An Expert Guide to SSL Certificates and Website Security

An Expert Guide to SSL Certificates and Website Security

By Michael Turner

December 17, 2024 at 03:09 AM

SSL certificates automatically enhance your website's security by creating encrypted connections between browsers and servers. This protection prevents unauthorized access to sensitive information and builds trust with visitors.

Key Points About SSL Certificates:

  • Automatically included with all Squarespace domains and connected third-party domains
  • Protects subdomains and integrated domains
  • Uses 2048-bit encryption (128-bit for checkout pages)
  • Updates every 90 days through Let's Encrypt
  • Requires domains to have 63 characters or fewer

SSL Settings Options:

  1. Secure (Recommended):
  • Forces HTTPS redirects
  • Includes HTTPS links in sitemaps
  • Improves SEO through HTTPS indexing
  • Won't load on browsers without SSL support
  1. Secure HSTS:
  • Provides additional security layer
  • Prevents spoofing attempts
  • Eliminates "connection not private" errors
  • Recommended to use with Secure setting
  1. Insecure:
  • Allows both HTTP and HTTPS access
  • Uses HTTP links in sitemaps
  • Search engines index HTTP version
  • Default for pre-October 2016 domains

Benefits of SSL Protection:

  • Encrypts visitor data
  • Prevents hacking attempts
  • Improves site loading speed
  • Enhances SEO performance
  • Builds visitor trust

Commerce and SSL:

  • Checkout pages always use SSL regardless of settings
  • Maintains PCI Level 1 compliance
  • Uses 128-bit SSL encryption
  • Custom domains appear in checkout URL for Commerce plans

Verifying SSL Status:

  • Look for "https://" in URL
  • Check for closed padlock icon
  • Certificate status shows as "Issued" in Domains panel
  • SSL panel displays "Active" status

Important Notes:

  • Cannot be disabled for security reasons
  • Works with all modern browsers
  • Automatically secures subdomains
  • Doesn't support third-party SSL certificates
  • Uses TLS 1.2 for HTTPS connections

For technical issues or security warnings, review your DNS settings and ensure proper domain connection. Allow up to 72 hours for SSL certificate changes to take effect.

Related Articles

Previous Articles