What Are SSL and TLS, and Why Certificates Expire
Short answer
TLS is the protocol that encrypts HTTPS connections; SSL is its predecessor, retired years ago but still used as a name out of habit. A certificate ties a domain to a cryptographic key and carries an expiry date, typically under a year, so "certificate expired" almost always means the site forgot to renew rather than anything sinister.
On this page
TLS, or Transport Layer Security, is the protocol that encrypts HTTPS. SSL, Secure Sockets Layer, is what it was called before 1999, and every version of SSL has been broken and removed from browsers.
The name stuck anyway. When a hosting company sells you an “SSL certificate” you are buying a TLS certificate, and the connection it secures runs TLS 1.2 or 1.3. Nobody in the industry finds this confusing any more, which is precisely why nobody has fixed it.
What happens when a connection starts
The handshake takes a few milliseconds and does three jobs.
1. Agree on the rules. Browser and server exchange supported protocol versions and cipher suites, and settle on the strongest both understand. A modern browser and a modern server land on TLS 1.3.
2. Verify identity. The server sends its certificate. The browser checks that the certificate covers the domain being requested, that it has not expired, and that it was issued by an authority the browser trusts.
3. Establish a shared secret. Using public-key cryptography, the two sides derive a session key neither sent across the wire. Everything afterwards is encrypted symmetrically with that key, which is far faster.
TLS 1.3 compressed this into one round trip and removed every cipher with a known weakness, which is why it is both faster and simpler than TLS 1.2 rather than facing the usual security-versus-speed trade.
What a certificate actually contains
A certificate is a signed statement. It says: this domain, this public key, valid between these two dates, vouched for by this authority.
| Field | What it means |
|---|---|
| Subject | The domain or domains covered |
| Public key | Used to establish the session secret |
| Valid from / to | The window in which browsers accept it |
| Issuer | The certificate authority that signed it |
| Signature | The authority’s cryptographic endorsement |
The chain of trust runs from your certificate to an intermediate authority to a root authority whose certificate is built into your operating system or browser. Browsers ship with a few hundred root certificates, and the whole system rests on those roots behaving properly, a dependency that has occasionally gone wrong, and when it has, browsers have removed the offending authority outright.
Validation levels, and why they barely matter now
| Type | What is checked | Issued in |
|---|---|---|
| DV, domain validated | You control the domain | Minutes, usually free |
| OV, organisation validated | Domain plus basic company records | Days |
| EV, extended validation | Domain plus deeper legal verification | Days to weeks |
EV certificates once produced a green bar with the company name in the address bar, and that was the entire commercial case for them. Browsers removed that display, having found it did not change user behaviour and was itself spoofable, since companies with similar registered names in different jurisdictions could obtain confusingly similar bars.
With the visual difference gone, DV covers the overwhelming majority of the web. The encryption is identical in all three cases.
Why “certificate expired” is so common
Every certificate has a hard expiry date, and on the day it passes, every visitor gets a full-page warning. There is no grace period and no degraded mode.
Certificate lifetimes have been cut repeatedly by the browser and certificate authority forum that sets these rules: from five years, to three, to two, to roughly thirteen months, with further reductions agreed. The reasoning is sound: if a private key is stolen, a shorter certificate limits how long the thief can use it, and revocation checking has never worked reliably enough to rely on.
The side effect is that manual renewal stopped being viable. A certificate needing renewal every thirteen months is a calendar reminder somebody will miss. Hence Let’s Encrypt and the ACME protocol, which issue 90-day certificates and renew them automatically. When a large site goes down with an expiry warning, it is almost always because automation that had been working silently broke and nobody was watching the alert.
So the honest reading of an expiry warning: this is an administrative failure, not an attack. Your connection is still encrypted. What is missing is the proof of who you are encrypting to.
Still, do not enter credentials. An expired certificate removes exactly the assurance that stops a man-in-the-middle, and the padlock’s narrow guarantee is the only thing that distinguished the real site from an impostor in the first place.
The other warnings, and what they mean
Name mismatch. The certificate covers example.com but you requested
www.example.com, or something genuinely different. Usually a configuration
error. Occasionally an impostor.
Issuer not trusted. The certificate chains to a root your device does not have. Three realistic causes: a self-signed certificate, which is normal on router admin pages and internal tools; corporate traffic inspection, where your employer installed its own root so it can decrypt your HTTPS; or interception you did not consent to.
Your clock is wrong. This produces an expiry or not-yet-valid error on every site at once, which is the giveaway. A device whose date is set years out will reject the entire web. Check the clock before anything else when everything breaks simultaneously.
Revoked. The authority withdrew the certificate, typically because the key was compromised. Do not proceed.
Realistic expectations
As a visitor, the only correct response to a certificate warning is to not type anything sensitive. If you were reading an article, proceeding is a low-stakes decision. If you were about to log in, it is not, and the site being otherwise familiar is irrelevant.
As a site owner, automate renewal and monitor it independently. Expiry is the most predictable outage in all of infrastructure — the date is printed in the certificate — and it still takes down significant services several times a year because the renewal job failed quietly in a log nobody read.
If the warning appears on only one device while others are fine, the problem is that device: its clock, its root certificate store, or security software intercepting traffic. If it appears on every device on a network, look at the network.