What an SSL certificate does and where to get one

An SSL certificate is a file you install on your web server that encrypts data traveling between your website and the people visiting it. When someone enters their password, credit card number, or personal information on your site, the SSL certificate scrambles that data so only your server can read it.

You obtain an SSL certificate from a Certificate Authority — a company that verifies you own the domain and issues the certificate. Common providers include Let's Encrypt (free), Sectigo, DigiCert, and GoDaddy. Your web hosting company may also sell certificates or offer them included with your plan.

The process takes anywhere from a few minutes (for automated validation) to a few days (if the Certificate Authority needs to verify your business identity). Once installed, your site displays a padlock icon in the browser address bar, and your URL changes from http:// to https://.

Key Takeaways

  • You can obtain a free SSL certificate from Let's Encrypt, or purchase one from providers like Sectigo, DigiCert, or your hosting company.
  • The Certificate Authority must verify you own the domain, usually by checking a DNS record or email confirmation within 24 to 48 hours.
  • Installation happens on your web server, not on your computer — your hosting provider's control panel typically has a built-in tool to install it.
  • Most certificates last one year and must be renewed; Let's Encrypt certificates renew automatically if you set up renewal before expiration.
  • A basic Domain Validation certificate protects data in transit; Business Validation or Extended Validation certificates add verification steps if you need higher trust signals.

Choosing between free and paid certificates

Let's Encrypt offers free SSL certificates and is trusted by all major browsers. The trade-off is that it only performs Domain Validation — it confirms you own the domain but does not verify your business identity. For most websites, blogs, and small businesses, this is sufficient. The certificate renews automatically if you configure it correctly, so you do not have to remember to reissue it each year.

Paid certificates from providers like Sectigo, DigiCert, or Comodo add Business Validation or Extended Validation. These involve the Certificate Authority calling your business phone number or checking public records to confirm you are a legitimate organization. Browsers display additional trust signals — sometimes a green bar or your company name in the address bar — which can matter if you handle sensitive transactions or want to signal credibility to visitors. Paid certificates typically cost between $50 and $300 per year, depending on the level of validation and the provider.

If your hosting company includes an SSL certificate in your plan, it is usually a basic Domain Validation certificate from Let's Encrypt or a partner provider. Check your hosting control panel or contact support to see what is already available to you before purchasing separately.

How to request and validate a certificate

The process differs slightly depending on your provider, but the general steps are the same. First, you generate a Certificate Signing Request (CSR) on your web server — this is a file containing information about your domain and organization. Your hosting provider's control panel usually has a tool to generate this automatically; if not, your hosting support team can do it for you.

You then submit the CSR to the Certificate Authority (or use their web form to provide your domain name). The Certificate Authority sends you a validation challenge, which usually takes one of three forms:

  1. Email validation: You receive an email at an address associated with your domain (like admin@yourdomain.com) and click a link to confirm you own it. This is the fastest method and typically completes within minutes.
  2. DNS validation: You add a temporary DNS record to your domain's DNS settings. The Certificate Authority checks for this record to confirm ownership. This takes a few minutes to set up but can take 24 to 48 hours for DNS changes to propagate across the internet.
  3. HTTP validation: You upload a small file to your web server at a specific path. The Certificate Authority downloads the file to confirm you control the server. This also takes a few minutes.

Once validation is complete, the Certificate Authority issues your certificate. You then install it on your web server using your hosting control panel or by providing the certificate file to your hosting support team. Most hosting companies automate this step entirely — you request the certificate in the control panel, validate it, and it installs automatically.

Installing the certificate on your server

If your hosting company provides a control panel (like cPanel, Plesk, or a custom dashboard), SSL installation is usually a single-click process. You navigate to the SSL/TLS section, select your domain, and choose to install the certificate you just received. The control panel handles the technical work of placing the certificate files in the correct location and configuring your web server.

If you manage your own server or use a hosting provider without a built-in tool, you will need to manually place the certificate files (usually named something like certificate.crt and private.key) in the correct directory and update your web server configuration file. For Apache servers, this means editing the httpd.conf or ssl.conf file. For Nginx, you edit nginx.conf. Your Certificate Authority provides detailed instructions for your specific server type.

After installation, restart your web server to load the new certificate. Test it by visiting your site in a browser — you should see the padlock icon next to your URL. If you see a warning about an untrusted certificate, the certificate file may not be installed correctly, or the domain name in the certificate may not match your actual domain. Contact your hosting support or the Certificate Authority's support team to troubleshoot.

Renewing your certificate before it expires

SSL certificates expire — typically after one year, though some providers offer two or three-year terms. If your certificate expires, browsers will display a warning when visitors try to access your site, and data will no longer be encrypted.

Let's Encrypt certificates renew automatically if you have configured automatic renewal on your server. Most hosting companies that use Let's Encrypt handle this behind the scenes, so you do not need to do anything. Check your hosting control panel 30 days before expiration to confirm the renewal is scheduled.

Paid certificates require manual renewal. Your Certificate Authority sends you an email reminder 30 to 60 days before expiration. You log into your account with the provider, purchase a renewal, and follow the same validation and installation steps as the original certificate. Some providers offer multi-year certificates to reduce the frequency of renewals, though the upfront cost is higher.

Set a calendar reminder for 60 days before your certificate expires, even if your provider sends one. If renewal fails for any reason — an email goes to spam, your account password is forgotten, or validation is delayed — you have time to contact support and resolve it before your site goes down.

Wildcard and multi-domain certificates

A standard SSL certificate protects a single domain — for example, www.example.com. If you run multiple subdomains or related domains, you have two options.

A wildcard certificate protects a domain and all of its subdomains with a single certificate. For example, a wildcard certificate for *.example.com covers www.example.com, blog.example.com, shop.example.com, and any other subdomain you create. Wildcard certificates cost more than single-domain certificates — typically $50 to $150 per year from paid providers — but Let's Encrypt offers free wildcard certificates as well.

A multi-domain certificate (also called a SAN certificate) protects multiple unrelated domains with one certificate. For example, you could protect example.com, example.net, and myshop.com all with a single certificate. These are useful if you own several small websites but want to manage one certificate instead of many. Multi-domain certificates from paid providers typically cost $100 to $300 per year depending on how many domains you include.

For most small websites and blogs, a standard single-domain certificate is sufficient. Use a wildcard certificate if you have many subdomains, or a multi-domain certificate if you own several separate websites.

Troubleshooting common certificate problems

If your browser shows a warning that the certificate is untrusted or expired, first check that your certificate is actually installed. Log into your hosting control panel and navigate to the SSL section — it should show your certificate as active and display the expiration date. If it shows no certificate, or an old one, the installation did not complete. Contact your hosting support to reinstall it.

If the certificate is installed but the browser still warns that the domain does not match, the certificate was issued for a different domain than the one you are visiting. This happens if you requested a certificate for example.com but your site is accessed via www.example.com, or if you moved your site to a new domain without requesting a new certificate. Request a new certificate for the correct domain and install it.

If your certificate expired, you have a short window to renew it before browsers block access entirely. Renew immediately through your Certificate Authority's website or your hosting control panel. Renewal is faster than the initial issuance because the Certificate Authority already has your information on file. Once renewed and installed, clear your browser cache and try again — sometimes browsers cache the old expired certificate.

If you cannot remember which Certificate Authority issued your certificate, visit your domain in a browser, click the padlock icon, and select "Certificate" or "Connection is secure" to view the certificate details. The issuer name is listed there. You can then log into that provider's website using your domain name or email address to manage renewal or reinstallation.

Frequently Asked Questions

Do I need an SSL certificate if my site does not collect passwords or payment information?

Not strictly, but it is still recommended. Google's search algorithm favors sites with SSL certificates, and visitors increasingly expect the padlock icon even on informational sites. A free Let's Encrypt certificate takes a few minutes to set up and has no downside, so most websites use one regardless of whether they collect sensitive data.

Can I move an SSL certificate to a different domain or hosting provider?

No. An SSL certificate is tied to the specific domain it was issued for and cannot be transferred. If you move your site to a new domain or new hosting provider, you must request a new certificate for the new domain. Let's Encrypt and most paid providers allow you to request a new certificate immediately at no additional cost (for Let's Encrypt) or for a renewal fee (for paid providers).

What happens if my SSL certificate expires?

Browsers will display a warning that the connection is not secure, and many visitors will not proceed to your site. Your data is no longer encrypted. Renew your certificate immediately through your Certificate Authority or hosting control panel. Renewal typically takes a few minutes to a few hours, depending on validation method.

Is a free SSL certificate as secure as a paid one?

Yes, in terms of encryption strength. Let's Encrypt certificates use the same encryption technology as paid certificates and are trusted by all major browsers. The difference is in validation level and trust signals. A paid Business Validation certificate adds verification that you are a legitimate organization, which some visitors may find reassuring, but the encryption itself is equally strong.

Can I use the same certificate on multiple servers?

Not with a standard certificate. Each server needs its own copy of the certificate files, but they all reference the same certificate issued for your domain. If you have multiple servers behind a load balancer, you install the same certificate on each one. If you have multiple unrelated servers, you need separate certificates for each domain.