What Is SSL and Why Is It Important?

What is SSL?

SSL (Secure Sockets Layer) is a standard technology behind establishing an encrypted connection between a web server (host) and a web browser (client). This connection between the two makes sure that all the data passed between them remain private and intrinsic. SSL is an industry standard and is used by millions of websites to protect their online transactions with their customers. If you have ever visited a website using the https:// in the address bar you were creating a secure connection via SSL. If you have an eshop or sell items via your website, SSL helps in establishing trust with your customers.

Understanding how the SSL connection protects your data

Secure SSL connection protects against intrusion

Using an SSL certificate creates an encrypted connection between the user’s web browser and the web server. This means that any data transmitted between the web server and the web browser can not be read without first being decrypted. This protects the data from being spied upon by someone else on the internet because they will not be able to understand the encrypted data.

How the encrypted connection is established

Secure SSL connection illustration

There a few basic steps that occur when you attempt to establish secure connection. Here’s a summary of the steps:

  1. You type in or select the secure URL (e.g. “https://abcdefg.com”)
  2. The web server receives your request and then submits a reply that attempts to establish trusted connection between the web browser and the web server – also called the “SSL handshake.”
  3. After the SSL certificate is verified through the SSL handshake, the data transferred between the web server and web browser is encrypted to keep it private and secure.

How to tell if a site is using SSL

While the details of the SSL protocol are not displayed to the visitor, most browsers will display a lock or some other form of identification in the address bar. This will indicate if you are currently protected by an SSL encrypted session. If you would like the details of the SSL certificate you can simply click on the lock.

What does the SSL mean to visitors?

Most SSL Certificates contain the domain name, company name, address, city, state, and country. It also contains an expiration date of the certificate and the details of the Certificate Authority (the company who issued the SSL). When a browser attempts to establish an SSL connection to a website it checks to make sure the certificate is not expired, has been issued by a trusted authority, and is being used for the correct website. If any of these checks fails your web browser will display a warning letting the user know that the site is not secured by SSL.

How do I get an SSL for my website?

Please read our article on Ordering an SSL if you’d like more information. For further assistance or if you have any more questions please feel free to contact our support department.

Thoughts on “What Is SSL and Why Is It Important?

  • Thanks for helping me learn more abotu SSL. I actually didn’t know that having an SSL certificate can help create an encrypted connection. I’m kind of interested to learn if the level of encryption can be customized or if it’s generally the same for anyone that has the certificate. 

    • There are differences in the validation of SSL Certificates but not necessarily “security”. For instance, some SSLs will validate the actual business is the owner of the domain. The browser really only looks to ensure that your SSL is (at the very least) Domain Control Validated, not expired, and authorized by a valid provider.

  • very basic questions, if I purchase the SSL for a site on a reseller account, the urls all point to the specific website, not to the reseller’s account, right? And the website would then be https on all pages?

    • Hello Jan,

      If you purchase ANY SSL, it is generally set to a particular URL (with the exception of WildCard SSLs). So, the SSL certificate only applies to pages that use that particular URL. I hope that helps to explain it. If you have any further questions, please let us know.

      Kindest regards,
      Arnel C.

  • Simple example to use local paths.




    this would point to:  website.com/css/images/arrow.jpg


    (‘/images/arrow.jpg’) <– notice the first forward slash.  This defines the root of the website.

    this would point to:  website.com/images/arrow.jpg


    If you are using a <A HREF>……



    <a href=’images/pluto.jpg’>

    This would look for the jpg in:  website.com/gallery/images/pluto.jpg


    <a href=’/images/pluto.jpg’>

    This would look for the jpg in:  website.com/images/pluto.jpg



    All your links should use the relative path.  You could also use two dots, <a href=’../images/pluto.jpg’> to go back one directory, but that can get tricky if you move files around.

  • My SSL connection makes a mess of my web page because it expects included files like css files and WordPress plugins to begin with https, not http. Short of duplicating dozens of files and changing their names so they begin with https I’m not sure what to do.

    Try this URL: https://www.artleasecanada.ca and you’ll see what I mean

    • Hello Stu,
      When preparing for SSL, you do not have to change file names, but rather ensure the paths are not absolute. For example, if you call an image called ‘dog.jpg’, then it should just be called with a relative path. This means in your code, you just have to place the part of the path from where the calling file is. If the image is in a folder named images, and your page is in the primary folder, then you only have to place ‘images/dog.jpg‘ as opposed to ‘https://example.com/images/dog/jpg‘. In the latter, you can see it has the absolute path, including the protocol.

      Even so, the files should still work, no matter the protocol used. The consequence of having a full path with non SSL protocol when using SSL is just that the green lock will not appear. It will give a warning that some items are being called via normal protocol.

      This explanation may not be as thorough as the article I wrote on why the lock is not displaying. Check that out if you like as it is a bit clearer.

      Kindest Regards,
      Scott M

  • Hi georgesvh,

    I’m glad you were able to resolve this issue. If you need further assistance please feel free to contact us.


    Tim S.

  • Hi georgesvh,

    If there’s a block it would be based on your IP address, which would prevent cyberduck from connecting as well. I’ve reviewed the logs and I see you have some failed attempts at logging in. It appears in one instance you weren’t using the full username. In another instance, once you logged in, it times out after 30 minutes of inactivity. I did see you recently uploaded some files within the last 5 minutes or so. Did you correct the issue?

    If you need further assistance please feel free to contact us.


    Tim S.

  • Problem resolved. Apparently RW caches login info, even if you change the credentials. After restart in RW, the site published. Thanks. Please close the ticket.

  • Yes, I know. I have been using RW for about 10 years. I did make a mistake in posting a 404.shtml file that then referred to another non-existing page, causing a looping. I wonder if that blocked RW from getting in. I removed the 404.shtml file using Cyberduck and now want to repost my fix using Rapidweaver, to no avail.

Was this article helpful? Let us know!