Skip to main content
FixMyTech

What Are SSL and TLS, and Why Certificates Expire

By

Published

7 min read

Share

Short answer

TLS is the protocol that encrypts HTTPS connections; SSL is its predecessor, retired years ago but still used as a name out of habit. A certificate ties a domain to a cryptographic key and carries an expiry date, typically under a year, so "certificate expired" almost always means the site forgot to renew rather than anything sinister.

On this page

TLS, or Transport Layer Security, is the protocol that encrypts HTTPS. SSL, Secure Sockets Layer, is what it was called before 1999, and every version of SSL has been broken and removed from browsers.

The name stuck anyway. When a hosting company sells you an “SSL certificate” you are buying a TLS certificate, and the connection it secures runs TLS 1.2 or 1.3. Nobody in the industry finds this confusing any more, which is precisely why nobody has fixed it.

What happens when a connection starts

The handshake takes a few milliseconds and does three jobs.

1. Agree on the rules. Browser and server exchange supported protocol versions and cipher suites, and settle on the strongest both understand. A modern browser and a modern server land on TLS 1.3.

2. Verify identity. The server sends its certificate. The browser checks that the certificate covers the domain being requested, that it has not expired, and that it was issued by an authority the browser trusts.

3. Establish a shared secret. Using public-key cryptography, the two sides derive a session key neither sent across the wire. Everything afterwards is encrypted symmetrically with that key, which is far faster.

TLS 1.3 compressed this into one round trip and removed every cipher with a known weakness, which is why it is both faster and simpler than TLS 1.2 rather than facing the usual security-versus-speed trade.

What a certificate actually contains

A certificate is a signed statement. It says: this domain, this public key, valid between these two dates, vouched for by this authority.

Field What it means
Subject The domain or domains covered
Public key Used to establish the session secret
Valid from / to The window in which browsers accept it
Issuer The certificate authority that signed it
Signature The authority’s cryptographic endorsement

The chain of trust runs from your certificate to an intermediate authority to a root authority whose certificate is built into your operating system or browser. Browsers ship with a few hundred root certificates, and the whole system rests on those roots behaving properly, a dependency that has occasionally gone wrong, and when it has, browsers have removed the offending authority outright.

Validation levels, and why they barely matter now

Type What is checked Issued in
DV, domain validated You control the domain Minutes, usually free
OV, organisation validated Domain plus basic company records Days
EV, extended validation Domain plus deeper legal verification Days to weeks

EV certificates once produced a green bar with the company name in the address bar, and that was the entire commercial case for them. Browsers removed that display, having found it did not change user behaviour and was itself spoofable, since companies with similar registered names in different jurisdictions could obtain confusingly similar bars.

With the visual difference gone, DV covers the overwhelming majority of the web. The encryption is identical in all three cases.

Why “certificate expired” is so common

Every certificate has a hard expiry date, and on the day it passes, every visitor gets a full-page warning. There is no grace period and no degraded mode.

Certificate lifetimes have been cut repeatedly by the browser and certificate authority forum that sets these rules: from five years, to three, to two, to roughly thirteen months, with further reductions agreed. The reasoning is sound: if a private key is stolen, a shorter certificate limits how long the thief can use it, and revocation checking has never worked reliably enough to rely on.

The side effect is that manual renewal stopped being viable. A certificate needing renewal every thirteen months is a calendar reminder somebody will miss. Hence Let’s Encrypt and the ACME protocol, which issue 90-day certificates and renew them automatically. When a large site goes down with an expiry warning, it is almost always because automation that had been working silently broke and nobody was watching the alert.

So the honest reading of an expiry warning: this is an administrative failure, not an attack. Your connection is still encrypted. What is missing is the proof of who you are encrypting to.

Still, do not enter credentials. An expired certificate removes exactly the assurance that stops a man-in-the-middle, and the padlock’s narrow guarantee is the only thing that distinguished the real site from an impostor in the first place.

The other warnings, and what they mean

Name mismatch. The certificate covers example.com but you requested www.example.com, or something genuinely different. Usually a configuration error. Occasionally an impostor.

Issuer not trusted. The certificate chains to a root your device does not have. Three realistic causes: a self-signed certificate, which is normal on router admin pages and internal tools; corporate traffic inspection, where your employer installed its own root so it can decrypt your HTTPS; or interception you did not consent to.

Your clock is wrong. This produces an expiry or not-yet-valid error on every site at once, which is the giveaway. A device whose date is set years out will reject the entire web. Check the clock before anything else when everything breaks simultaneously.

Revoked. The authority withdrew the certificate, typically because the key was compromised. Do not proceed.

Realistic expectations

As a visitor, the only correct response to a certificate warning is to not type anything sensitive. If you were reading an article, proceeding is a low-stakes decision. If you were about to log in, it is not, and the site being otherwise familiar is irrelevant.

As a site owner, automate renewal and monitor it independently. Expiry is the most predictable outage in all of infrastructure — the date is printed in the certificate — and it still takes down significant services several times a year because the renewal job failed quietly in a log nobody read.

If the warning appears on only one device while others are fine, the problem is that device: its clock, its root certificate store, or security software intercepting traffic. If it appears on every device on a network, look at the network.

Frequently asked questions

Is SSL still used anywhere?
Not as a protocol. All SSL versions were found insecure and browsers removed support for them. The word survives in product names like "SSL certificate" and "SSL offloading", where what is actually running is TLS 1.2 or 1.3.
Why do certificates expire so quickly now?
Shorter lifetimes limit the damage if a private key is stolen, since a compromised certificate stops being accepted sooner. The maximum public certificate lifetime has been cut repeatedly, and the industry is continuing to shorten it, which is why automated renewal has become mandatory in practice.
Does a paid certificate encrypt better than a free one?
No. The encryption is identical, because it comes from the protocol, not the certificate. Paid certificates differ in validation depth, warranty terms and support, none of which changes the strength of the connection.
My own site shows "certificate expired". What do I do?
Renew it, which on most hosting is a single button or happens automatically through Let's Encrypt. If renewal is already automated and still failed, the usual cause is a changed DNS record or a blocked validation path that the renewal check depends on.
Can I ignore a certificate warning on my router's admin page?
Usually yes. Home routers ship with self-signed certificates because no public authority can issue one for a private address, so the warning is expected. Only proceed when you typed the router's address yourself and are on your own network.

All Explainers guides