Skip to main content

SSL Certificates Explained: Expiry, Validity, and Why the Lock Icon Isn't the Whole Story

The padlock icon in a browser's address bar has become shorthand for "this site is safe" — a habit visitors picked up over years of security training. The problem is, the padlock only confirms one narrow thing: that the connection between the browser and the server is encrypted. It says nothing about whether the site itself is trustworthy, well-maintained, or configured correctly. Understanding what an SSL/TLS certificate actually does — and doesn't — do matters more than most business owners realize.

What a Certificate Actually Certifies

An SSL/TLS certificate proves two things: that traffic between the visitor and the server is encrypted in transit, and — depending on the validation level — that whoever requested the certificate controls the domain (or, for more rigorous validation levels, that a real registered business is behind it). It does not certify that the site is free of malware, that the CMS is patched, or that the business behind it is legitimate. Attackers get valid, padlocked certificates for phishing sites constantly — encryption and trustworthiness are simply different things.

Expiry: The Quiet Outage Nobody Plans For

Certificates expire, typically after 90 days to a year depending on the issuer. When one lapses unnoticed, visitors don't see a vague warning — they see a hard, alarming "Your connection is not private" browser interstitial that stops most people from proceeding at all. For a business site, that's a full outage that looks exactly like a security incident, even though it's just a missed renewal.

Validation Levels: DV, OV and EV

Domain Validated (DV) certificates only confirm domain control and can be issued in minutes — this is what the vast majority of websites use today, including free options like Let's Encrypt. Organization Validated (OV) and Extended Validation (EV) certificates involve actual verification of the business behind the domain, but browsers no longer visually distinguish EV certificates the way they once did (the old green address bar is gone), so most visitors have no way to tell the difference just by looking.

HTTPS Everywhere, Not Just the Login Page

A holdover from an older security mindset is encrypting only login or checkout pages while leaving the rest of the site on plain HTTP. Every page should load over HTTPS by default — partial HTTPS leaves session cookies and page content exposed on every other page, and modern browsers actively flag HTTP pages as "Not Secure."

Check Your Certificate Status Instantly

Our free Website Security Checker checks certificate validity and expiry for any domain in seconds, alongside the security headers and other checks that a padlock alone won't tell you about.

Certificates Are Infrastructure, Not a One-Time Setup

Automated renewal removes the manual-renewal outage risk, but someone still needs to make sure that automation is actually running and alerting on failure. Decoding IT's infrastructure management services include certificate lifecycle monitoring as a standard part of keeping a business website online and properly secured.

Decoding IT is a Muscat-based IT solutions provider helping businesses across Oman keep their websites properly encrypted and their certificates from becoming a surprise outage. Contact our team to review your certificate setup.