When an address starts with https:// and the browser shows a padlock, the connection between the visitor and the server is encrypted. That’s done with TLS, which many people still call SSL, and it requires a certificate. For a website, it’s no longer optional: without HTTPS, browsers mark the site as “not secure”, payment solutions don’t work, and HTTP/2 and HTTP/3 can’t be used. Here we explain the difference between SSL, TLS and HTTPS, how it works, and how to set it up properly on WordPress.
SSL, TLS and HTTPS: what’s the difference?
SSL was the original protocol for encrypted connections, developed by Netscape in the 1990s. All its versions were retired long ago because of known security holes, and its successor, TLS, is what’s actually used today. The name SSL has simply stuck, so an “SSL certificate” is in practice a TLS certificate. Finally, HTTPS is just HTTP, the protocol browsers use to fetch websites, sent through an encrypted TLS connection.
How TLS works
TLS gives a connection three properties. It’s confidential, because data is encrypted, so no one along the way can read login details, payment data or forms. It has integrity, because any change to the data along the way is detected. And it’s authentic, because the certificate proves you’re talking to the right server and not one pretending to be it. The last one is often forgotten, but without it the encryption would be worthless: you could have a completely private conversation with a fraudster.
Before any data is sent, the browser and server perform a handshake. The browser says which encryption methods it supports, the server picks one and sends its certificate, and the browser checks that the certificate is valid, issued to the right domain and signed by an issuer it trusts. Then they agree on a key that only the two of them know, and the rest of the connection is encrypted with it. The key exchange itself is designed so that an attacker who sees the entire handshake still can’t work out the key.
In older versions, the handshake cost two round trips between browser and server before data could be sent. TLS 1.3 from 2018 brought that down to one and removed a number of weak encryption methods at the same time. TLS 1.0 and 1.1 are officially retired and rejected by modern browsers, so a server should support TLS 1.3 and 1.2 and nothing older. You can check that for free with the SSL Labs server test.
SSL certificates
A certificate binds your domain to a public key and is signed by a certificate authority that browsers trust. The most common type is a DV certificate, where the issuer only checks that you control the domain, usually through a file on the server or a record in DNS. OV and EV certificates also require the company behind it to be verified. Browsers used to show the company name in the address bar for EV certificates, but that’s been removed, so visitors see no difference. The encryption is the same at every level, and for an online store a free DV certificate from Let’s Encrypt, for example, is entirely sufficient.
| Type | What the issuer checks | Typical use |
|---|---|---|
| DV (domain validated) | That you control the domain | The vast majority of websites and online stores |
| OV (organization validated) | The domain and that the company exists | Companies that require it in a policy or a tender |
| EV (extended validation) | The domain and a more thorough check of the company | Banks and the like, today with no visible difference in the browser |
Just as important as the level is which names the certificate covers. A certificate is only valid for the domain names listed in it, and example.com and www.example.com are two different names. Most issuers include both automatically, but it’s still the most common cause of warnings. A wildcard certificate (*.example.com) covers every subdomain one level down, such as shop and blog, but not the bare domain itself, and with Let’s Encrypt it requires you to prove ownership through DNS. If you have several different domains, such as a .com and a .dk, they can share one certificate with several names or have one each.
Certificates expire, and their lifetime is getting shorter: the browser makers and issuers in the CA/Browser Forum have decided to reduce the maximum validity step by step over the coming years. Renewal therefore has to be automatic. An expired certificate triggers a full-page warning in the browser, and then the store is effectively closed. Good hosting renews automatically, and good maintenance that keeps the certificate renewed catches it if renewal fails.
How to check a certificate
The quickest way is to click the icon to the left of the address in your browser. There you can see who issued the certificate, which names it covers and when it expires. If you want to know whether the server is set up properly, SSL Labs’ free server test gives it a grade and shows protocol versions, weak ciphers and missing intermediate certificates. And with access to a terminal, you get the key details in one place:
echo | openssl s_client -connect example.com:443 -servername example.com 2>/dev/null \
| openssl x509 -noout -subject -issuer -dates
The notAfter line is the expiry date. Check it for the domain both with and without www, and you’ll catch most problems before your customers see them.
HTTPS on your website
HTTPS means more than security. Browsers mark sites without HTTPS as “not secure”, Google uses it as a signal in search results, and HTTP/2 and HTTP/3 in practice only work over encrypted connections, so without HTTPS you also miss out on speed. This is how you set it up on WordPress:
- Install a certificate. Most hosting providers do it with one click or automatically, and that should be a requirement when you choose. Read more in the guide to choosing hosting.
- Change the addresses in WordPress to https:// under Settings → General.
- Redirect all HTTP traffic to HTTPS with a permanent 301 redirect, so old links and search results land in the right place.
- Fix mixed content: images, scripts and stylesheets still loaded over http://. Fix the addresses in the database with a search-and-replace tool, and check the theme and plugins for hard-coded addresses.
- Turn on HSTS once everything works, so the browser always uses HTTPS for your domain.
- Update Search Console and other tools to the HTTPS address.
Error messages and what they mean
When something is wrong with the certificate, the browser stops the visitor with a full-page warning. The message usually says exactly where the problem is. The names here are Chrome’s, but other browsers show the same thing in other words:
| Error | What it means | The usual cause |
|---|---|---|
NET::ERR_CERT_DATE_INVALID | The certificate has expired or isn’t valid yet | Automatic renewal has stopped working |
NET::ERR_CERT_COMMON_NAME_INVALID | The certificate doesn’t cover the name that was opened | www or the bare domain is missing |
NET::ERR_CERT_AUTHORITY_INVALID | The browser doesn’t trust the issuer | A self-signed certificate or a missing intermediate certificate |
ERR_SSL_PROTOCOL_ERROR | Browser and server can’t agree on the connection | A server misconfiguration or only outdated TLS versions |
ERR_TOO_MANY_REDIRECTS | The site sends the browser in circles | A CDN and WordPress redirecting back and forth between HTTP and HTTPS |
Two things we see more often than the rest: certificates that expire because automatic renewal stopped working after a change to DNS or hosting, and leftover mixed content in old posts. The latter doesn’t cause a full-page warning, but the padlock disappears, and the browser can block scripts loaded over http://, so parts of the site stop working. The browser’s developer tools show exactly which files are involved under Console.
What HTTPS doesn’t protect against
The padlock means the connection is encrypted, not that the site can be trusted. Scam sites have valid certificates too, and HTTPS protects neither against a hacked plugin, a weak admin password nor an insecure server. Encryption is one layer. Updates, backups, strong logins and secure file transfer with SFTP are the others.
Frequently asked questions
Is a free certificate as secure as a paid one?
Yes, the encryption is the same. A paid certificate can offer higher validation of the company or a warranty, but visitors can’t tell the difference.
How long is an SSL certificate valid?
Certificates from Let’s Encrypt are valid for 90 days and renew automatically. For all issuers, the CA/Browser Forum has decided to cut the maximum validity in steps: 200 days from March 2026, 100 days from March 2027 and 47 days from March 2029. Manual renewal is no longer a realistic plan.
Why does it say “not secure” even though I have a certificate?
Usually because the site can still be opened over http:// without a redirect, or because it loads images or scripts over http://. Check that all traffic is redirected to HTTPS, and look for mixed content in the browser’s developer tools.
Does HTTPS make my site slower?
No, not noticeably. With TLS 1.3 the handshake is short, and because HTTPS is required for HTTP/2 and HTTP/3, a site with HTTPS is in practice usually faster than without.
Want it handled for you?
We set up HTTPS properly, keep certificates renewed and monitor that everything works, as part of our WordPress maintenance.