3 4 5 A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

What is SSL

SSL and certificates for protected connectionsDefinition:

SSL stands for Secure Sockets Layer, a family of cryptographic protocols created to establish protected communications between applications connected to a network. SSL provided authentication, confidentiality and integrity through a negotiation that took place before data was exchanged.

All versions of SSL are obsolete and were replaced by TLS (Transport Layer Security). However, expressions such as SSL certificate, SSL connection and SSL encryption remain common commercial terms for certificates and connections that actually operate with TLS.

Origin and evolution of SSL

SSL was developed by Netscape during the 1990s to protect communications between browsers and servers. SSL 2.0 was the first publicly distributed version, while SSL 3.0 introduced major protocol changes and provided a basis for the later development of TLS.

Weaknesses discovered in SSL prevent it from being considered suitable for current connections. The IETF prohibited the use of SSL 2.0 and stated that SSL 3.0 must not be used. The name survives because it became established before TLS became the standard.

Differences between SSL and TLS

SSL and TLS have the same broad purpose, but they are not two equivalent current modes. TLS is the successor protocol, with revised specifications and mechanisms. Modern systems negotiate TLS versions and should not fall back to SSL for compatibility with older software.

TLS establishes a protected channel through two main components. During the handshake, the client and server agree on parameters, authenticate the server and obtain shared cryptographic material. The record protocol then uses those keys to protect transmitted data.

For this reason, when a provider offers an “SSL certificate”, it normally supplies a digital certificate used by TLS. The certificate does not contain or activate the SSL protocol: it binds a public key to one or more names and allows the client to validate the identity presented during negotiation.

What an SSL certificate contains

A certificate used with TLS usually follows the X.509 standard. Its main data include the covered domain or set of domains, the public key, the issuer, the validity period and the certification authority’s digital signature.

Certificates can be distinguished by the scope of names they cover. A conventional certificate may protect one specific name; a multi-domain certificate includes several names; and a wildcard certificate can cover subdomains at a defined level. This classification is separate from the validation level applied by the certification authority.

Domain-validated, organisation-validated and extended-validation certificates are also available. These categories describe the checks performed before issuance, but they do not guarantee that the content is legitimate, that fraud is absent or that the server remains secure after installation.

Certificate issuance and installation

The process begins with the generation of a key pair. The private key remains under the server’s control, while the public key is included in a request or automated issuance process. The certification authority verifies control of the domain and, depending on the certificate type, additional information about the organisation.

After issuance, the server presents the certificate together with the intermediate certificates needed to form a chain of trust. The client checks the requested name, validity, signature and relationship with an authority it trusts. Renewal may be manual or use automated protocols, and an expired or incorrectly configured certificate causes validation errors.

Issuance does not always involve a purchase. Commercial certification authorities and automated services that provide certificates at no cost are both available. Validation level, name coverage, automation and associated services are dimensions separate from the TLS protocol being used.

SSL protection and limitations

In current usage, the protection attributed to SSL is actually provided by TLS. The channel offers three main properties:

  • Confidentiality: Transmitted content is encrypted so that parties outside the endpoints cannot read it directly.
  • Integrity: Alterations made during transmission can be detected.
  • Authentication: The client can verify that the server controls the private key associated with the presented certificate.

These properties protect data during the connection, but they do not remove other risks. TLS does not prevent a user from submitting information to a fraudulent domain with a valid certificate, does not protect data after storage and does not fix vulnerabilities in the application or device.

Relationship between SSL and HTTPS

HTTPS is HTTP transmitted over a connection protected by TLS. The certificate helps authenticate the server during that connection, while HTTPS defines how web requests and responses are exchanged over the protected channel.

The address begins with https://, but visual indicators vary between browsers. The absence of a warning means that the connection has passed the browser’s technical checks; it does not by itself establish that the page is trustworthy. Certificate information can be viewed through the browser’s security controls.