What an SSL certificate does and where to get one

An SSL certificate is a file that encrypts the connection between a visitor's browser and your web server. When someone visits your site, their browser checks that certificate to confirm they are actually talking to your server, not an imposter. Without one, browsers show a "not secure" warning and visitors see your site as potentially dangerous — even if it is not.

You obtain an SSL certificate from a Certificate Authority (CA) — a company that verifies your identity and issues the certificate. The most common CAs are Let's Encrypt (free), Sectigo, DigiCert, and GoDaddy. Your web hosting provider may offer certificates directly, or you can buy from a CA independently. The process takes anywhere from minutes (for automated validation) to a few days (if the CA needs to verify your business details by phone or email).

The certificate itself is just a text file with encrypted data. Your hosting provider or server administrator installs it on your web server, and then your site automatically uses it for all visitor connections. Visitors do not need to do anything — the encryption happens automatically in the background.

Key Takeaways

  • SSL certificates come from Certificate Authorities like Let's Encrypt, Sectigo, or DigiCert, and many hosting providers offer them as part of your account.
  • Free certificates from Let's Encrypt work as well as paid ones for encryption, but paid certificates often include extra features like business verification and higher coverage limits.
  • The validation process ranges from instant (domain validation) to several days (business validation), depending on how thoroughly the CA verifies your identity.
  • Once installed, an SSL certificate requires renewal before it expires — most last one year, though some paid certificates last longer.
  • Your hosting provider's control panel usually handles installation and renewal automatically, so you may not need to do anything after purchase.

Three types of SSL certificates and what they cover

A Domain Validated (DV) certificate verifies only that you control the domain name. The CA sends you an email or asks you to add a text file to your domain, you confirm it, and the certificate is issued within minutes to hours. DV certificates are the cheapest option (often free from Let's Encrypt) and work for any website that does not need to prove the business behind it. Most small blogs, portfolios, and personal sites use DV certificates.

An Organization Validated (OV) certificate verifies that you own or represent a real business. The CA checks your business registration, calls your phone number, and may ask for documents. This takes several days. OV certificates show your business name in the certificate details, which builds trust for customer-facing sites like small e-commerce shops or service providers. They cost more than DV but less than the highest tier.

An Extended Validation (EV) certificate is the most thorough. The CA verifies your legal business identity, ownership, and operational status — similar to a background check. This takes a week or more. EV certificates used to show a green bar in the browser address bar, though most modern browsers have removed that visual indicator. They are mainly used by large financial institutions, payment processors, and major retailers. They are the most expensive option and rarely needed for small websites.

For most websites, a free DV certificate from Let's Encrypt is sufficient. If you run an online store or handle sensitive customer information, an OV certificate may be worth the cost to show visitors your business is verified.

How to obtain a certificate through your hosting provider

The easiest route is through your web hosting provider's control panel. Most providers (GoDaddy, Bluehost, SiteGround, Namecheap, and others) offer SSL certificates directly in their dashboard. Log into your hosting account, look for a section called "SSL Certificates", "Security", or "HTTPS", and you will usually see options to install a free certificate or purchase a paid one.

If your provider offers free SSL (many do, especially with newer hosting plans), click the button to install it. The system will validate your domain automatically — usually by checking that you own the domain through your registrar records. Installation takes minutes to a few hours. Your site will then use HTTPS automatically for all connections.

If you want a paid certificate with more features, your provider's dashboard will show pricing and options. You select the certificate type (DV, OV, or EV), complete any required verification steps, and the provider installs it on your server. Most hosting providers handle renewal automatically, so the certificate renews before it expires without you having to do anything.

Check your hosting provider's documentation or contact their support team if you cannot find the SSL section. Many providers have step-by-step guides specific to their control panel.

Obtaining a certificate directly from a Certificate Authority

If your hosting provider does not offer SSL or you want more control, you can buy directly from a CA. Let's Encrypt is free and automated — you use software called Certbot on your server to request and install certificates. Certbot is command-line based, so it requires some technical comfort, but many hosting providers now offer one-click Certbot installation in their control panels.

Paid CAs like Sectigo, DigiCert, and Comodo have websites where you can purchase certificates directly. You select the certificate type, enter your domain name, and complete the validation process on their site. They then provide you with certificate files that you (or your server administrator) install on your web server. This route requires more technical knowledge because you are handling the installation yourself rather than using a hosting provider's automated system.

If you go this route, you will also need to renew the certificate manually before it expires. Most CAs send reminder emails, but the responsibility falls on you. Some CAs offer auto-renewal features for an additional fee, which handles renewal automatically.

Validation methods and how long each takes

The CA validates your identity using one of three methods. Domain validation is the fastest — the CA sends you an email at an address associated with your domain, or asks you to add a text file to your domain. You confirm, and the certificate is issued within minutes to a few hours. This is what Let's Encrypt uses.

Email validation is similar but slightly slower. The CA emails an administrator address for your domain (like admin@yourdomain.com) with a link to click. You click it, and the certificate is issued. This usually takes a few hours to a day.

Phone or document validation is used for OV and EV certificates. The CA calls your business phone number or asks for documents like a business license or utility bill. This is the slowest method and can take several days to a week, depending on how quickly you respond and how busy the CA is.

If you need a certificate quickly, choose a DV certificate with domain validation. If you need business verification, plan for several days and have your business documents ready.

Installing the certificate on your server

If your hosting provider handles installation (which most do), you do not need to do anything after purchase. The provider's system installs the certificate automatically on your web server, and your site starts using HTTPS immediately.

If you are installing the certificate yourself, the process depends on your server type. For Apache servers, you typically place the certificate files in a specific directory and update your server configuration file to point to them. For Nginx, the process is similar but the configuration syntax differs. For Windows servers running IIS, you import the certificate through the IIS management console.

Most CAs provide installation instructions for common server types. If you are not comfortable with server configuration, ask your hosting provider's support team to install it for you — many will do this at no extra cost, even if you bought the certificate elsewhere.

After installation, test your site by visiting it in a browser and looking for the padlock icon in the address bar. The padlock means the connection is encrypted. If you see a warning instead, the certificate may not be installed correctly — check your server configuration or contact your hosting provider.

Renewal and expiration

SSL certificates expire and must be renewed before that date. Most certificates last one year, though some paid certificates last two or three years. When your certificate is close to expiration, the CA sends reminder emails to the address you provided during purchase.

If your hosting provider manages your certificate, renewal usually happens automatically. You do not need to do anything — the provider renews it before expiration and installs the new one on your server. Check your hosting provider's documentation to confirm they handle auto-renewal.

If you manage the certificate yourself, you must renew it manually before expiration. Let's Encrypt certificates can be renewed automatically using Certbot. For paid certificates from other CAs, you typically log into your account on their website, request renewal, complete validation again, and install the new certificate files on your server.

If a certificate expires and you do not renew it, your site will show a security warning to visitors, and browsers may block access entirely. Set a calendar reminder for 30 days before expiration if you are managing renewal yourself.

Frequently Asked Questions

Do I need an SSL certificate if my site does not handle payments or logins?

Not strictly, but you should have one anyway. Browsers now show "not secure" warnings for any site without HTTPS, which makes visitors distrust your site even if it is harmless. Search engines also rank sites with HTTPS higher than those without. A free certificate from Let's Encrypt takes minutes to install and solves both problems.

What is the difference between a certificate for one domain and a wildcard certificate?

A standard certificate covers one domain name, like example.com. A wildcard certificate covers that domain plus all subdomains, like blog.example.com, shop.example.com, and api.example.com. Wildcard certificates cost more and are useful only if you run multiple subdomains. For most websites, a standard certificate is enough.

Can I move an SSL certificate from one hosting provider to another?

It depends on the certificate type. Free certificates from Let's Encrypt can be moved because they are not tied to a specific provider — you just request a new one on your new server. Paid certificates from other CAs are usually tied to a specific domain and server, so you cannot transfer them. You would need to purchase a new certificate for your new hosting account, though many CAs offer refunds if you have not used the certificate for long.

What happens if my SSL certificate is compromised or hacked?

If you suspect your certificate's private key has been exposed, contact your CA immediately and request revocation. The CA will invalidate the certificate, and you can request a new one. Most CAs issue replacement certificates free if the original was compromised. Revocation takes a few hours to propagate, so visitors may still see warnings briefly.

Do I need a separate certificate for www.example.com and example.com?

No. Most CAs automatically cover both the domain and the www version in a single certificate. When you request a certificate for example.com, it covers www.example.com as well. Check with your CA to confirm, but this is the standard practice.