Skip to content

What is SSL/TLS?

Web Development, explained by the engineers who build it. Definition, how it works, use cases and common questions.

SSL/TLS definition

SSL/TLS is the family of cryptographic protocols that secures data sent over a network, most visibly as the S in HTTPS. TLS (Transport Layer Security) replaced the older, now insecure SSL (Secure Sockets Layer), but the names are still used interchangeably. TLS encrypts traffic, verifies the server's identity with a certificate and detects any tampering.

How does TLS work?

When a browser connects to an HTTPS site, it starts a TLS handshake. The two sides agree on a protocol version and cipher suite, the server presents its certificate, and they use key exchange, typically elliptic-curve Diffie-Hellman, now often combined with post-quantum ML-KEM in a hybrid exchange by current browsers, to create shared session keys without ever sending those keys over the network. From then on, every byte is encrypted with fast symmetric ciphers such as AES-GCM or ChaCha20, and each message carries an authentication tag that reveals tampering.

TLS 1.3 shortened the handshake to a single round trip and removed weak algorithms that caused problems in earlier versions. That makes modern HTTPS both safer and faster than many people assume; encryption overhead is rarely a meaningful cost for a web application today. See encryption for the underlying concepts of symmetric and public-key cryptography.

Certificates and certificate authorities

A TLS certificate binds a domain name to a public key and is signed by a certificate authority (CA) that browsers and operating systems trust. The browser checks the signature chain, the domain name, the validity dates and whether the certificate has been revoked. If any check fails, users see a full-page warning, which is why an expired certificate can take a business offline as effectively as a server outage.

Certificates come in three validation levels: domain validated (DV), organization validated (OV) and extended validation (EV). Browsers treat them the same for encryption, so DV certificates from free, automated CAs such as Let's Encrypt are now the norm. Automation through the ACME protocol, built into most CDNs, load balancers and hosting platforms, removes renewal risk almost entirely, and it is becoming essential: under CA/Browser Forum rules, the maximum lifetime of public certificates fell to 200 days in March 2026 and will shrink to 47 days by 2029.

SSL vs TLS

SSL was developed by Netscape in the 1990s. Every SSL version is now broken and disabled in modern software, and TLS 1.0 and 1.1 are deprecated as well. What people buy as an SSL certificate is really a TLS certificate: the certificate format is the same, only the protocol that uses it has changed. Servers should offer TLS 1.2 and TLS 1.3 only, and the term SSL survives mainly in product names and habit.

For most teams the practical point is simple: whatever terminates TLS, whether a CDN, load balancer or the application server, must be configured and monitored, and traffic between that point and your servers should also be encrypted rather than left as plain HTTP inside the network.

Configuring TLS securely

Most TLS problems come from configuration rather than cryptography. A sound setup for a public website or API covers the points below, and free scanners such as SSL Labs grade a public endpoint in a couple of minutes:

  • Enable TLS 1.2 and 1.3 only, with modern cipher suites
  • Automate certificate issuance and renewal, and alert well before expiry
  • Redirect HTTP to HTTPS and send an HSTS header
  • Use CAA DNS records to limit which CAs may issue certificates for your domain
  • Encrypt internal traffic too, using mutual TLS between services where a zero trust model applies
  • Keep private keys in a managed store such as a cloud key management service

SSL/TLS: common questions

Something else on your mind? Ask a consultant and get a reply within one business day.

Is SSL the same as TLS?

Not exactly. TLS is the successor to SSL and is the protocol actually used today, since every SSL version is insecure and disabled. The names persist out of habit, so an SSL certificate, an SSL connection and HTTPS all refer to TLS in practice, and nobody needs to buy anything labeled TLS separately.

Do I need to pay for an SSL certificate?

Usually not. Domain-validated certificates from Let's Encrypt, and those issued automatically by CDNs and cloud load balancers, provide the same encryption as paid ones. Paid certificates make sense for specific needs, such as organization validation for some enterprise or government requirements, or support agreements bundled with them.

What happens when a TLS certificate expires?

Browsers and API clients refuse the connection, showing users a security warning or failing calls outright. For an online store or API that is effectively an outage. Automated renewal through ACME plus monitoring that alerts weeks before expiry prevents it, and should cover internal certificates as well as public ones.

Keep exploring the web development glossary

Need SSL/TLS in your product?

A solutions consultant replies within one business day with next steps, a rough estimate and a suggested team.