What is SSL?
SSL is a way to lock the data that travels between a visitor and a website. An SSL certificate is like an ID card for the site. It enables the padlock and the https address.
What does "self-signed" mean?
Normally a trusted company called a Certificate Authority (CA) signs your certificate. That is like a school stamping your student card. Browsers trust the stamp.
A self-signed certificate is signed by you. It is like writing your own ID card and stamping it yourself. The lock still hides the data. But nobody else has checked who you are.
What happens in a browser?
Browsers do not know you, so they show a warning such as "Your connection is not private". Visitors must click through to continue. Most people will leave instead.
When is a self-signed certificate fine?
- Testing a site on your own computer.
- Private tools used only by you or your team.
- Internal servers that are not open to the public.
When should you avoid it?
- Public websites.
- Online shops or login pages.
- Anything where visitors must trust you.
For these, use a certificate from a trusted CA. Many CAs offer free ones, and many hosting accounts can issue one for you.
How to create one
You need a server with OpenSSL. OpenSSL is a free tool that makes keys and certificates.
- Connect to your server with SSH.
- Run this command:
openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout server.key -out server.crt
This makes a private key file (server.key) and a certificate file (server.crt) that last 365 days.
- Answer the questions it asks. For "Common Name", type your domain name.
- Install the two files in your web server or control panel.
.key file secret. Anyone who has it can pretend to be your site.Quick recap
- A self-signed certificate is signed by you, not by a trusted CA.
- It encrypts data, but browsers show a warning.
- Use it only for testing or private use.
- Use a trusted certificate for public websites.