Security · 8 min read ·
What Is an SSL Certificate? Why Every Website Needs HTTPS
What an SSL certificate is, DV vs OV vs EV, free vs paid SSL, the "Not secure" warning, HTTPS and Google rankings, forcing HTTPS and fixing mixed content.
An SSL certificate is a small digital file, issued by a trusted certificate authority, that proves a website belongs to its domain and lets browsers set up an encrypted HTTPS connection. With it, passwords, form entries and payment details cannot be read or changed on the way between visitor and server; without it, Chrome and other browsers label your site "Not secure". For most websites, a free domain-validated certificate, such as one from Let's Encrypt, gives exactly the same encryption as a paid one.
What an SSL certificate does
- Encryption. Data travelling between the browser and your server is scrambled. Someone on the same café Wi-Fi, or anywhere along the network path, sees only gibberish.
- Authentication. The certificate proves the server really is
yourdomain.inand not an impostor, because the certificate authority checked that whoever requested it controls the domain. - Integrity. Nothing can be altered in transit, so no one in the middle can inject ads, scripts or malware into your pages.
Strictly speaking, today's certificates are used with TLS (Transport Layer Security), the successor to SSL. SSL itself was retired years ago, and modern sites use TLS 1.2 or 1.3. The old name stuck, so "SSL certificate" and "TLS certificate" mean the same thing.
How HTTPS works, in plain English
- A visitor's browser connects to
https://yourdomain.inand asks the server to prove who it is. - The server sends its certificate, which contains your domain name, a public key, an expiry date and the certificate authority's digital signature.
- The browser checks that signature against the trusted authorities built into the device, and confirms the domain matches and the certificate has not expired.
- Browser and server agree on a one-time session key, and everything after that is encrypted.
All of this takes milliseconds. HTTPS also unlocks HTTP/2 and HTTP/3, which browsers only support over encrypted connections, so a secure site is often a faster one too.
Types of SSL certificates: DV, OV and EV
| Type | What is checked | Issued in | Best for | Cost |
|---|---|---|---|---|
| Domain Validated (DV) | That you control the domain | Minutes, automatically | Blogs, business sites, most online shops | Free or low cost |
| Organisation Validated (OV) | The domain, plus the organisation's legal registration | Usually 1–3 days | Companies that want their verified name in the certificate details | Paid, mid-range |
| Extended Validation (EV) | Strict checks of legal, physical and operational existence | Several days or more | Banks, large e-commerce and regulated businesses | Paid, highest |
All three use the same encryption; the difference is only how much the certificate authority checked about who you are. Since 2019, Chrome and Firefox no longer show the company name in a green address bar for EV certificates, so visitors see the same indicator whichever type you use.
Single-domain, wildcard and multi-domain certificates
- Single-domain certificates cover one name, usually with www included.
- Wildcard certificates cover every first-level subdomain, such as
*.yourdomain.in. - Multi-domain (SAN) certificates cover several different domains on one certificate.
Free SSL certificate vs paid: is free good enough?
For most websites, yes. Let's Encrypt is a non-profit certificate authority whose free DV certificates are trusted by every major browser and secure a huge share of the web. The encryption is identical to a paid DV certificate. A paid certificate makes sense when you need OV or EV identity checks (for some tenders, enterprise clients or compliance rules), want a warranty or direct support from the certificate authority, or cannot automate renewal.
Validity periods are getting shorter for everyone. Free certificates last 90 days and renew automatically. Paid certificates used to last just over a year, but in 2025 browser makers and certificate authorities agreed to cut the maximum lifetime of every public certificate: 200 days from March 2026, 100 days from March 2027 and 47 days from March 2029. Whatever you pay, automated renewal is becoming essential.
Every HostEthical web hosting plan includes free SSL on every site, so for a normal website there is nothing extra to buy or install.
The "Not secure" warning
Since Chrome 68 in July 2018, Chrome has labelled every page loaded over plain HTTP as "Not secure", and other browsers do much the same. The warning is especially visible when someone starts typing into a form, which is exactly when a customer is about to share a phone number or place an order.
A broken certificate is worse still. If a certificate has expired or does not match the domain, browsers show a full-page "Your connection is not private" warning that most visitors will not click past.
One more detail: since 2023 Chrome shows a neutral "tune" icon instead of a padlock on HTTPS sites, because many people took the padlock to mean "this business is trustworthy". HTTPS means the connection is private; it says nothing about the honesty of the site owner.
Is HTTPS a Google ranking factor?
Yes, a lightweight one. Google announced HTTPS as a ranking signal in 2014, and it remains part of its page experience signals. It will not lift a thin page above better ones, but it is a tiebreaker in your favour, and HTTP pages lose visitors to the warning anyway. There is also an analytics benefit: when visitors click from an HTTPS site to an HTTP site, browsers drop the referrer, so traffic you earned shows up as "direct" instead.
Do you need SSL if you do not sell anything?
Yes. Any site with a contact form, login, newsletter sign-up or comment box collects personal data. India's Digital Personal Data Protection Act, 2023 expects businesses to take reasonable security safeguards for the personal data they handle, and encrypting it in transit is the most basic of those. Many browser features, including location access and installable web apps, only work on HTTPS, and most payment gateways and ad platforms expect a secure site.
How to get an SSL certificate
On shared hosting
With HostEthical hosting, point your domain at your hosting using nameservers or an A record (see how to connect a domain to hosting). A certificate can only be issued once the domain resolves to the server, so allow a little time after a DNS change, then check that https:// loads without warnings.
On a VPS
On an unmanaged VPS you install the certificate yourself. Certbot, a free tool from the Electronic Frontier Foundation, gets and renews Let's Encrypt certificates. On Ubuntu with Nginx:
sudo apt install certbot python3-certbot-nginx
sudo certbot --nginx -d yourdomain.in -d www.yourdomain.in
sudo certbot renew --dry-run
Certbot sets up automatic renewal, and the last command tests it. Our VPS setup guide covers the steps before this.
How to force HTTPS
Having a certificate does not stop people reaching the HTTP version of your site. Send every HTTP request to HTTPS with a permanent (301) redirect, so visitors and Google only ever see one version.
WordPress: under Settings → General, make sure both the WordPress Address and Site Address start with https://, then add a server-level redirect.
Hosting that supports .htaccess files: add this at the top of the .htaccess file in your site's root folder, using the File Manager or SFTP:
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
Nginx, common on a VPS:
server {
listen 80;
server_name yourdomain.in www.yourdomain.in;
return 301 https://$host$request_uri;
}
HSTS: once everything works over HTTPS, the Strict-Transport-Security header tells browsers to use HTTPS for your domain automatically. Start with a short max-age such as 300 seconds and raise it to a year only when you are sure, because browsers will refuse plain HTTP for that whole period.
How to fix mixed content warnings
Mixed content means an HTTPS page loads some images, scripts, stylesheets or fonts over http://. Browsers block insecure scripts and stylesheets outright, which can break layouts and features, and they upgrade or flag insecure images. It is most common right after an older site moves to HTTPS.
- Find the culprits. Open the page, press F12 and check the Console tab, which lists each insecure URL.
- Fix links stored in the database. WordPress saves full URLs in posts, so older content still says
http://. Take a backup, then use a search-and-replace plugin, or WP-CLI on a VPS:wp search-replace 'http://yourdomain.in' 'https://yourdomain.in' --skip-columns=guid - Check theme and plugin settings. Logo URLs, header and footer scripts, page-builder settings and custom CSS backgrounds often hard-code
http://. - Update old embeds. Replace old map, video and widget embed codes with their HTTPS versions, and remove any that do not support HTTPS.
- Add a safety net. The header
Content-Security-Policy: upgrade-insecure-requeststells browsers to fetchhttp://resources over HTTPS. It is a useful fallback, not a substitute for fixing the source.
SSL renewal, expiry and common errors
Every certificate has an expiry date. To check yours, click the icon to the left of the address bar and open the certificate details, or run:
echo | openssl s_client -connect yourdomain.in:443 -servername yourdomain.in 2>/dev/null | openssl x509 -noout -dates
With hosting that includes free SSL, renewal normally happens in the background. When it fails, the cause is usually one of these: the domain no longer points at the server, a CAA record excludes the certificate authority (see DNS records explained), the domain itself has lapsed (see domain expiry and renewal), or, on a VPS, a firewall blocks port 80, which validation needs.
| Browser error | What it means | Fix |
|---|---|---|
NET::ERR_CERT_DATE_INVALID | The certificate has expired, or the visitor's device date is wrong | Renew the certificate. If only one person sees it, they should correct the date and time on their phone or PC. |
NET::ERR_CERT_COMMON_NAME_INVALID | The certificate does not cover this name, often www or a subdomain | Reissue it to cover both yourdomain.in and www.yourdomain.in. |
ERR_TOO_MANY_REDIRECTS | HTTP and HTTPS redirects loop into each other | Keep one redirect rule; make sure a plugin and the server are not both redirecting. |
NET::ERR_CERT_AUTHORITY_INVALID | Self-signed certificate, or the intermediate chain is missing | Use a certificate from a trusted authority and install the full chain. |
| "Not fully secure" | Mixed content on the page | Follow the mixed-content steps above. |
Frequently asked questions
Is a free SSL certificate safe?
Yes. Free certificates from trusted authorities such as Let's Encrypt use the same encryption as paid ones and work in all major browsers; paid certificates add identity validation, a warranty and support.
How long does an SSL certificate last?
Free Let's Encrypt certificates last 90 days and renew automatically. Industry rules are shortening the maximum lifetime of all public certificates, to 200 days from March 2026 and 47 days by 2029.
How can I tell if a website has a valid SSL certificate?
The address starts with https:// and the browser shows no warning. Click the icon to the left of the address to see who issued the certificate and when it expires.
Does an SSL certificate mean a website is trustworthy?
No. It proves the connection is encrypted and the domain is genuine, not that the business behind it is honest, so look for other trust signals before sharing payment details.