EMZETT.
Login

Certificates in web development

In short: In web development this usually means TLS certificates (often called “SSL certificates”). They prove that a website really belongs to the domain and enable the encrypted connection via HTTPS.

In more detail: The certificate contains the domain, the public key, the validity period and the signature of a certificate authority (see certificate authorities). The browser checks it when connecting (TLS).

In Depth

Types

  • DV (Domain Validation): only checks that you own the domain. Quick and often free.
  • OV/EV (Organization/Extended Validation): also checks the company.
  • Wildcard: covers all subdomains (*.example.com, see subdomain).

In practice

  • Let’s Encrypt: free DV certificates, valid for 90 days, renewable automatically.
  • Certificate chain: your certificate → intermediate certificate → root certificate that the browser trusts.
  • Expiry: an expired certificate causes a browser warning. Automatic renewal and monitoring are a must.
  • Errors: wrong name, expired, incomplete chain or missing root certificate.
  • Other certificates: code-signing certificates sign software, client certificates identify users.

See also: certificate, HTTPS, IT security in web development