7 different types of SSL certificates explained
February 25, 2026
SSL/TLS certificates secure digital communication through encryption and authentication, allowing websites and applications to protect data in transit and use HTTPS. These certificates are typically issued by a Certificate Authority (CA) and must be installed correctly to work as intended.
Installation involves uploading certificate files and configuring servers, with specific instructions for platforms like Zimbra, Nginx, Tomcat, and more. Prior steps include generating a CSR and choosing the right SSL type, while post-installation actions focus on testing, monitoring, and renewal. Trusted CAs like Sectigo simplify the process with guidance and SSL certificate options for different website and business needs.
SSL stands for Secure Sockets Layer, while TLS stands for Transport Layer Security, the modern protocol used today. Once issued by a trusted CA, an SSL/TLS certificate must be installed to move from the enrollment stage to the provisioning stage of the certificate lifecycle. This makes the certificate active and ready for use.
While certificate installation is a technical process, it doesn’t have to be overwhelming. This guide breaks down how SSL certificate installation works, what to prepare before you begin, and how to install certificates across common servers and platforms.
There are multiple steps involved in the SSL/TLS certificate process.
We’ve included more information on what’s needed prior to installation below.
Before you can install your certificate, you need to determine which type of SSL certificate will actually be installed. There are several options available, but this decision will ultimately come down to the level of validation needed and the number of domains that need to be covered.
There are three validation levels including extended validation (EV), which offers the highest level of validation, organization validation (OV), and domain validation (DV). You must then determine if you need a single domain, wildcard, or multi-domain SSL certificate.
It’s recommended to buy your certificate from a trusted Certificate Authority, such as Sectigo. The CA is responsible for validating certificate requests and issuing certificates that browsers and systems recognize as trusted. After you complete the purchase, the CA will guide you through the next steps, including certificate validation and issuance
Certificate signing requests play a critical role in the early stages in the SSL certificate lifecycle, including request, enrollment, and issuance. These must be created and submitted at the beginning of the process and, without them, installation will not be possible. These encrypted messages contain crucial information about the individuals or organizations who seek SSL/TLS certificates.
Information used to identify the requester include:
Creating a CSR automatically generates a public key, which functions as half of the key pair needed for SSL certificates. Once equipped with the CSR's information, the CA should be prepared to create the requested certificate.
The SSL installation process can play out differently with various services and platforms. To that end, you'll want to follow server-specific instructions to ensure that the certificate is installed correctly. We've highlighted a few examples of installation procedures below:
This is just a small sample of the different processes that may be followed when installing SSL/TLS certificates. Sectigo provides easy access to a wealth of server and platform-specific instructions, including the following:
After an SSL certificate is installed, it will need to be tested and, eventually, renewed before it expires.
Various command-line tools (such as OpenSSL) can confirm that SSL/TLS certificates have been installed correctly. These tools may also check for vulnerabilities. Following a successful test, monitor the certificate to ensure that any new vulnerabilities are promptly revealed and addressed.
Public SSL certificate validity periods have recently been reduced. As of March 15, 2026, they can have a maximum validity period of 200 days. That limit will drop to 100 days on March 15, 2027, and 47 days on March 15, 2029. As certificate lifespans continue to shorten, it is important to know how long each certificate will remain valid and what renewal steps are required. Certificate lifecycle management automation helps to prevent missed renewals or outages.
If you encounter issues during or after installation, consult your certificate authority for support. In addition to providing the actual digital certificate, the CA will ideally offer guidance, including detailed instructions for installing certificates, troubleshooting and other support services.
Choosing the right CA is crucial for ensuring a seamless installation process and making the most of your SSL/TLS certificates once they are installed. Stick with a trusted CA that has a strong track record and a reputation for working closely with customers.
Sectigo offers digital certificates to suit every type of organization. We offer everything from single SSL certificates to wildcard and multi-domain options. What's more, we accommodate all validation levels. Feel free to browse our products or get in touch to discover how various types of SSL/TLS certificates can enhance your security strategy.