HTTPS and Certificates Explained for People Who Just Run a Website
By ABD Web Tools Editorial · 2026-02-14 · 7 min read
Most site owners meet TLS twice: once when they set it up, and once when something breaks and browsers start showing full-page warnings. Understanding roughly what a certificate is and is not makes both moments much shorter.
What a certificate actually proves
A TLS certificate binds a hostname to a public key, signed by an authority the browser already trusts. When your site presents it, the browser checks three things: that the signature chain leads to a trusted root, that the certificate has not expired, and that the hostname in the certificate matches the address in the bar.
That is the whole guarantee. It says the connection is encrypted and you are talking to the host you asked for. It says nothing about whether the site is honest, well built or safe to buy from.
The certificate types, plainly
Domain Validated certificates prove control of the domain and are issued in seconds, usually free. Organisation and Extended Validation certificates additionally verify a legal entity, cost money and take days. Browsers no longer display those differences prominently, so for most sites a free DV certificate delivers the same practical security.
Advertisement
Renewal is the part that breaks
Modern certificates are short-lived by design, so automated renewal is not optional. Almost every outage of this kind traces to one of a handful of causes.
- The renewal cron job stopped running after a server rebuild.
- The validation path was blocked by a redirect or firewall rule.
- The certificate renewed but the service was never reloaded.
- A new subdomain was added and left off the certificate.
- A CAA record blocks the authority the automation uses.
Reading the common browser warnings
'Certificate expired' means renewal failed — check the automation and reload the service. 'Name mismatch' means you are serving a certificate for a different hostname, often www versus apex. 'Incomplete chain' means intermediates are missing; desktop browsers may forgive it while mobile clients and API consumers do not. 'Mixed content' is not a certificate fault at all — the page is HTTPS but pulls a script or image over HTTP.
A sane baseline configuration
Redirect all HTTP traffic to HTTPS with a permanent redirect, serve the full chain, enable HSTS once you are confident every subdomain is covered, disable protocol versions below TLS 1.2, and set a CAA record naming your authority. Then add an expiry monitor that alerts you two weeks before the date, because automation fails silently more often than it fails loudly.
Frequently asked questions
Are free certificates less secure?
No. The encryption is identical. Paid certificates differ in validation depth, warranty and support, not in cryptographic strength.
Does HTTPS affect SEO?
It is a light ranking signal, but the bigger effect is user trust: browsers mark plain HTTP pages as not secure, which suppresses conversions.
What is HSTS and should I enable it?
It tells browsers to only ever use HTTPS for your domain. Enable it after confirming every subdomain has a valid certificate, since the policy is cached and hard to reverse quickly.
Why does my site work on desktop but warn on mobile?
Usually a missing intermediate certificate. Desktop browsers often fetch it automatically; many mobile and API clients do not.
Advertisement