هذا المحتوى متاح حاليًا باللغة الإنجليزية فقط.
What does a certificate do?
What we call “SSL” today is really the TLS protocol. When your browser connects to a site, the server presents a certificate; the browser checks that a trusted authority issued it for that host name, then sets up an encrypted channel.
- Confidentiality: Someone on the same network (say, café Wi-Fi) can't read passwords or session cookies.
- Integrity: A device in the middle can't inject malicious code into the page.
- Identity: The server you reach really belongs to that domain.
How certificates cause trouble
| Problem | Result | Prevention |
|---|---|---|
| Expired certificate | Full-screen browser warning, broken API integrations | Automatic renewal and expiry monitoring |
| Missing intermediate | Errors on some devices and browsers | Serve the full chain from the server |
| Wrong host name | “Your connection is not private” warning | Plan SANs to cover every subdomain |
| Legacy TLS versions | Downgrade risk, compliance findings | Disable TLS 1.0/1.1, enable 1.2 and 1.3 |
A certificate alone isn't enough
Even with a valid certificate, if visitors make their first connection over plain HTTP, an attacker can intercept that first request. Three complementary settings are needed:
- 01
HTTP → HTTPS redirect
Every HTTP request should be moved to HTTPS with a permanent redirect.
- 02
HSTS
The Strict-Transport-Security header tells the browser to use HTTPS only.
- 03
Clean up mixed content
No scripts, styles or images should load over HTTP on an HTTPS page.
Check your own site
The SSL Checker shows your certificate's validity, chain, expiry date and TLS versions. The Website Security Scanner adds redirect, HSTS and mixed content checks.
At enterprise scale
For organizations managing hundreds of domains and certificates, the real risk is the assets nobody sees. Our Attack Surface Management service continuously tracks forgotten certificates and subdomains.



