How HTTPS and SSL Certificates Work
SkillVeris Team
Cloud & Security Team

HTTPS is HTTP wrapped in TLS encryption, which keeps data private and verifies you are talking to the real server, not an impostor.
In this guide, you'll learn:
- An SSL/TLS certificate binds a domain name to a public key and is signed by a certificate authority your browser already trusts.
- The TLS handshake uses asymmetric (public-key) cryptography to safely agree on a fast symmetric key for the rest of the session.
- The padlock icon means the connection is encrypted and the certificate is valid — it does not mean the site itself is trustworthy.
- Let's Encrypt issues free, automated certificates, which is why HTTPS is now the default across the web.
1What Is HTTPS?
HTTPS (Hypertext Transfer Protocol Secure) is ordinary HTTP running inside an encrypted TLS tunnel. It does two jobs at once: it encrypts the data flowing between your browser and a server so nobody can read or tamper with it, and it verifies the server's identity so you know you're really connected to your bank and not an attacker impersonating it.
The 'S' is provided by TLS (Transport Layer Security), the successor to the older SSL protocol. People still say 'SSL certificate' out of habit, but every secure site today uses TLS. Without HTTPS, anyone on the same network — a coffee-shop Wi-Fi, an internet provider — could read your passwords in plain text.
2The Two Problems HTTPS Solves
HTTPS exists to solve two separate but related dangers of sending data over a network you don't control.
- Eavesdropping: encryption scrambles the data so intermediaries see only meaningless bytes.
- Tampering: TLS adds integrity checks, so if a packet is altered in transit the connection breaks instead of delivering corrupted data.
- Impersonation: the certificate proves the server owns the domain, defeating fake sites that look identical.
- Together these give you confidentiality, integrity, and authentication — the three pillars of a secure channel.
🔑Key Idea
Encryption alone isn't enough. You could encrypt a conversation with an attacker perfectly and still be robbed. Certificates solve the 'who am I actually talking to?' half of the problem.
3Public-Key Cryptography in Plain English
HTTPS relies on asymmetric cryptography, which uses a mathematically linked pair of keys. Anything encrypted with the public key can only be decrypted with the matching private key, and vice versa.
Picture a mailbox with a public slot anyone can drop letters into, but only you hold the key to open it. The server publishes its public key for the world to use; it guards the private key. This lets a browser send a secret to the server that only the server can read, without ever having met before.
Why Not Use It for Everything?
Asymmetric encryption is slow. So TLS uses it only briefly — to safely agree on a shared symmetric key. Symmetric encryption (the same key on both ends) is far faster and handles the actual data for the rest of the session.
4The TLS Handshake, Step by Step
The TLS handshake is the short negotiation that happens before any real data is sent. In modern TLS 1.3 it takes a single round trip and completes in milliseconds.
- Client hello: the browser lists the TLS versions and cipher suites it supports.
- Server hello and certificate: the server picks a cipher and sends its certificate containing its public key.
- Verification: the browser checks the certificate's signature, domain, and expiry against its list of trusted authorities.
- Key exchange: both sides use public-key math to agree on a shared session key without sending it in the clear.
- Encrypted session: from here, all traffic is encrypted with the fast symmetric session key.
💡Pro Tip
TLS 1.3 removed older, weaker options and cut the handshake to one round trip. If you control a server, disable TLS 1.0 and 1.1 entirely — they have known weaknesses.
5Certificates and Certificate Authorities
A certificate is a digital document that says 'this public key belongs to this domain,' signed by a certificate authority (CA). Your browser and operating system ship with a built-in list of trusted CAs, and trust flows down from them.
The Chain of Trust
CAs don't sign every site directly. A root CA signs intermediate CAs, and those sign your certificate. The browser verifies each link up to a root it already trusts. If any link is missing or expired, the padlock disappears and a warning appears.
Validation Levels
Certificates come in tiers based on how much identity checking the CA performs before issuing them.
Domain Validation (DV): proves control of the domain only — fast, free, most common.
Organization Validation (OV): the CA verifies the legal organization behind the domain.
Extended Validation (EV): the most rigorous vetting, used by some banks and enterprises.6Getting and Renewing a Certificate
Getting HTTPS on your own site is now free and largely automated thanks to Let's Encrypt, a nonprofit certificate authority. The most common workflow uses Certbot to request, install, and renew certificates.
- sudo certbot --nginx -d example.com -d www.example.com # request and auto-configure
- certbot renew --dry-run # test that automatic renewal works
- Certificates from Let's Encrypt last 90 days by design
- A scheduled job renews them automatically well before expiry
⚠️Watch Out
Expired certificates are one of the most common causes of site outages. Always automate renewal and set up an alert that fires days before expiry, not after.
7What the Padlock Really Means
The padlock icon confirms two specific things and nothing more: the connection is encrypted, and the certificate is valid for the domain in the address bar. It does not mean the website is honest, safe, or malware-free.
Attackers routinely obtain free DV certificates for phishing domains, so a padlock on a site claiming to be your bank proves only that the connection is private — not that the site is legitimate. Always check the actual domain name, not just the lock.
8Common Mistakes to Avoid
A few recurring errors weaken HTTPS or break it entirely. Avoid these to keep connections secure and uninterrupted.
- Letting certificates expire because renewal was never automated.
- Serving mixed content — an HTTPS page that loads images or scripts over plain HTTP, which browsers flag as insecure.
- Supporting outdated protocols like TLS 1.0 or weak ciphers that attackers can exploit.
- Treating the padlock as proof a site is trustworthy rather than merely encrypted.
- Skipping the intermediate certificate in the chain, which breaks trust on some clients.
9Key Takeaways
The core of HTTPS comes down to a few durable ideas worth remembering.
- HTTPS is HTTP inside a TLS tunnel that provides encryption, integrity, and identity.
- Public-key crypto safely agrees on a fast symmetric key during the handshake.
- A certificate binds a domain to a public key and is signed by a trusted CA.
- Let's Encrypt makes certificates free and automatic, so HTTPS is now the default.
- The padlock means encrypted, not trustworthy — always read the real domain.
10Frequently Asked Questions
Q: What is the difference between SSL and TLS? A: TLS is the modern, more secure successor to SSL. SSL is technically obsolete and its last version was deprecated years ago, but people still say 'SSL certificate' out of habit. Every secure connection today actually uses TLS.
Q: Does HTTPS make my website completely secure? A: No. HTTPS secures data in transit between browser and server, but it does nothing about vulnerabilities in your application code, weak passwords, or server misconfiguration. It is one essential layer, not the whole picture.
Q: Why do certificates expire? A: Short lifetimes limit the damage if a private key is ever stolen and force keys to rotate regularly. Let's Encrypt issues 90-day certificates specifically to encourage automated renewal, which is more reliable than long-lived manual ones.
Q: Can I use HTTPS for free? A: Yes. Let's Encrypt issues free domain-validated certificates, and tools like Certbot automate installation and renewal. This is a major reason HTTPS is now standard across the entire web.
Related Reading
Get The Print Version
Download a PDF of this article for offline reading.
About the Publisher
SkillVeris Team
Cloud & Security Team
Our cloud and security experts break down complex infrastructure topics into practical, beginner-friendly guides.
View all postsRelated Posts
Never miss an update
Get the latest tutorials and guides delivered to your inbox.
No spam. Unsubscribe anytime.