What is an SSL certificate and why do I need one?
What SSL certificates do
SSL (Secure Sockets Layer) certificates, now technically superseded by TLS (Transport Layer Security), encrypt the data sent between a user's browser and your web server. This means that sensitive information like passwords, credit card numbers, and personal details cannot be easily intercepted by attackers. When a site has an SSL certificate, the URL starts with 'https://' instead of 'http://', and a padlock icon appears in the address bar.
Certificates are issued by Certificate Authorities (CAs) after verifying domain ownership (and sometimes organization identity). They contain the domain name, the certificate holder, the issuer, and a public key used for encryption. The corresponding private key is kept on the server.
- Encrypts data in transit
- Authenticates the website's identity
- Enables HTTPS, which is required for many modern web features
- Builds trust with visitors
Why you need one
Beyond security, SSL certificates are now essential for SEO and user experience. Google uses HTTPS as a ranking signal, and browsers like Chrome flag non-HTTPS sites as 'Not Secure'. This warning can scare away visitors, especially on pages with login forms or checkout processes.
Additionally, many web technologies, such as geolocation, service workers, and HTTP/2, require a secure context (HTTPS) to function. If you run an online store, you're also required by PCI DSS to use SSL to protect payment information.
Common mistakes
- Thinking SSL is only for e-commerce sites; all sites benefit from encryption and trust.
- Believing that SSL slows down a site significantly; modern hardware and protocols make the overhead minimal.
- Assuming a padlock means the site is trustworthy; it only means the connection is encrypted, not that the site is legitimate.
