SSL
In short: “Secure Sockets Layer” — the predecessor of TLS. The name has stuck in everyday speech to this day (“SSL certificate”), but technically it’s practically TLS running in the background everywhere now.
In more detail: SSL was developed in several versions (SSL 1.0–3.0), all of which are now considered insecure and officially deprecated. In 1999, SSL 3.0 was developed further into TLS 1.0. Terms like “SSL certificate” or “SSL encryption” are therefore historically grown but technically outdated names for what should today be called TLS certificates and TLS encryption.
In Depth
The version history shows why SSL is completely retired today:
SSL 1.0 (1994) - never published, serious design flaws discovered internally
SSL 2.0 (1995) - several known vulnerabilities, officially banned since 2011
SSL 3.0 (1996) - vulnerable to the POODLE attack, officially banned since 2015
TLS 1.0 (1999) - developed from SSL 3.0, now also outdated
TLS 1.1 (2006) - outdated
TLS 1.2 (2008) - the standard for a long time, still considered secure
TLS 1.3 (2018) - current standard, faster handshake, removes insecure options
Modern browsers and servers no longer support real SSL at all for security reasons — every connection colloquially described as “SSL-encrypted” actually runs over TLS (usually TLS 1.2 or 1.3). The term has nevertheless stuck in everyday language, similar to how people colloquially still say “on the radio” instead of “on terrestrial broadcast”.
The term “SSL certificate” used by certificate providers (e.g. Let’s Encrypt) is also technically imprecise, but so widespread that even reputable providers often use both terms synonymously in their customer communication — the actual certificate itself doesn’t know “SSL” or “TLS” at all, it only contains a public key and a signed identity mapping; which protocol (SSL or TLS) and which version of it is used for the actual connection is negotiated separately by client and server when the connection is established.
Why the renaming from SSL to TLS happened
The renaming from SSL 3.0 to TLS 1.0 in 1999 was technically a relatively small development step, but organisationally/politically significant: SSL was originally developed by Netscape as a proprietary company protocol, whereas standardisation from TLS onwards ran under the Internet Engineering Task Force (IETF) — a vendor-neutral organisation that maintains open internet standards. The new name signalled this transition from a single company’s product to an open standard developed further by the entire internet community. Security tools and vulnerability scanners still explicitly distinguish between a server’s supported SSL and TLS versions today, because a server that still accepts old SSL versions is classified as insecure regardless of its other configuration — modern server software therefore disables SSL support entirely by default.
Detecting outdated SSL/TLS versions
For website operators, there are publicly accessible testing tools (e.g. the SSL Labs test by Qualys) that automatically check a server for supported protocol versions, cipher suites and known vulnerabilities, and summarise the result with an easy-to-understand rating (from A+ to F). A server that still accepts old, insecure protocol versions for compatibility reasons gets a poor rating, even if modern clients would use the secure TLS 1.3 connection anyway — such tests help find accidentally open compatibility gaps before attackers exploit them.
See also: TLS, Certificate