What a digital certificate does
A digital certificate is a file that proves who you are on the internet. It works like an ID card for your computer or website — it contains your identity information and a digital signature from a trusted authority that says "yes, this person is who they claim to be." When you visit a secure website or send an encrypted message, the certificate is what allows the other side to trust that you are real.
The certificate itself is just data — a collection of numbers and text that your browser or email program can read. It includes your name (or your organization's name), the date it was issued, when it expires, and a unique code called a public key that other people use to send you encrypted messages. It also includes a signature from the authority that issued it, proving the certificate has not been tampered with.
You do not usually see the certificate working. Your browser checks it automatically when you land on a website with "https://" in the address bar. If the certificate is valid and matches the website's domain, you see a padlock icon. If something is wrong — the certificate expired, or it belongs to a different website — your browser warns you before you go further.
Key Takeaways
- A digital certificate is a file that proves your identity or a website's identity, issued by a trusted authority called a certificate authority.
- Certificates contain your public key, which other people use to send you encrypted messages that only you can read with your private key.
- Your browser automatically checks website certificates and shows a padlock icon when the connection is secure and the certificate is valid.
- Certificates expire and must be renewed, which is why websites sometimes show security warnings even though they are legitimate.
- Personal certificates for email and document signing work the same way as website certificates but prove your identity instead of a website's.
How certificates prove identity
A certificate proves identity through a chain of trust. A certificate authority (CA) is an organization that has been trusted by your browser or operating system to issue certificates. When you request a certificate, the CA checks that you are who you say you are — they might ask for government ID, business registration, or proof of domain ownership. Once they verify you, they issue a certificate with their digital signature attached.
Your browser comes pre-loaded with a list of CAs it trusts. When you visit a website, your browser checks whether the website's certificate was signed by one of those trusted CAs. If it was, the browser trusts the certificate. If the signature does not match, or if the CA is not on the trusted list, the browser shows a warning. This prevents someone from creating a fake certificate and pretending to be a bank or email service.
The signature itself is created using the CA's private key — a secret number that only the CA has. Your browser uses the CA's public key (which is public and widely known) to verify that the signature is real. If the signature checks out, you know the certificate came from the CA and has not been changed since it was issued.
The difference between public and private keys
Every digital certificate comes with two related keys: a public key and a private key. The public key is part of the certificate and is shared with everyone. The private key is secret and stays only with you. Together, they make encryption work.
When someone wants to send you an encrypted message, they use your public key to scramble it. Only your private key can unscramble it — no one else has that key, so no one else can read the message. This is why your private key must stay private. If someone gets your private key, they can read all your encrypted messages and impersonate you.
The same pair of keys also works in reverse for digital signatures. You use your private key to sign a document or email, proving it came from you. Other people use your public key to verify the signature. If the signature checks out, they know the document came from you and has not been changed.
Where you encounter digital certificates
You encounter certificates every time you visit a website that starts with "https://" — that "s" means the connection is encrypted using a certificate. Banks, email services, shopping sites, and social media all use certificates to protect your data in transit. The certificate proves the website is legitimate and encrypts everything you send so that hackers on the same network cannot read it.
Email certificates work the same way but for messages. If someone sends you an email with a digital signature, their certificate proves the email came from them and has not been altered. Some organizations require employees to sign emails with certificates. You can also use a certificate to encrypt email so that only the intended recipient can read it.
Document signing certificates are used to sign PDFs, contracts, and other files. When you sign a document with a certificate, you are proving you created or approved it and that it has not been changed since you signed it. Government agencies, banks, and law firms often require documents to be signed this way instead of with a handwritten signature.
When certificates expire and what happens
Every certificate has an expiration date, usually one to three years from when it was issued. When a certificate expires, it is no longer valid. Your browser will show a security warning if you try to visit a website with an expired certificate, even if the website is legitimate and the certificate was real when it was issued.
Website owners must renew their certificates before they expire. Most CAs send reminders as the expiration date approaches. If a website owner forgets to renew, visitors see a warning like "Your connection is not private" or "Certificate has expired." This does not mean the website is unsafe — it just means the owner did not renew on time. The website is still encrypted, but your browser cannot verify it is legitimate.
Certificates expire for security reasons. If a private key is stolen, the certificate authority can revoke the certificate so it is no longer trusted. Expiration dates force regular renewal, which gives the CA a chance to re-verify the owner's identity and check that the private key has not been compromised. It also means old, forgotten certificates do not stay valid forever.
Self-signed certificates and why they show warnings
A self-signed certificate is one that you sign yourself instead of having a certificate authority sign it. You can create one for testing or for internal use within a company. Your browser does not recognize self-signed certificates as trustworthy because they are not signed by a CA on the trusted list.
When you visit a website with a self-signed certificate, your browser shows a warning like "This site's security certificate is not trusted." This does not mean the connection is unencrypted — it is still encrypted. It just means your browser cannot verify that the website is who it claims to be. Someone could create a self-signed certificate and pretend to be your bank, and your browser would have no way to know the difference.
Self-signed certificates are fine for internal company networks or for testing during development. They should never be used on public websites where strangers might visit. If you see a self-signed certificate warning on a website you do not recognize, it is safer to leave the site.
How to check a website's certificate
Most browsers let you click the padlock icon in the address bar to see details about a website's certificate. In Chrome, click the padlock and then click "Certificate is valid." In Firefox, click the padlock, then the arrow next to "Connection secure," then "More information," then "View Certificate." You will see the certificate's details: the domain it belongs to, who issued it, when it expires, and the public key.
Check that the domain in the certificate matches the website you are visiting. If you are on amazon.com but the certificate says it belongs to amazom.com (note the typo), something is wrong — do not enter any passwords or payment information. Also check the expiration date. If it has already passed, the certificate is expired and the website owner should have renewed it.
You can also see the certificate chain — the list of CAs that signed the certificate. At the top is the root certificate authority, which is built into your browser. Below that are intermediate CAs that the root authority trusts. If any link in the chain is broken or untrusted, your browser will warn you.
Frequently Asked Questions
What happens if a website's certificate is stolen?
The certificate authority can revoke the certificate, which adds it to a blacklist that browsers check. Browsers will then show a warning even though the certificate looks valid. The website owner must request a new certificate from the CA. In the meantime, visitors cannot access the site securely.
Can I get a digital certificate for myself?
Yes. You can request a personal certificate from a certificate authority for email signing or document signing. Some CAs issue them for free, while others charge a fee. You will need to provide proof of identity. Once you have it, you can import it into your email program or document software.
Why do some websites still use http instead of https?
Websites that do not handle sensitive information sometimes skip the cost and complexity of getting a certificate. However, modern browsers now show a "Not Secure" warning for http sites, which discourages their use. If a website asks for your password or payment information, it should always use https.
What is the difference between a certificate and a password?
A password is something you know and type in. A certificate is a file that proves who you are without you having to type anything. Certificates are harder to steal because they are not transmitted over the network — only the public key is shared. Passwords can be guessed or cracked if they are weak.
Do I need to do anything to use digital certificates?
For website certificates, no — your browser handles everything automatically. For email or document signing, you may need to install a personal certificate in your email program or document software. Once installed, you can sign emails or documents with a single click.