You type a website address, see the padlock, don’t think about it again. Good, that’s the point. Behind it is a process where the site proves who it is and gets a certificate for its domain.

It Starts With A Request

First, the owner picks a Certificate Authority, a trusted org that issues certificates after checking a site’s details.

The owner creates a private key on the server, stays secret. Alongside it, the server generates a Certificate Signing Request containing the domain name and the public key tied to that private key.

The CSR gets sent to the CA. The private key doesn’t travel with it, that part matters.

The Domain Gets Verified

The CA needs to confirm whoever’s asking actually controls the domain. For a basic certificate, usually pretty simple.

A verification email might go to an approved address. Sometimes a special DNS record proves control instead. A small verification file can sit on the website too, in a location the CA checks.

Once proof’s confirmed, the CA approves the request. Exact checks depend on certificate type, a business wanting stronger verification goes through more than a personal site needing basic HTTPS.

The Certificate Gets Issued

The CA creates the certificate and signs it with its own private key. That signature matters, browsers already trust recognised CAs, so they can confirm the certificate came from a trusted source and hasn’t been altered.

Contains the site’s identity info, public key, and a validity period, not something you get once and forget forever.

Owner installs it on the server. Depending on hosting, sometimes automatic, sometimes not.

What Happens When Someone Visits

Browser receives the site’s certificate, checks if it’s valid and matches the domain. Everything checks out, browser and server establish an encrypted connection, so whatever’s moving between them stays protected.

Does It Need Renewing

Yes, certificates have limited lifespans. Need a new one before the current expires, otherwise visitors start seeing warnings.

Automatic renewal’s the better setup, forgetting about certificates is an easy way to break an otherwise healthy site. Modern hosting often renews automatically, if yours doesn’t, track the expiry date yourself.

Request the certificate, prove domain control, install it, keep it renewed. Once HTTPS is working, nobody thinks about the certificate again, probably the best sign it was set up right.