Understanding SSL Certificates: Essential Guide to Secure Your Website

Understanding SSL Certificates: Essential Guide to Secure Your Website

By Michael Turner

December 17, 2024 at 05:45 AM

SSL certificates are automatic security protections that encrypt connections between websites and visitors' browsers. They prevent hackers from stealing information or impersonating your site.

Key Points About SSL Certificates:

  • Free and automatic for all properly connected domains
  • Covers main domains, subdomains, and child domains
  • Domain names must be under 63 characters
  • Takes up to 72 hours to activate after changes

Checking Your SSL Status:

  1. Open domain dashboard and verify "Issued" status
  2. Check SSL panel shows "Active"
  3. Visit your site to confirm certificate

Recommended SSL Settings:

Safe (Preferred)

  • Redirects to HTTPS automatically
  • Improves SEO with HTTPS sitemaps
  • Required by some domain providers

HSTS Secure

  • Additional encryption layer
  • Prevents security warning messages
  • Recommended when using Safe setting

Insecure

  • Allows both HTTP and HTTPS access
  • Uses HTTP sitemaps
  • Not recommended for most sites

Important Security Notes:

  • Payment pages use 128-bit SSL encryption regardless of settings
  • Custom code may cause mixed content warnings
  • Certificates renew every 90 days automatically
  • Uses 2048-bit encryption (except payments)
  • TLS 1.2 for all HTTPS connections

Benefits of SSL:

  • Builds visitor trust
  • Prevents data theft
  • Improves site loading speed
  • Enhances SEO performance

Troubleshooting Tips:

  • Verify domain connection is correct
  • Check DNS records for issues
  • Allow up to 72 hours for changes
  • Ensure custom code uses HTTPS links

Third-party certificates aren't supported - sites must use Squarespace's built-in SSL protection. During DNS changes, HTTPS access may be temporarily unavailable while new certificates generate.

FAQs:

  • SSL cannot be disabled but can be set to "Not Secure"
  • Works with all subdomains
  • Account login details always encrypted
  • Supported on all modern browsers

For additional help with SSL certificate issues, consult the SSL Troubleshooting documentation.

Related Articles

Previous Articles