It’s actually to prove that a web server belongs to (or is trusted by for delivering their content) a specific website.
qualified certificates go a step further, by proving that a web server belongs to a specific company or a real person. but that’s costly, because verification is inherently more difficult.
bjoern_tantau@swg-empire.de 4 hours ago
Nah, the point is to encrypt the traffic and tell you what you are receiving really comes from example.com and not an evil third party.
victorz@lemmy.world 4 hours ago
Ah, right. That’s the primary purpose, thank you for the reminder! 🙏