Category — Page 2

SSL Basics — Page 2

50 guides covering the foundations: what SSL/TLS is, how the handshake works, the cryptography underneath, and every certificate type and field you'll run into.

What Is HSTS and Should You Enable It?

One header that closes the gap attackers use to intercept a visitor's very first connection to your site.

What Is a Man-in-the-Middle Attack and How SSL Prevents It?

The attack SSL/TLS was fundamentally designed to stop — walked through step by step, blocked at each turn.

Understanding X.509 Certificate Format

Every certificate on the internet follows the same 1988 standard — here's what's actually inside the file.

What Is Certificate Revocation? OCSP vs CRL

What happens when a certificate needs to be invalidated before its expiry date — and how browsers find out.

What Is Mutual TLS (mTLS)?

Normal HTTPS proves the server's identity. Mutual TLS makes the client prove its identity too.

What Is a Certificate Authority (CA)?

The organizations your browser already trusts — and why that trust is what makes any certificate work at all.

Root Certificates vs Intermediate Certificates

Your server almost never presents a root certificate directly — here's why that's by design.

Self-Signed Certificates: What They Are and When to Use Them

Every browser will warn you about them — and for local development, that's exactly the right trade-off.

What Is HTTPS and How Is It Different From HTTP?

One letter, and an entire encrypted layer sitting underneath it.

What Does the Padlock Icon Actually Mean?

Less than most people assume — and browsers have been quietly redesigning it for exactly that reason.