SSL Supported Devices and Compatibility
-
When we say a device or browser supports SSL, it means the device can establish a secure TLS connection and trusts the Certificate Authority that issued your certificate. Having an SSL certificate installed is not enough — the connecting client must also recognize the root certificate at the top of your certificate's chain; otherwise, users will see a security warning even if the certificate itself is valid.
How SSL Compatibility Works — Trust Stores
Every operating system, browser, and application that supports SSL maintains a trust store — a built-in list of Certificate Authority root certificates that it considers trusted. When a browser connects to your site, it checks whether your SSL certificate can be traced back to one of the roots in its trust store. This process is called chain validation.
Different platforms maintain their own trust stores and update them independently — which is why a certificate trusted on one system is not automatically trusted on all others. GoGetSSL partners exclusively with Sectigo and DigiCert — CAs whose root certificates are included in all major trust stores.
The Role of Root and Intermediate Certificates
SSL certificates follow a three-level chain of trust: the Root CA at the top (self-signed and embedded in trust stores), an Intermediate CA in the middle (used to sign end-entity certificates while keeping the root protected), and your SSL certificate at the bottom. When a browser validates your certificate, it walks up this chain, confirming each signature. For this to succeed, your server must send the intermediate certificate alongside your SSL certificate — if it is missing, clients will fail to validate the chain even if your root CA is fully trusted.
✔ Tip: Always install the chain certificate bundle provided alongside your SSL certificate. Most installation issues involving trust errors are caused by a missing intermediate.
Platform Support and Legacy Compatibility
SSL/TLS is supported across all major desktop and mobile browsers, web servers (Apache, Nginx, IIS, LiteSpeed), mail servers and clients, and application runtimes such as Java (JRE 1.8+), Node.js, and .NET. Most modern smart devices and IoT hardware also support it, though compatibility may vary by firmware version.
Older environments are the main exception. Windows XP has an outdated root store and no SNI support; Android 2.x has a limited root store and lacks modern cipher suite support; Java runtimes below 8u101 may require manual keystore updates to trust modern certificates; and older embedded or IoT firmware may carry trust stores that are only updated through manufacturer firmware upgrades, if at all.
⚠ Note: Compatibility with legacy clients depends on the root certificates embedded in the device's trust store at the time of manufacture. If the trust store is outdated and cannot be updated, no SSL certificate will resolve the issue.
Dedicated IP vs SNI
When hosting multiple HTTPS sites on a single server, SSL certificates can be delivered via Dedicated IP (one IP per domain) or SNI — Server Name Indication (multiple certificates on one IP). SNI is the standard in virtually all modern hosting environments.
Sectigo Root CA Migration
Sectigo has transitioned to new intermediate CAs, affecting the certificate chain for all newly issued and reissued Sectigo SSL certificates. In most cases, no action is required, but environments with outdated or manually managed trust stores may need updating. For full details, see: Sectigo Public Root CA Migration.
Web Browsers
- AOL 5+
- Apple Safari 1+
- Camino 1.0+
- Firefox 1.0+
- Flock 1.0+
- Google Chrome 1+
- Konqueror (KDE)
- Konqueror 2.2.1+
- Maxthon 2+
- Microsoft WebTV
- Microsoft IE 5.01+
- Microsoft IE 7+ (Vista)
- Microsoft IE 7+ (Windows XP)
- Microsoft Edge
- Microsoft WebTV
- Mozilla Firefox 1.0+
- Mozilla Suite 1.0+
- Mozilla 0.6 +
- MSN Explorer
- Netscape Communicator 4.51+
- Opera 5+
- Red Hat Linux Konqueror
- Safari (Mac OS) 10+ and higher
- Sony Playstation
Micro Browsers /PDAs
- ACCESS NetFront Browser v3.4 +
- Access NetFront
- ACCESS NetFront™ — 3.3 and higher
- Android™ — All versions
- Apple iOS 2.0+
- AT&T
- BlackBerry® — 4.1 and higher
- Brew
- iPad™ — All versions
- iPhone® — All versions
- KDDI Openwave v6.2.0.12 +
- Kindle® — All versions
- Kyocera
- Microsoft IE Pocket PC 2003
- Microsoft IE Smartphone 2003
- Microsoft Windows CE 2003
- Microsoft IE Pocket PC 2003
- Microsoft IE Smartphone 2003
- Microsoft Windows CE 2003
- Motorola® phones
- Netfront 3.0+
- Netscape Communicator 4.51+
- Nintendo Wii
- Nokia phones
- Nokia® devices
- Nook®
- NTT Docomo
- Openwave mobile browser
- Opera 7.0+
- Opera Mini v3+
- Opera mini
- Opera Mobile 6+
- Palm / Handspring Blazer 2.0+
- Palm OS® — 6.1 and higher
- Palm Treo
- RIM BlackBerry OS
- RIM BlackBerry Tablet OS
- RIM Blackberry v4.2.1 +
- SoftBank Mobile
- Sony Netjuke audio
- Sony Netjuke audio
- Sony Playstation 3
- Sony PlayStation Portable®
- Sony-Ericsson phones
- Sprint® devices
- Sun Java Runtime® (JRE)
- Symbian OS based handsets (Levono, Nokia, Orange, Panasonic, Samsung, Siemens, Sony-Ericsson)
- TorchMobile Iris Browser
- Vodaphone
- webOS
- Windows CE
- Windows Mobile 2003+, 5+
- Windows Mobile 5 and 6**
- Windows Mobile® 2005 AKU 2 and higher
- Windows Phone 7+
- Microsoft Windows Mobile 5/6*
Server Platforms
- Apache + MOD SSL
- Apache + Raven 1.5x
- Apache + Raven
- Apache + SSLeay
- BEA WebLogic
- C2Net Stronghold
- Cobalt RaQ3/RaQ4 "Main Site"
- cPanel / WHM
- Ensim Control Panel
- HSphere
- IBM HTTP Server
- iPlanet Enterprise Server 4.1
- iPlanet Server / Sun One
- Java Web Server (Javasoft / Sun)
- Lotus Domino 4.6 and higher
- Microsoft IE Server 4.0
- Microsoft IE Server 5.0 & 6.0
- Microsoft IIS
- Microsoft ISA
- Microsoft Live Communication Server
- Netscape Enterprise/Fast Track
- Novell ConsoleOne
- O'Reilly / DWP 2.X / 3.X
- Plesk
- Stronghold 3
- Tomcat
- WebSTAR 4
- Zeus Web Server v3
Application Suites
- Adobe AIR
- IBM Web Sphere Custom Environment (WCE)
- IBM Web Sphere Micro Environment (WME)
- Microsoft Authenticode
- Mozilla Suite 1.0+
- Sea Monkey
- Sun J2EE 1.4.2_02
- Sun Java SE 1.4.2+
- Visual Basic for Applications (VBA)
Additional Applications
- Google Checkout
- Internet Explorer 7: (Vista)
- Internet Explorer 7: (XP)
- Mozilla Firefox 3.
- SeaMonkey
- Sun Java 1.4.2
Mail Servers
- Courier IMAP
- CPopper
- CPPop (cPanel mail server) and other stunnel based mail servers
- Exchange 5 / 2000 / 2003 (Outlook Web Access)
- IPswitch IMAIL
- Postfix
Document Security Platforms
- Microsoft Office(Word, Excel, Powerpoint, Access, InfoPath)
- Microsft Outlook 2013/2010/2007/2003, Windows Live Mail, Mozilla Thunderbird, MAC OS X Mail, Apple Mail, Eudora, iOS, Android and more.
Email Clients (S/MIME)
- Lotus Notes
- Mail.app (Mac OS X)
- Microsoft Outlook 99+
- Microsoft / Windows Mail 1.0+ (Vista)
- Microsoft Entourage (OS/X)
- Microsoft Outlook 99+
- Microsoft Outlook Express 5+
- Mozilla Thunderbird 1.0+
- Mulberry Email 3.1.6+
- Netscape Communicator 4.51+
- Qualcomm Eudora 6.2+
- The Bat 1+
- Microsoft Outlook 99+