HTTPS is HTTP carried inside an encrypted connection set up by TLS (Transport Layer Security). It gives you three things: confidentiality (nobody on the path can read the traffic), integrity (nobody can alter it unnoticed) and authentication (you are talking to the real server for that name). The padlock in the address bar means these checks passed.
The handshake in plain language
Before any web page is sent, the browser and server agree on how to protect the connection. In TLS 1.3 this takes one round trip:
- ClientHello. The browser says which TLS versions and cipher suites it supports, names the site it wants (this is the SNI field) and sends its half of a key exchange.
- ServerHello and certificate. The server picks a cipher suite, sends its half of the key exchange and presents its certificate, together with a signature proving it owns the matching private key.
- Both sides compute the same secret. Using the key exchange (usually elliptic-curve Diffie-Hellman), each side derives the same session keys without the keys ever crossing the network.
- Finished. Each side confirms the handshake was not tampered with. From now on, everything is encrypted with a fast symmetric cipher such as AES-GCM or ChaCha20-Poly1305.
Because new keys are made for every connection, recording the traffic and later stealing the server's long-term key still does not reveal past sessions. This property is called forward secrecy.
Certificates and the chain of trust
A certificate binds a public key to one or more domain names (listed in the Subject Alternative Name field) and is signed by a certificate authority (CA). It also carries a validity period.
Your browser and operating system ship with a list of trusted root CAs. A server normally sends a chain: its own leaf certificate, signed by an intermediate CA, which is signed by a trusted root. The browser checks each signature up the chain, that the name matches, that the dates are valid and that the certificate has not been revoked.
Certificates are being issued for shorter and shorter lifetimes. Under the CA/Browser Forum schedule the maximum is falling in steps (200 days from March 2026, 100 days from 2027 and 47 days from 2029), which makes automated renewal essential. Free CAs such as Let's Encrypt already issue short-lived certificates through automation.
Inspect a site's certificate with the SSL Certificate Checker, or decode one you have in a file with the Certificate Decoder.
What the padlock does not mean
HTTPS proves that the connection is private and that the server controls the certificate for that name. It does not prove the site is honest. Scam and phishing sites use HTTPS too, so check the domain name itself.
Common certificate errors
| Error | Usual cause |
|---|---|
| Certificate expired | Renewal failed or was forgotten |
| Name mismatch | The certificate does not list the name you typed (check the SAN list, and www versus the bare domain) |
| Untrusted issuer | A self-signed certificate, or a CA your device does not trust |
| Incomplete chain | The server forgot to send the intermediate certificate (works on some devices, fails on others) |
| Wrong date on the device | A clock that is far off makes every certificate look expired or not yet valid |
Beyond the certificate
- HSTS (the
Strict-Transport-Securityheader) tells browsers to use HTTPS only for your site; see HTTP Headers Cheat Sheet. - HTTP/3 runs over QUIC, which builds TLS 1.3 into the transport.
- Mixed content, an HTTPS page loading a script or image over plain HTTP, weakens the page and is blocked by browsers.
- Old protocol versions (SSL, TLS 1.0 and 1.1) are broken or deprecated and should be switched off. Grade your configuration with the Security Headers Analyzer.
See also TLS and Digital certificate.