Three words, one padlock
If you have shopped for a certificate or read a security tip, you have seen HTTPS, SSL and TLS used as if they were synonyms. They are connected, but they are not the same thing, and one of them has been dead for years. Here is the untangled version.
HTTPS: the secure web protocol
The web runs on HTTP — the protocol your browser uses to request a page and receive it. Plain HTTP is sent in the clear, so anyone between you and the server can read or alter it. HTTPS is simply HTTP wrapped in encryption: same protocol, now travelling through a secure channel. The S is for secure, and it is the thing the padlock in the address bar refers to.
HTTPS is the outcome you want. It is not itself the encryption — it relies on something underneath to provide the secure channel.
TLS: the encryption that makes it secure
That something is TLS — Transport Layer Security. TLS is the protocol that does the actual work: it encrypts the connection, verifies the server's identity using a certificate, and ensures the data is not tampered with in transit. When your browser connects over HTTPS, it performs a TLS handshake first to set up the encrypted channel, then sends HTTP through it.
So HTTPS = HTTP + TLS. TLS is the engine; HTTPS is the result.
SSL: the retired ancestor
SSL — Secure Sockets Layer — is what TLS used to be called. It was the original encryption protocol for the web, but every version of SSL has known, serious weaknesses and has been formally deprecated for years. The industry moved to TLS, and modern sites should accept only modern TLS versions.
The name never caught up, though. People still say 'SSL certificate', certificate vendors still market 'SSL', and config files still mention ssl. In almost every modern context, when someone says SSL they actually mean TLS. The label is legacy; the technology underneath is TLS.
Which term should you use?
- Say HTTPS when you mean 'the site is served securely'.
- Say TLS when you mean the encryption protocol or its version (
TLS 1.2,TLS 1.3). - Treat SSL as a synonym people use out of habit — fine in conversation, but the real protocol is TLS, and actual SSL should be switched off.
What actually matters for your site
The naming is trivia; the configuration is not. What counts is that your site serves over HTTPS, presents a valid certificate, and accepts only current TLS versions while refusing the old, broken ones. A site that technically supports HTTPS but still allows outdated protocols is not as secure as the padlock suggests.
Check how your site is served
You cannot tell which TLS versions your server accepts just by visiting it. An automated scan inspects how your site negotiates its secure connection and flags weak or outdated configuration. Scan your site and see whether your HTTPS is as solid as it looks.