When you see a padlock next to a website address and the address starts with https://, that site is using an SSL certificate. This guide explains what an SSL certificate is, how it protects your visitors, which type you need, and when a free certificate is enough.
SSL certificate meaning in one sentence
An SSL certificate is a small data file installed on a web server that proves the website's identity and lets the browser set up an encrypted connection with it.
Without it, everything a visitor sends to your site (passwords, contact forms, card details) travels as plain text that can be read or changed on the way. With it, the data is encrypted between the visitor's browser and your server.
SSL vs TLS vs HTTPS
- SSL (Secure Sockets Layer) is the original name of the protocol. The old SSL versions are no longer used because they are not secure.
- TLS (Transport Layer Security) is the modern protocol that actually protects connections today.
- HTTPS is simply HTTP running over TLS. It is what you see in the address bar.
People still say "SSL certificate" out of habit. Technically it is a TLS certificate, but the product is the same thing.
How does an SSL certificate work?
In simple terms, three things happen when someone opens your site:
- The browser asks the server to prove who it is. The server sends its certificate.
- The browser checks the certificate. It verifies that the certificate was issued by a trusted certificate authority (CA), that it has not expired, and that it was issued for exactly this domain.
- They agree on a secret key. If everything checks out, browser and server create a shared encryption key, and the rest of the visit is encrypted.
This takes a fraction of a second and the visitor does not notice it, apart from the padlock.
Why your website needs SSL
- Security: logins, forms and payments are encrypted.
- Trust: modern browsers mark sites without HTTPS as "Not secure", especially on pages with forms. Many visitors leave when they see that warning.
- Payments: card payment providers require HTTPS on checkout pages.
- Search: Google uses HTTPS as a light ranking signal. It will not push a weak page to the top, but sites without HTTPS start at a disadvantage.
- Modern features: many browser features (geolocation, some payment and login APIs) only work over HTTPS.
Types of SSL certificates
By validation level
| Type | What is checked | Issued in | Good for |
|---|---|---|---|
| DV (Domain Validation) | only that you control the domain | minutes to a few hours | blogs, small business sites, most websites |
| OV (Organization Validation) | the domain and that the company really exists | 1–3 days | company websites, portals |
| EV (Extended Validation) | a full check of the company | several days | banks, large e-commerce, sites where trust is critical |
All three give the same encryption. The difference is how much the certificate authority checked about who owns the site.
By number of domains
- Single-domain: protects one name, for example example.com (usually also www.example.com).
- Wildcard: protects a domain and all its subdomains of one level: *.example.com covers shop.example.com, mail.example.com, blog.example.com.
- Multi-domain (SAN): protects several different domains with one certificate.
Free vs paid SSL certificates
Free certificates (issued automatically by hosting panels) are DV certificates. They encrypt traffic exactly as well as paid DV certificates and renew themselves every few months. For most websites, a free certificate is enough.
A paid certificate makes sense when you need:
- OV or EV validation, so the certificate shows your verified company name;
- a wildcard for many subdomains on one certificate;
- a warranty from the certificate authority and longer validity per issue;
- support with installation on servers outside a hosting panel.
At IPHOST, every web hosting plan includes unlimited free SSL for your domains, installed and renewed automatically. If you need more, see our SSL certificates.
How much does an SSL certificate cost?
- Free DV certificates: $0, included in most hosting plans.
- Paid DV certificates: usually from about $10 to $60 per year.
- Wildcard certificates: usually from about $60 to $250 per year.
- OV and EV certificates: from about $50 to several hundred dollars per year.
For reference, at IPHOST a RapidSSL® DV certificate costs $26.11/year and a RapidSSL Wildcard costs $154.43/year (prices at the time of writing; current prices are on the SSL page).
How to get and install an SSL certificate
- On shared hosting with a control panel: in most cases you do nothing. The free certificate is issued automatically once your domain points to the hosting. In cPanel you can check it under *SSL/TLS Status*.
- For a paid certificate: you order it, generate a CSR (certificate signing request) on your server or in the panel, confirm domain ownership (by email, DNS record or a file on the site), and install the issued certificate.
- After installation: redirect all traffic from HTTP to HTTPS so visitors and search engines always use the secure version. Our guide shows how to redirect from HTTP to HTTPS.
Common SSL errors and what they mean
- "Your connection is not private" / NET::ERR_CERT_DATE_INVALID: the certificate has expired. Renew it, or check that automatic renewal works.
- NET::ERR_CERT_COMMON_NAME_INVALID: the certificate was issued for a different name, for example only www.example.com and not example.com.
- Mixed content warning: the page loads over HTTPS, but some images or scripts still load over HTTP. Change those links to HTTPS.
- Certificate not trusted: the intermediate certificate (the chain) is missing on the server. Reinstall the full chain.
Get started with IPHOST
All IPHOST web hosting plans include unlimited free SSL, installed and renewed automatically. If you need a wildcard or an extra certificate, choose one on our SSL certificates page. Not sure what hosting is? Start with What is web hosting?.