# What is an SSL certificate?

An SSL certificate makes the site available over HTTPS.

> Source: https://www.mainpath.ai/en/wiki/ssl/

## What it is

An SSL certificate, usually TLS today, proves that the browser is talking to the server that belongs to this name. It encrypts the connection. Without a certificate the site stays on HTTP, or the browser shows a warning before anyone even sees the content.

The browser checks the name in the certificate against the name in the address bar. The two have to match.

## What it is made of

The certificate names the name it is valid for, and a date until which it is valid. `example.com` and `www.example.com` are two names. A certificate for only one of them makes the other warn. Wildcards such as `*.example.com` cover the subdomains, not the bare domain, depending on how it was issued.

## What goes wrong

Certificates expire. An expired certificate is not a small notice, the site is practically closed for visitors. Renewing means getting a new one in time and giving it to the server without breaking the connection. By hand on every server, that is a task someone forgets, usually on a Friday.

## What you otherwise look after yourself

The certificate hangs on the name, so on DNS. If the name points somewhere else, the certificate on the right server does not help.

## How it shows up on MainPath

MainPath attaches the certificate to the project's domain, together with the DNS records under [Domains]({{< relref "/docs/domain" >}}).

