Certificate TLS / X.509
A digital document that binds a public key to a domain — the foundation of HTTPS.
Contains domain, public key, expiry, CA signature. The browser verifies the signature against its list of trusted CAs. Let's Encrypt issues free certs valid for 90 days.