Quick, plain-English answers to the questions we're asked most often about SSL/TLS certificates.
What is an SSL/TLS certificate?
It's a small file installed on your server that encrypts traffic between your site and its visitors, and authenticates that the site is who it claims to be. It's what turns http:// into https:// and shows the padlock.
Do I really need one?
Yes. Browsers mark plain HTTP sites as "Not secure", search engines favour HTTPS, and payment and login pages effectively require it. Any site that wants trust needs a certificate.
DV, OV or EV - which do I need?
DV proves domain control (fast, for most sites); OV and EV also verify your organisation (for business and high-trust sites). See DV vs OV vs EV.
How long does issuance take?
DV is usually minutes after validation; OV/EV take 1-3 business days for organisation checks.
How long is a certificate valid?
Currently about a year, and industry rules are shortening it. For longer coverage, buy a multi-year plan and reactivate free before each expiry.
One domain, subdomains, or many domains?
Use a single-domain certificate for one site, a wildcard for all subdomains of one domain, or a multi-domain (SAN) certificate for several different domains.
Buying from India - what about GST?
You get a proper tax invoice and can claim input credit. See SSL & GST for Indian businesses.