Contact

What is SSL/TLS Certificate?

Definition

An SSL/TLS certificate is a digital document that binds a domain name to a specific public key and is signed by a trusted certificate authority (CA). When setting up an HTTPS connection, the browser validates it to confirm it has reached the right server. Certificates are grouped by validation level into DV, OV and EV, and their maximum lifetimes are being shortened in stages by industry rules.

Also known as: SSL certificate, TLS certificate, HTTPS certificate, X.509 certificate, digital certificate

Tree of the SSL/TLS chain of trust from a root certificate authority through intermediates to certificates issued for domains

Anatomy of a certificate

A certificate is an X.509 document that mainly records which hostnames it covers (the Subject Alternative Name list), the server's public key, a validity window, the issuing authority and that authority's digital signature. The private key is not part of it. It stays on the server and should never be shared; during the TLS handshake the server proves it holds that key by signing with it.

Certificates are validated as a chain. The site's leaf certificate is signed by an intermediate certificate, which in turn is signed by a root certificate stored in the browser's or operating system's trust store. The server must send its intermediates along with the leaf. A self-signed certificate chains to nothing, so on the public web it triggers a browser warning; it only makes sense for internal testing.

DV, OV and EV compared

TypeWhat is verifiedTypical use
DV (Domain Validation)That the applicant controls the domain nameThe vast majority of websites; automated certificates
OV (Organization Validation)Domain control plus the legal existence of the organisationCorporate sites that want the organisation named in the certificate
EV (Extended Validation)A more thorough organisation checkSome financial and public-sector bodies

The encryption is identical across all three; only the vetting of the identity details differs. Chrome and Firefox dropped the special EV display in the address bar in 2019 and other major browsers no longer highlight it either, so EV no longer works as a visible trust badge for users. Domain control is usually proven by placing a file on the web server (HTTP-01) or publishing a TXT record in DNS (DNS-01). Wildcard certificates such as *.example.com cover exactly one level of subdomain and require DNS validation.

Shrinking lifetimes and what they mean for you

The rules for publicly trusted certificates are set by the CA/Browser Forum, a body of browser vendors and certificate authorities. The maximum validity, long fixed at 398 days, dropped to 200 days on 15 March 2026 and is scheduled to fall to 100 days on 15 March 2027 and to 47 days on 15 March 2029. Let's Encrypt, the free automated CA, issues 90-day certificates by default and offers opt-in six-day certificates; it has announced plans to cut its default profile to 64 days in February 2027 and to 45 days in February 2028.

The conclusion is unavoidable: renewing a certificate by hand once a year is no longer a workable process. An ACME client such as certbot, or a host or CDN that manages certificates for you, removes almost all of the risk of an expired certificate.

Problems seen in the wild

  • Name mismatch: the certificate covers www.example.com but the site is served on example.com.
  • Missing intermediate: desktop browsers often cope, while some mobile devices and server-to-server clients fail.
  • Silent renewal failure: automation broke weeks ago and, without expiry monitoring, visitors are the first to notice.
  • "Paid means more secure": a paid DV certificate encrypts no better than a free one.

A certificate alone does not move a site to HTTPS: HTTP requests still need redirecting and every embedded resource has to load from a secure URL.

Related terms

← Back to the glossary