
An SSL certificate works by proving your website is who it claims to be, and by supplying the cryptographic key that encrypts traffic between your visitor and your server. It does two jobs at once: identity and encryption.
Most explanations stop at “it encrypts your data”. That is true but incomplete, and the incomplete version is why people misread what the padlock means.
What Happens Without Encryption
A request travelling over plain HTTP is readable by every device it passes through — the visitor’s router, their internet provider, any network in between, and anyone monitoring a shared connection.
Readable means exactly that: form contents, passwords, session cookies, and the pages being viewed are all visible as text. It also means modifiable. Content can be altered in transit, which is how advertising injection and some malware distribution works.
Encryption solves both problems at once. Nothing in between can read the traffic, and nothing can change it without detection.
The Handshake, Step by Step
When a browser connects to an encrypted site, four things happen in under a second.
- The browser asks for the certificate. It connects to the server and requests proof of identity.
- The server presents its certificate. This contains the domain name it covers, the public key, the issuing authority, and the expiry date.
- The browser verifies the certificate. It checks that the domain matches, that the certificate has not expired, and — critically — that it was issued by an authority the browser trusts.
- Keys are exchanged and encryption begins. The two sides agree a session key using the certificate’s public key, and all subsequent traffic is encrypted with it.
Only step four is about encryption. Steps one to three are about identity, and that is the part most descriptions skip.
Why Certificate Authorities Are the Trust Anchor
Anyone can generate a certificate. What makes one trustworthy is who signed it.
Browsers ship with a built-in list of root certificate authorities — organisations they have decided to trust. Those roots sign intermediate certificates, and intermediates sign the certificates issued to individual websites. The result is a chain: your certificate points to an intermediate, which points to a root the browser already trusts.
When a browser verifies a certificate, it walks that chain upward. If it reaches a trusted root, the certificate is accepted. If the chain is broken, incomplete, or ends somewhere the browser does not recognise, the connection is refused.
This is why a self-signed certificate encrypts traffic perfectly well but still triggers a warning. The encryption works; the identity claim has nobody vouching for it.
What the Padlock Verifies, and What It Doesn’t
The padlock is narrower than most people assume.
It does verify: that traffic to this site is encrypted, that the certificate covers the domain shown in the address bar, that the certificate is currently valid, and that a recognised authority issued it.
It does not verify: that the business behind the site is legitimate, that the site is safe to buy from, or that the operators are honest. A phishing site can obtain a valid certificate for its own domain in minutes, and that domain might be one character different from the real one.
This distinction matters because “look for the padlock” remains common security advice. The padlock confirms you have a private connection to whichever domain is in the address bar; reading that domain carefully is the part it cannot do for you. Higher validation tiers exist precisely because domain control is a low bar — for when those tiers are worth the cost, see Do I Need an SSL Certificate?.
Frequently Asked Questions
TLS is the current protocol; SSL is its predecessor and has been deprecated for years. The industry kept saying “SSL certificate” out of habit. Any certificate sold today is used with TLS regardless of the label on the box.
Browsers refuse the connection and display a full-page warning instead of the site. There is no grace period and no degraded mode — the site becomes effectively unreachable for most visitors until a valid certificate is installed.
Negligibly. The handshake adds a small amount of setup time, and modern protocol versions have reduced it further. Encrypted connections also unlock newer transport protocols that are faster than the unencrypted alternatives.
Understanding what a certificate does — and does not — prove makes the tier decision far easier to reason about. ANP Technology supplies and manages Sectigo certificates, including validation handling and renewal tracking so nothing lapses unnoticed.






