at all. Prefer to see work before you talk numbers? Get a free homepage mockup, built for your business, yours to keep either way.

No obligation, this just starts a conversation. Prefer to talk first? Call or text (407) 694-2055. Orlando based, working with local businesses nationwide since 2008.

Got it, thanks!

Brandon reads every one of these himself. You will hear back shortly with an honest read on what we would do first, what it costs, and whether it is worth it for you.