SSL vs TLS
Ask a room full of site owners what the padlock icon guarantees and the answers scatter. Some say the site is safe, some say nobody can steal card details, a few say it proves the business is real. Meanwhile the hosting invoice lists an “SSL certificate”, the server config mentions TLS, and nobody explains why both words are in play.
One of those two names has been out of service for a decade. Every release of SSL has been formally withdrawn, and SSL Labs measurements put lingering support at around 1% of sites. What runs underneath your padlock is TLS, and the older name simply outlived the thing it described. Qualys SSL Pulse recorded TLS 1.3 support on 75.3% of the largest sites as of June 2025.
What follows untangles the two SSL/TLS protocols, walks through a connection as it happens, sorts out which certificate to buy, explains why certificates now expire twice as fast, and covers what teams building in the UAE deal with beyond encryption.
What SSL and TLS Are, and Why Only One of Them Still Works
The Protocol That Got Withdrawn
Secure Sockets Layer came out of Netscape during the mid-1990s to solve a narrow problem: shops had started appearing online and card numbers were crossing the network in the open. Three releases followed, all three now history.
The first never shipped, since weaknesses surfaced ahead of launch. The second shipped in 1995, leaned on MD5, and was shut down by RFC 6176 in 2011. Version three survived until 2014, when researchers demonstrated POODLE: force a connection to drop back to the older version, and encrypted cookies become readable. RFC 7568 closed that chapter in 2015.
How the Standard Changed Hands
A protocol underpinning commerce cannot stay proprietary forever, and by the late 1990s the industry agreed. Stewardship passed to the IETF, and 1999 brought Transport Layer Security. The first release amounted to a polished version three, hence the joke that TLS 1.0 was really SSL 3.1.
Public development produced three more releases. CBC mode weaknesses got closed in 2006, support for SHA-256 and AES-GCM followed two years later, and the current release landed in 2018 after roughly a decade of drafts involving Google, Mozilla, Microsoft and Cloudflare.
Why Invoices Still Say “SSL Certificate”
Marketing kept the retired name alive. Dashboards, price lists and documentation still use it, because customers search for the phrase they know. OpenSSL, a library speaking nothing but TLS for years, never renamed itself either.
The SSL/TLS meaning gets clearer once three separate things stop being treated as one:
- the protocol sets the rules for opening a secure connection, and TLS is the only one still doing that job;
- the certificate proves that whoever runs the server also controls the domain;
- the implementation is code carrying out those rules, OpenSSL being the best known example.
Heartbleed shows why the difference matters. Coverage in 2014 called it a hole in SSL, when the bug sat in OpenSSL code handling a keepalive feature and the specification was never at fault. Patch the library and the problem disappears, which is not how a broken protocol behaves.
Which Protocol Versions Are Still Supported in 2026
Four of the six SSL/TLS protocols released since 1995 are gone. Both SSL versions went first, followed by TLS 1.0 and 1.1, deprecated by RFC 8996 in March 2021 after browsers had pulled them a year earlier. PCI DSS and NIST SP 800-52 Rev. 2 prohibit them outright, so a site taking card payments has no decision left here.
TLS 1.2 occupies an awkward middle position. No formal deprecation has arrived as of mid-2026, and an endpoint configured properly is still sound. That qualifier does a lot of work: ECDHE for key exchange and nothing else, a short list of modern cipher suites, compression off, renegotiation off. Vendor defaults are usually looser.
Then there is TLS 1.3, where one observation explains its position better than any feature list. BEAST, CRIME, POODLE, Logjam: run down the named attacks of the past fifteen years and nearly all exploited machinery that 1.3 threw out. Instead of patching around old design decisions, the working group rebuilt the protocol with a deliberately smaller surface.
Practical takeaway for any server you manage: 1.3 first, 1.2 for stragglers, everything older switched off by name rather than left to a default.
SSL vs TLS: How Six Releases Compare
Looking at the difference between SSL and TLS in network security release by release shows the trend better than a feature list.
Two properties separate the modern releases from the rest. Forward secrecy, optional for years, became compulsory in 1.3, so a stolen server key cannot unlock traffic captured months earlier. Downgrade protection also matured, closing the fallback trick POODLE relied on.
What Happens in the Milliseconds Before a Page Loads
Agreeing on Encryption With a Stranger
Two machines that have never communicated need a shared secret key before encrypted traffic can flow, and they have to establish it across a channel anyone can read. Solving that is the entire purpose of the opening exchange, known as the handshake.
The browser opens by listing what it can do: protocol versions, cipher suites, plus a batch of random bytes. Whatever the server picks from that list becomes the agreement for the session, and it answers with random bytes of its own and its certificate.
Validation happens next, before anything sensitive moves. Your browser follows the certificate upward through whoever signed it until the trail reaches an authority in the root store shipped with your system, or fails. A broken trail produces a warning page instead of a website.
Key agreement is the clever part. With Diffie-Hellman neither side transmits the secret: each combines its own private value with the other party’s public value, and the arithmetic lands on an identical result at both ends that an observer cannot reproduce from what crossed the wire. That result becomes the symmetric key protecting everything afterwards.
Why two stages? The maths solving the stranger problem is expensive, while the symmetric encryption handling bulk traffic cannot start without a shared key. Forward secrecy comes free with the arrangement: a server key stolen next year unlocks nothing recorded today.
One Round Trip Instead of Two
Older connections burn two complete message exchanges before the first byte of content appears, which anyone testing over mobile data notices. The 2018 release collapsed that to one by having the browser guess the key agreement parameters up front instead of waiting to be told. Somewhere between 100 and 300 milliseconds comes off every new connection.
Return visitors can go further with 0-RTT, presenting a ticket saved from last time and sending encrypted data immediately. The catch is replay: an intercepted request can be resent by an attacker, so the mode belongs on page fetches rather than anything that changes state.
Housekeeping explains the rest. Legacy cipher suites, key exchange without forward secrecy, compression and renegotiation left the specification, and alerts that once travelled in the clear became encrypted. Fewer knobs means fewer ways to misconfigure a server.
DV, OV and EV: What You Are Actually Paying For
Encryption costs nothing, since every web server ships with it. The invoice covers verification a certificate authority performs before vouching for you, and SSL/TLS certificates come in three depths of checking.
- DV, Domain Validation. All the authority confirms is control of the domain, proven by an email to an administrative address, a file on the site or a DNS record. Minutes to issue, frequently free, fine for blogs and internal tooling.
- OV, Organization Validation. Company records enter the picture: registered name, registration number, address. Turnaround runs to a few days, which suits corporate sites and anything behind a customer login.
- EV, Extended Validation. Documents get reviewed and somebody phones the applicant to confirm they are authorised. Browsers removed the green company name years ago, but the vetting never went anywhere, which is why financial services still order it.
Coverage is a separate question, constantly tangled with validation. One name, one standard certificate. A wildcard covers a domain plus its subdomains. A SAN certificate carries several unrelated domains at once. Any coverage option pairs with any validation level, so a free DV certificate listing four names is ordinary. Hobby project, take the free DV. Checkout pages justify the organisational check.
Why Certificates Now Expire After 200 Days
Ballot SC-081v3 passed at the CA/Browser Forum in April 2025, where certificate authorities and browser makers write the rules together. The vote finished 29 in favour, nobody against, and what it approved was a countdown for how long a publicly trusted certificate may stay valid:
- 15 March 2026 brought the ceiling down from 398 days to 200;
- 15 March 2027 takes it to 100;
- 15 March 2029 takes it to 47.
Stage one is live and binds every publicly trusted authority, though scope is narrower than headlines suggest: private corporate authorities, code signing and S/MIME keep their existing lifetimes.
Free authorities move even faster. Let’s Encrypt began offering roughly 160-hour certificates, six days and change, on 15 January 2026, alongside certificates issued against IP addresses rather than domain names. Published plans cut its standard lifetime to 64 days in February 2027 and 45 days the following February.
The reasoning is consistent. Compromised keys stay useful only while the certificate holding them remains valid, and revocation machinery has never worked reliably enough to shorten that window on demand. Expiry does the job instead.
Consequences land on operations. TLS/SSL automation stops being optional once renewals outpace human attention, and TLS/SSL certificate lifecycle management means three moving parts: an ACME client renewing without supervision, alerting that catches it failing quietly, and a list of every certificate your organisation holds. That list is what teams get wrong. Staging environments, mail servers, admin panels and half-forgotten subdomains all carry certificates, and at 200 days each reaches its deadline twice as quickly.
What TLS Protects and What It Leaves Exposed
What the protocol delivers:
- traffic between browser and server becomes unreadable to anyone capturing it;
- the server proves its identity through the certificate chain;
- tampering in transit fails the integrity check;
- forward secrecy in 1.3 protects captured traffic against future key leaks.
What it was never designed to handle:
- Whether the operator deserves trust. Criminals obtain certificates as easily as anyone else, and Anti-Phishing Working Group data showed over 90% of phishing pages already displaying a padlock back in 2023. An encrypted channel says nothing about who waits at the far end.
- A compromised server. Anyone holding access to the machine reads plaintext.
- Weaknesses in the application. Injection flaws, reused admin passwords and leaky third-party scripts sit outside the transport layer.
Five Places TLS Is Doing Real Work Right Now
Websites. Certificate validation plus an encrypted channel keeps passwords, payment details and form submissions away from anyone on the same network.
Email. Two approaches coexist. STARTTLS begins in the clear and asks to upgrade mid-protocol on ports 587, 143 and 110. Implicit TLS encrypts from the first packet on ports 465, 993 and 995, and it is the safer default, because a failed negotiation produces no connection rather than an unprotected one.
Service-to-service traffic. Inside a cluster, the use of SSL or TLS encryption extends to mutual TLS, where the client presents a certificate too and the server checks it. Zero Trust designs depend on this, as do device fleets with no realistic way to handle passwords.
Remote access. Several VPN products wrap their tunnel in TLS, inheriting the authentication model protecting ordinary web traffic.
Infrastructure you run yourself. Nothing installs a certificate on your behalf when the site lives on your own VPS. Sequence matters: server first, web server configuration second, certificate third, with Let’s Encrypt and Nginx the common pairing. Spinning up a cloud VPS takes minutes, and the certificate work runs to about half an hour.
When a Valid Certificate Is Not Enough: The DigiNotar Lesson
Abstract discussions of trust chains turn concrete the moment an authority fails, and one collapse remains the reference case.
DigiNotar issued certificates from the Netherlands and sat in every major root store. Attackers got inside during 2011 and walked out with a certificate for a Google domain the company never intended to issue, which was then used to intercept traffic from real users. The uncomfortable part: no cryptography failed. Handshakes completed, keys were negotiated, padlocks appeared. Browsers behaved correctly, because the certificate they were shown traced back to an authority they had been told to trust.
Trust was revoked across the board within weeks and the company went bankrupt shortly after. The lesson has not aged: encryption settles whether traffic can be read, the chain settles who is reading it, and a connection is only as trustworthy as the weakest authority your browser accepts.
Data Residency in the UAE and Where TLS Fits In
Teams building in the Emirates face a second question alongside encryption: where the data physically sits. Federal Decree-Law No. 45 of 2021, the Personal Data Protection Law, has applied since 2 January 2022 and covers any organisation handling personal data belonging to people in the UAE, wherever it is registered. It also remains unfinished. Executive Regulations called for in Article 28 have yet to appear, enforcement has been measured as a result, and advisers commonly cite 1 January 2027 as the horizon for full compliance.
Three boundaries are worth knowing before drawing any conclusions:
- Free zones run their own regimes. Companies licensed in DIFC or ADGM fall outside the federal law, answering instead to frameworks such as DIFC Data Protection Law No. 5 of 2020.
- Whole categories sit elsewhere. Health records, banking and credit information and government data follow sector rules rather than the PDPL.
- Blanket onshore localisation is not the federal position. Keeping data in-country usually comes from sector requirements, free zone rules or client contracts.
Hosting location therefore becomes a commercial judgement rather than a compliance checkbox, which is why many Emirates projects deploy locally anyway. Falconcloud keeps its UAE capacity in Equinix DX1 in Dubai, a Tier III facility, and bills in dirhams through local banks. Picking that region for a VPS in the UAE is a single choice at deployment, with TLS covering transport separately.

Common TLS Configuration Mistakes and How to Fix Them
What to Check on Your Own Site Today
Strip away the naming, and TLS vs SSL is not a choice at all: the retired half survives as a product name and nothing more. Three checks tell you where your own site stands.
- Versions in use. Confirm 1.3 and 1.2 are enabled and older releases disabled explicitly rather than by omission. Any public scanner reports this in under two minutes.
- Renewal pipeline. Under the 200-day ceiling, verify not just that an ACME client exists but that its last few runs succeeded.
- Certificate fit. DV suits personal projects. Payment pages point towards OV or EV, and multiple hostnames are easier with SAN from day one.
Projects needing infrastructure in the Emirates can put a server in the Dubai region behind the same certificate work.
FAQ
What is SSL/TLS, in plain terms?
It is shorthand for the encryption layer under HTTPS. SSL named the original, TLS names every version still in service, and the pairing survives because the industry never stopped writing both.
Is a paid certificate worth it when Let’s Encrypt is free?
The encryption is identical. The difference is the depth of verification behind the certificate. A free DV certificate covers blogs and small sites, while OV and EV matter when visitors need to see a verified organisation behind the domain or a payment provider requires it.
What should I do if a certificate is revoked?
Revocation means the certificate is invalid before its expiry date. Find out why from the issuing authority, generate a new key pair and request a replacement. After a private key compromise, never reuse the old key.