Shopping doesn't need to be secure, only the checkout portion where they actually enter the credit card and other information need to be. If you go to the checkout section then Zencard does switch to https automatically. Your customer will see a whole padlock if SSL have been implemented correctly for a particular page. If there are some elements that isn't transfered by SSL then you will see a broken padlock and a warning will come out.
SSL is a connection layer, whenever you type in https: the connection request goes to the server and request a secure connection. Once the connection have been established then anything sent over will be encryped based on the highest security setting that can be use between the two.
SSL is based on a public key encryption system. You generated 2 keys when you request an SSL certificate. The private key which you keep can decrypt anything by the public key and vice versa. When an SSL connection is establish your server send out the public key to the requesting browser so that they can use it to decrypt anything encrypted on the server by your private key. The browser then uses the public key to encrypt data it sent to the server that only the private key your possess can decrypt.
SSL is the mechanism through which negotiation and transferance of the public key occur behind the scene.
Yeah! I'm small! I'm Fluffy! Stick tongue out