# SSL (Secure Sockets Layer)

URL: https://softwaredictionary.org/terms/ssl
Category: Security
Last updated: 2026-10-06

In short: SSL is the deprecated predecessor of TLS for encrypting connections; every version is insecure and prohibited, and today's "SSL" connections actually use TLS.

## What is SSL?

SSL, or Secure Sockets Layer, was the first widely used protocol for encrypting connections between browsers and web servers. Netscape released SSL 2.0 in 1995 and SSL 3.0 in 1996, and in 1999 the IETF standardized its successor under a new name, TLS 1.0, which was essentially SSL 3.1.

Every SSL version is now broken and prohibited. RFC 6176 banned SSL 2.0 in 2011, and RFC 7568 deprecated SSL 3.0 in 2015, forbidding its use after the POODLE attack showed that attackers could recover secrets such as cookies from its traffic. Browsers, servers and libraries have dropped it, and even the early TLS 1.0 and 1.1 were retired in 2021, leaving TLS 1.2 and TLS 1.3. So any connection described as SSL today actually runs over TLS.

The name stuck anyway. Certificates are still sold as "SSL certificates", but they are X.509 certificates that work with any TLS version: the certificate proves the server's identity, and the protocol decides how the connection is encrypted. Tools keep the old name for compatibility, such as the OpenSSL library, nginx's `ssl_certificate` setting, PostgreSQL's `sslmode` and Java's `SSLContext`, much like people still say they "dial" a phone number.

SSL vs TLS is therefore not a choice between two options: TLS is the newer version of the same protocol, and SSL is only its historical name. When someone says "enable SSL", they almost always mean enabling TLS, and the configuration should allow only TLS 1.2 and 1.3. A security scan that reports SSLv3 or SSLv2 as enabled points to a real weakness that should be fixed.

## Key takeaways

- SSL is the 1990s predecessor of TLS, created by Netscape.
- SSL 2.0 and SSL 3.0 are both prohibited by IETF RFCs.
- Connections called SSL today actually use TLS 1.2 or 1.3.
- "SSL certificates" are X.509 certificates used with TLS.
- Names such as OpenSSL and `ssl_certificate` survive for historical reasons.

## Example: An nginx HTTPS server: SSL in the names, TLS on the wire

```nginx
server {
    listen 443 ssl;
    server_name example.com;

    # "ssl" in these names is historical: the connection itself uses TLS
    ssl_certificate     /etc/letsencrypt/live/example.com/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;
    ssl_protocols       TLSv1.2 TLSv1.3;   # never SSLv2 or SSLv3
}
```

## Frequently asked questions

**What is the difference between SSL and TLS?**

TLS is the successor of SSL: the same kind of protocol, renamed when the IETF standardized it in 1999. All SSL versions are insecure and disabled, and connections today use TLS 1.2 and TLS 1.3.

**Why is it still called an SSL certificate?**

Mostly habit and marketing from the 1990s. The certificate is an X.509 certificate that proves a server's identity and is used with TLS; "TLS certificate" is the more accurate name, but both mean the same thing.

**Is SSL still used anywhere?**

Not on the modern web. Major browsers turned off SSL 3.0 by 2015 and current libraries leave it out, so only very old devices and misconfigured servers still offer it, which security scans flag as a vulnerability.

## Sources

- [RFC 6101: The Secure Sockets Layer (SSL) Protocol Version 3.0](https://www.rfc-editor.org/rfc/rfc6101.html)
- [RFC 6176: Prohibiting Secure Sockets Layer (SSL) Version 2.0](https://www.rfc-editor.org/rfc/rfc6176.html)
- [RFC 7568: Deprecating Secure Sockets Layer Version 3.0](https://www.rfc-editor.org/rfc/rfc7568.html)

---

Software Dictionary: https://softwaredictionary.org/ · https://softwaredictionary.org/llms.txt
