TLS protocol versions, certificate types, a deployment checklist, and direct links to SSL analysis tools.
Current standard. Faster handshake, forward secrecy by default, deprecated weak ciphers removed.
Still widely used and secure when configured correctly. Required for PCI DSS compliance.
Deprecated since 2021. No longer supported by major browsers.
Vulnerable to POODLE and BEAST attacks. Disable immediately.
Critically insecure - POODLE vulnerability. Must not be used.
Broken. Never use.
Verifies domain ownership only. Issued in minutes. Suitable for most sites.
Best for: Blogs, personal sites, APIs
Verifies the company behind the domain. Shows org name in certificate details.
Best for: Business websites, e-commerce
Highest validation - deep vetting of the organisation. Green bar in older browsers.
Best for: Banks, financial services
Secures a domain and all first-level subdomains.
Best for: Multi-subdomain setups
Covers multiple domain names in one certificate.
Best for: Multi-site hosting
Generated locally - no CA validation. Causes browser warnings.
Best for: Internal tools, development
A complete reference guide to SSL/TLS protocol versions, certificate types, and deployment best practices. Learn the difference between TLS 1.3 and TLS 1.2, when to use a DV, OV, or EV certificate, and what your HTTPS setup needs to pass a security audit. Includes direct links to SSL Labs, DigiCert, and other analysis tools pre-filled with your domain.