Concepts

HTTPS vs. SSL vs. TLS: the terms, untangled

Three words, one padlock

If you have shopped for a certificate or read a security tip, you have seen HTTPS, SSL and TLS used as if they were synonyms. They are connected, but they are not the same thing, and one of them has been dead for years. Here is the untangled version.

HTTPS: the secure web protocol

The web runs on HTTP — the protocol your browser uses to request a page and receive it. Plain HTTP is sent in the clear, so anyone between you and the server can read or alter it. HTTPS is simply HTTP wrapped in encryption: same protocol, now travelling through a secure channel. The S is for secure, and it is the thing the padlock in the address bar refers to.

HTTPS is the outcome you want. It is not itself the encryption — it relies on something underneath to provide the secure channel.

TLS: the encryption that makes it secure

That something is TLS — Transport Layer Security. TLS is the protocol that does the actual work: it encrypts the connection, verifies the server's identity using a certificate, and ensures the data is not tampered with in transit. When your browser connects over HTTPS, it performs a TLS handshake first to set up the encrypted channel, then sends HTTP through it.

So HTTPS = HTTP + TLS. TLS is the engine; HTTPS is the result.

SSL: the retired ancestor

SSL — Secure Sockets Layer — is what TLS used to be called. It was the original encryption protocol for the web, but every version of SSL has known, serious weaknesses and has been formally deprecated for years. The industry moved to TLS, and modern sites should accept only modern TLS versions.

The name never caught up, though. People still say 'SSL certificate', certificate vendors still market 'SSL', and config files still mention ssl. In almost every modern context, when someone says SSL they actually mean TLS. The label is legacy; the technology underneath is TLS.

Which term should you use?

  • Say HTTPS when you mean 'the site is served securely'.
  • Say TLS when you mean the encryption protocol or its version (TLS 1.2, TLS 1.3).
  • Treat SSL as a synonym people use out of habit — fine in conversation, but the real protocol is TLS, and actual SSL should be switched off.

What actually matters for your site

The naming is trivia; the configuration is not. What counts is that your site serves over HTTPS, presents a valid certificate, and accepts only current TLS versions while refusing the old, broken ones. A site that technically supports HTTPS but still allows outdated protocols is not as secure as the padlock suggests.

Check how your site is served

You cannot tell which TLS versions your server accepts just by visiting it. An automated scan inspects how your site negotiates its secure connection and flags weak or outdated configuration. Scan your site and see whether your HTTPS is as solid as it looks.

Related reading

FAQ

Is SSL the same as TLS?
Practically, when people say SSL they mean TLS. SSL is the older, now-deprecated protocol that TLS replaced; the name simply stuck. Actual SSL versions are insecure and should be disabled, while modern TLS does the real work.
Does HTTPS use SSL or TLS?
Modern HTTPS uses TLS. HTTPS is HTTP carried inside a TLS-encrypted channel. Although certificates are still marketed as SSL certificates, the protocol securing the connection today is TLS, not SSL.
Is an 'SSL certificate' wrong then?
The name is outdated but harmless. What vendors call an SSL certificate is a TLS certificate — it works with TLS to prove your server's identity and enable HTTPS. The certificate itself is fine; only the old SSL protocol is the problem.