Skip to main content
Support
0
Contact us
Nederlands
Deutsch
Español
Dedicated serversFlexible VPSCloud TechnologyColocationChallenges in ITSectorsCareers
Cloud Compute

With Cloud Compute, you have access anytime and anywhere to a portal through which you can configure your entire IT environment from wherever you are in the world.

Cloud Storage

Reliable access to your files, infrastructure, and applications at all times – with no interruptions or delays. At Worldstream, we offer a variety of storage solutions.

Flexible cloud icon
Flexible cloud
Private cloud icon
Private cloud
Bare metal icon
Bare Metal Compute
Hollow cube icon
Object storage
Hollow cube icon
File storage
Block storage icon
Block storage
Backup storage icon
Backup storage
Need support?

With experienced engineers and an average response time track record on 7 minutes, you can expect a solid technical support solution in next to no time.

All Servers

Choose your Dedicated Server now. Custom or Instant Delivery. Powerhouse servers built for your use case.

Use Cases

Whatever your use case, we’re here to help you find the ideal solution.

Deal servers icon
Deals
AMD servers icon
AMD Processors
AI servers icon
Intel Processors
Hollow cube icon
Virtualisation, Containerisation and Orchestration
Hollow cube icon
Websites and Applications
Hollow cube icon
Gaming and Streaming Infrastructure

24/7/365 support with an average response time of just 7 minutes. Thanks to our own data centers, our engineers can go directly to your server for fast, hands-on assistance. Email or call us anytime.

Smart outsourcing

Some IT creates added value, while other types are supportive. Use that as a starting point for outsourcing.

Cost Efficiency

Complete IT packages may seem like the safe option, but when you consider the costs, other choices often make more sense.

IT flexibility & control

Outsourcing doesn’t mean losing control; it actually provides more flexibility and control.

Cloud repatriation

The cloud is not a final destination: You should continuously evaluate and adjust your cloud environment as needs evolve.

Financial services
Logistics & Transportation
Retail & E-commerce
Media & Entertainment
Tech & Software Development
Security
Managed Service Providers
Need support?

With experienced engineers and an average response time track record on 7 minutes, you can expect a solid technical support solution in next to no time.

Chat with usContact us
About WorldstreamAbout the technologyCasesKnowledge base
About usMeet the teamJobsBecome a resellerCertificationsOur data centersOur networkDDoS ProtectionAMD EPYC serversTechnology PartnersOperating SystemsAll casesEasyTerraDutch Drone CompanyPerfGridArticlesFAQNews and BlogsProducts and Services
Contact us

Call +31 (0) 174 – 712 117

Industriestraat 53, Naaldwijk

Nederlands
Deutsch
Español
0
Dedicated serversFlexible VPSCloud TechnologyColocationChallenges in ITSectorsCareersAbout WorldstreamAbout the technologyCasesKnowledge baseMy Worldstream
Contact
Support
NederlandsDeutschEspañol
  1. HomeHome
  2. Knowledge Base
  3. Security
  4. How SSL/TLS certificates work

How SSL/TLS certificates work

Applies to General security concept, any serverAudience Technical evaluator, developerLast reviewed September 2026

Quick answer

A TLS certificate proves a server's identity to a connecting client and enables encrypted communication between them. It's trusted because it's signed by a Certificate Authority whose own certificate browsers and operating systems already trust, forming a chain up to a trusted root. A self-signed certificate encrypts the connection just as well but breaks that chain of trust, which is why browsers warn about it.

On this page
  • What a certificate actually does
  • The chain of trust
  • Self-signed vs. CA-issued certificates
  • Shorter certificate lifetimes and automated renewal

What a certificate actually does

A TLS certificate does two jobs at once. It proves identity: the certificate states which domain it belongs to, and the private key that matches it is held only by the legitimate server, so a client connecting to that domain can be confident it's actually talking to the right server and not something impersonating it. And it enables encryption: the certificate carries the public key half of a key pair used to set up an encrypted connection, so everything exchanged afterwards is unreadable to anyone intercepting the traffic in between.

Both matter together. Encryption without identity verification would stop eavesdropping but not impersonation, since anyone could generate a key pair and encrypt a connection while still pretending to be someone else. The identity proof is what closes that gap.

The chain of trust

A certificate's claim to represent a given domain isn't taken on its own word. It's backed by a signature from a Certificate Authority (CA), an organisation that verified the certificate applicant controls that domain before signing. The CA's own certificate is, in turn, one that browsers and operating systems ship already trusting, as part of a built-in list of trusted root certificates. Often there's an intermediate certificate in between the root and your server's certificate, so the full chain runs from your certificate, up through one or more intermediates, to a root that's already trusted out of the box.

When a browser connects to a server, it checks this whole chain: is the server's certificate validly signed by the intermediate, is the intermediate validly signed by a trusted root, and does the domain in the certificate match the domain being visited. If every link holds, the connection proceeds without a warning. If any link is missing, expired, or doesn't match, the browser flags it.

Self-signed vs. CA-issued certificates

A self-signed certificate is one where the server signs its own certificate instead of a CA signing it. Technically, it still enables encryption exactly as well as a CA-issued one. What it doesn't provide is the identity proof: there's no independent party vouching that the certificate actually belongs to who it claims to, so nothing in the chain connects back to a trusted root. Browsers respond to that by warning the visitor rather than connecting silently.

That makes self-signed certificates a reasonable choice for internal tools, local development, or testing, situations where you already know and trust the server and the warning is just noise. It's not a reasonable choice for anything public-facing, where visitors have no independent way to know whether the server they've connected to is genuine, and being trained to click through a security warning is exactly the habit that makes phishing sites work.

Shorter certificate lifetimes and automated renewal

Certificate validity periods have been shrinking industry-wide for years, down from the multi-year certificates once common to periods measured in months. Shorter lifetimes limit how long a compromised or wrongly issued certificate stays valid before it has to be renewed, and force the renewal process to actually get exercised regularly rather than being something nobody's touched in years by the time it matters.

The practical consequence is that manually renewing a certificate every year or two, workable when lifetimes were long, doesn't scale to lifetimes measured in weeks or months. That's why automated issuance and renewal, using the ACME protocol that services like Let's Encrypt are built on, has become the default approach rather than an optional convenience. An ACME client on the server (or in front of it) requests a certificate, proves control of the domain automatically, and renews it again well before expiry, without anyone needing to remember to do it by hand.

Related articles

  • Exposing services with Ingress and automatic TLS via cert-manager
  • Choosing a control panel: cPanel vs. DirectAdmin vs. no panel
Was this article helpful?

Solid IT. No Surprises

Sparring partner for IT maturity
Eliminating barriers so you can run
Predictable and transparant costs

Contact

  • Industriestraat 53, Naaldwijk
  • Payment Methods
  • Abuse
  • Developers Resources
  • Network Operations Center
  • About us
  • Meet the team
  • Jobs
  • Become a reseller
  • Certifications
  • Our data centers
  • Our network
  • DDoS Protection
  • AMD EPYC servers
  • Technology Partners
  • Operating Systems
  • Overview
  • FAQ
  • Cases
  • News & Blogs
  • Use Cases
Nederlands
Deutsch
Español
Nederlands
Deutsch
Español
  • Legal
  • Disclosure