Secure Sockets Layer (SSL) is an encryption protocol created by Netscape to secure the exchange of information between browsers and servers.
The protocol uses a third party - the Certification Authority (CA), to identify at least one party involved in the transfer. What really happens:
- browser sends a request to a secure page (https://)
- the server sends the public key to the browser, along with the certificate
- the browser checks to see if the certificate was issued by a certification authority, if it is valid and if it was issued for that site
- then follows the actual exchange of information between browser and server, in encrypted format
