Understanding SSL Protocol Security: A Complete Guide

Understanding SSL Protocol Security: A Complete Guide

By Michael Thompson

December 17, 2024 at 04:30 AM

SSL Certificates: The Essential Guide

SSL certificates automatically protect any domain correctly pointing to your Squarespace site. This security protocol prevents hackers from impersonating you or stealing visitor information.

Requirements for SSL Certificates:

  • Automatically included for Squarespace domains, third-party domains, subdomains, and predefined domain names
  • Domain must be properly connected
  • Domain names must be under 63 characters

Checking SSL Certificate Status:

  1. Visit Domains dashboard and verify "Issued" status
  2. Check SSL panel for "Active" status
  3. Visit your site to confirm certificate functionality

SSL Settings Options:

  1. Secure (Recommended):
  • Redirects all traffic to HTTPS
  • Includes HTTPS links in sitemap
  • Optimizes for SEO with HTTPS indexing
  • Requires SSL-supporting browsers
  1. HSTS Security:
  • Provides enhanced encryption
  • Prevents site spoofing
  • Eliminates "connection not private" errors
  • Recommended when using Secure setting
  1. Not Secure:
  • Allows both HTTP and HTTPS access
  • Uses HTTP links in sitemap
  • Search engines index HTTP version
  • Default for pre-October 2016 domains

Payment Security:

  • All payment pages use 128-bit SSL encryption
  • Maintains Level 1 PCI compliance
  • Secure regardless of site SSL settings

Technical Specifications:

  • Uses Let's Encrypt for DV SSL certificates
  • 2048-bit SSL encryption (except payment pages)
  • TLS 1.2 for HTTPS connections
  • 90-day certificate renewal cycle
  • Automatic certificate issuance

Benefits of SSL Protection:

  • Builds visitor trust
  • Prevents data theft
  • Improves site loading
  • Enhances SEO performance

Troubleshooting Tips:

  • Allow up to 72 hours for certificate processing
  • Check domain connection settings
  • Verify DNS records
  • Update mixed content to prevent browser warnings

Important Notes:

  • Cannot disable SSL certificates completely
  • Supports subdomains automatically
  • Login credentials always encrypted
  • Third-party SSL certificates not supported

For security issues, consult the SSL troubleshooting guide or contact support for assistance.

Related Articles

Previous Articles