
What Is SSL?
SSL stands for Secure Sockets Layer — a cryptographic protocol that encrypts data transmitted between a visitor's browser and a web server. Modern implementations use TLS (Transport Layer Security), an updated and more secure version of SSL, though the term "SSL" remains in common use for both.
An SSL certificate is a digital file installed on a web server that serves two purposes: it verifies the identity of the website, and it activates 256-bit encryption for all data passing between the user and the server. This means passwords, credit card numbers, and personal information cannot be read by anyone who might intercept the connection.
How Is HTTPS Different from HTTP?
HTTP (HyperText Transfer Protocol) is the basic protocol for transferring data between a browser and a server. It has no encryption — all data is sent as plain text and can be read by anyone who intercepts it on the network.
HTTPS (HTTP Secure) is HTTP with SSL/TLS encryption layered on top. All data is encrypted before transmission. Browsers display a padlock icon in the address bar when a site uses HTTPS, signalling to the user that the connection is secure.
How Does SSL/TLS Actually Work?
Behind the padlock icon is a process called the TLS handshake, which happens in a fraction of a second before a page loads. Its goal is for the browser and server to verify each other's identity and agree on a shared secret key that will be used to encrypt all subsequent data.
In simplified terms, the steps are:
- Client Hello — The browser sends a connection request along with the list of cipher suites and TLS versions it supports.
- Server Hello + Certificate — The server responds with its SSL certificate, which contains its public key. The browser verifies that the certificate was issued by a trusted Certificate Authority (CA) and has not expired.
- Key Exchange — Both sides use asymmetric encryption to securely agree on a shared session key, in such a way that an eavesdropper cannot compute it.
- Encrypted Session — Once the session key is established, all data is encrypted with faster symmetric encryption, keeping the entire connection secure.
This encryption guarantees three things at once: confidentiality (nobody else can read the data), integrity (the data is not altered in transit), and authentication (you are certain you are talking to the genuine server and not an impostor site).
Types of SSL Certificates
DV SSL — Domain Validation
The most accessible entry-level certificate. Verifies only that the applicant owns the domain. Issued within minutes to a few hours. Suitable for blogs, informational websites, and small business sites that simply need HTTPS. Starting from 1,000 THB/year at AsiaGB.
OV SSL — Organization Validation
Includes verification of the organisation's legal identity in addition to domain ownership. Takes 1–3 business days to issue. Best for business websites, login pages, and any site that collects user information or handles transactions.
EV SSL — Extended Validation
The highest level of validation. Involves a thorough review of the organisation's legal, physical, and operational existence. Some browsers display the company name in the address bar. Takes 3–7 business days to issue. Used by banks, financial institutions, and organisations where maximum trust is essential.
Wildcard SSL
Covers the primary domain and all subdomains simultaneously. For example, a Wildcard SSL for *.asiagb.com automatically protects www.asiagb.com, shop.asiagb.com, and blog.asiagb.com. An efficient and cost-effective solution for websites with multiple subdomains.
SSL Type Comparison Table
| Type | Validation Level | Issuance Time | Best For | From (1 year) |
|---|---|---|---|---|
| DV | Domain ownership only | 15 min – 1 hour | Blogs, general & small business sites | 1,000 THB/year |
| OV | Organisation identity | 1–3 business days | Business sites, login pages | 4,000 THB/year |
| EV | Full organisation vetting | 3–7 business days | Banks, financial institutions | 7,000 THB/year |
| Wildcard | DV or OV (covers subdomains) | 15 min – 3 business days | Sites with multiple subdomains | 5,000 THB/year |
Why Your Website Needs SSL
SSL is no longer an optional extra — it has become a baseline standard for every website, for several important reasons:
- Avoids the "Not Secure" warning — Modern browsers like Chrome and Firefox flag any HTTP site as "Not Secure," which makes visitors hesitant to enter information and quick to leave.
- It's an SEO ranking signal — Google has long confirmed it uses HTTPS as a ranking signal, so sites with SSL have a better chance of ranking well than those without.
- Builds trust — The padlock icon reassures users that their data is safe, which is especially important on sites that collect personal details or process payments.
- Protects user data — It prevents data interception (man-in-the-middle attacks) on public Wi-Fi and untrusted networks.
- Enables modern technology — Features such as HTTP/2, PWAs, online payments, and many APIs require HTTPS to function.
Let's Encrypt vs Paid SSL: What's the Difference?
Let's Encrypt is a free DV SSL certificate issued by a non-profit certificate authority. It is trusted by all major browsers and provides solid encryption for general use. However, there are some differences compared to paid certificates:
- Certificate lifespan — Let's Encrypt renews every 90 days (automated on hosting). Paid SSL certificates typically last 1 year.
- Types available — Let's Encrypt only issues DV. Paid options include DV, OV, EV, and Wildcard.
- Warranty — Paid certificates include a financial warranty against mis-issuance. Let's Encrypt does not.
- Best for — Let's Encrypt for standard websites; paid SSL for businesses requiring higher trust signals or OV/EV validation.
Important: Websites without SSL display a "Not Secure" warning in Chrome, Firefox, and other modern browsers — which causes visitors to distrust the site and abandon it before entering any information. Additionally, Google uses HTTPS as a ranking signal in search results. Every website should have SSL installed.
AsiaGB SSL Options
AsiaGB offers SSL certificates at every level from trusted global certificate authorities:
- Free Let's Encrypt — Automatically installed for all hosting customers via DirectAdmin
- DV SSL from 1,000 THB/year — Available from RapidSSL, GeoTrust, and DigiCert
- OV SSL — For businesses requiring organisation identity verification
- EV SSL — The highest assurance level for financial institutions and large organisations
- Wildcard SSL — Protect all subdomains under one certificate
- All browsers supported — Chrome, Firefox, Safari, Edge, and mobile browsers
- 256-bit encryption — Industry-standard protection for all transmitted data
- Free installation — For AsiaGB hosting customers
Frequently Asked Questions
What is the difference between SSL and TLS?
TLS is the newer, more secure successor to SSL. Every website today uses TLS (version 1.2 or 1.3), but people still commonly say "SSL" out of habit, so in practice both terms refer to the same technology.
Is free Let's Encrypt secure enough for a business website?
Let's Encrypt uses the same encryption standard as paid DV certificates and is trusted by all browsers, so it is secure enough for general websites and small online stores. However, if you need organisation identity validation (OV/EV) or a financial warranty, a paid SSL certificate is the better choice.
How often does an SSL certificate need to be renewed?
Let's Encrypt certificates last 90 days and renew automatically on hosting. Paid SSL certificates typically last 1 year and must be renewed before they expire, otherwise the browser will display an expired-certificate warning.
Does a site with no forms or payments still need SSL?
Yes. Even a simple blog or informational site needs SSL, because without it browsers show a "Not Secure" label and Google ranks it lower than sites using HTTPS. Every website should have SSL installed.
Secure Your Website Today
DV SSL from 1,000 THB/year from RapidSSL, GeoTrust, DigiCert — or free Let's Encrypt for all hosting customers
View SSL Certificates