HTTPS is ordinary web traffic (HTTP) sent inside an encrypted connection made with TLS. It does two jobs: it keeps what you send and receive private, and it proves you are talking to the real site rather than an impostor.
HTTPS is HTTP sent inside an encrypted TLS connection. Before any page is sent, the browser checks the site’s certificate to confirm it is talking to the real domain, then both sides agree on keys that encrypt everything that follows. The result: nobody in between can read or change the traffic.
The padlock means
- Encrypted: nobody between you and the site, such as public Wi-Fi or an internet provider, can read or change the traffic.
- Authenticated: the site showed a certificate, for this exact domain, signed by a certificate authority your browser trusts.
It does not mean the site is honest or safe. Scam sites can have valid certificates too.
What a certificate is
A small file that says “this public key belongs to example.com“, signed by a certificate authority (CA) such as Let’s Encrypt. Browsers and operating systems ship with a list of trusted CAs. If the signature checks out, the domain matches and the date is valid, the browser trusts the connection. If any of those fail, you see a “not private” warning.
The handshake, simply
- Your browser connects and lists the encryption methods it supports.
- The server picks one and sends its certificate.
- The browser checks the certificate.
- Both sides use key exchange to agree on fresh session keys that never travel over the network.
- Everything after that is encrypted with those keys.
With modern TLS 1.3 this takes a single round trip, so HTTPS adds very little delay.
Public and private keys
HTTPS relies on a pair of keys. The private key stays secret on the server; the public key is published inside the certificate. Data signed with the private key can be checked by anyone with the public key, which is how the server proves it really owns the certificate. In TLS 1.3, the two sides then agree session keys with a method (ephemeral Diffie-Hellman) that keeps past sessions safe even if the private key is stolen later. This property is called forward secrecy.
The private key is the one thing that must never leak. On a server with Certbot it is privkey.pem, readable only by root.
The chain of trust
Browsers do not trust your certificate directly. They trust a short list of root certificate authorities built into the operating system or browser. Roots sign intermediate certificates, and intermediates sign yours:
ISRG Root X1 (root, trusted by your device)
└── R11 (intermediate)
└── example.com (your certificate)
Your server must send its certificate and the intermediate. Sending only its own certificate breaks the chain on many devices; that is why Nginx should use fullchain.pem. See the full chain for any site with:
openssl s_client -connect example.com:443 -servername example.com -showcerts </dev/null
Types of certificate
| Type | Checks | Shown to visitors as | Cost |
|---|---|---|---|
| Domain validated (DV) | You control the domain | Padlock | Free (Let’s Encrypt) or paid |
| Organisation validated (OV) | Also, the organisation exists | Padlock; details in the certificate | Paid |
| Extended validation (EV) | Stricter organisation checks | Padlock; browsers no longer show a green bar | Paid |
Browsers show the same padlock for all three, and the encryption is identical. For almost every website, a free DV certificate is the right choice.
HSTS: making browsers insist on HTTPS
Even with a redirect from HTTP to HTTPS, a visitor’s very first request may go over plain HTTP. HTTP Strict Transport Security tells browsers to always use HTTPS for your domain, for a set time:
add_header Strict-Transport-Security "max-age=31536000" always;
Only add it once HTTPS works everywhere on the domain. While the header is cached, browsers refuse to load the site over HTTP at all, even if your certificate breaks. Add includeSubDomains only if every subdomain has HTTPS too.
Why every site should use it
- Browsers mark plain HTTP pages as “Not secure”.
- Many modern browser features only work over HTTPS.
- Certificates are free. See Let’s Encrypt.
Mixed content
A page loaded over HTTPS that includes images, scripts or styles over http:// is mixed content. Browsers block insecure scripts outright and may show a warning or a broken padlock for images. After moving a site to HTTPS, search the content and theme for http:// links to your own domain and change them to https://. On WordPress:
wp search-replace 'http://example.com' 'https://example.com' --skip-columns=guid --dry-run
The browser’s developer console lists every mixed-content file on a page.
SSL or TLS?
SSL is the old name. Every version of SSL is long retired, and today’s connections use TLS 1.2 or 1.3. People still say “SSL certificate” out of habit; it means the same thing.
Related
Something out of date? Software changes. If a step no longer works, tell us and we will check it and update the page.



