Welcome our webmaster and SEO forum
Please enjoy the forum, contribute what you can, and wind up the Moderators!
Closed Thread
Results 1 to 9 of 9

Thread: SSL Certificates

  1. #1
    Paul_KY is offline Senior Member Paul_KY is on a distinguished road
    Join Date
    Aug 2004
    Posts
    1,285

    Default SSL Certificates

    Who needs them?

    Site's that sell or sites, which promote?

    Thanks

    Paul
    "There's no such thing as impossible. It's a myth. Don't believe it."

  2. #2
    Duke Guest

    Default

    I have the option turned off in my phpnuke site because I have no idea what it is

  3. #3
    novocaine Guest

    Default SSL

    The Secure Socket Layer protocol was created by Netscape to ensure secure transactions between web servers and browsers. The protocol uses a third party, a Certificate Authority (CA), to identify one end or both end of the transactions. This is in short how it works.

    1.

    A browser requests a secure page (usually https://).
    2.

    The web server sends its public key with its certificate.
    3.

    The browser checks that the certificate was issued by a trusted party (usually a trusted root CA), that the certificate is still valid and that the certificate is related to the site contacted.
    4.

    The browser then uses the public key, to encrypt a random symmetric encryption key and sends it to the server with the encrypted URL required as well as other encrypted http data.
    5.

    The web server decrypts the symmetric encryption key using its private key and uses the symmetric key to decrypt the URL and http data.
    6.

    The web server sends back the requested html document and http data encrypted with the symmetric key.
    7.

    The browser decrypts the http data and html document using the symmetric key and displays the information
    and

    How do you know that you are dealing with the right person or rather the right web site. Well, someone has taken great length (if they are serious) to ensure that the web site owners are who they claim to be. This someone, you have to implicitly trust: you have his/her certificate loaded in your browser (a root Certificate). A certificate, contains information about the owner of the certificate, like e-mail address, owner's name, certificate usage, duration of validity, resource location or Distinguished Name (DN) which includes the Common Name (CN) (web site address or e-mail address depending of the usage) and the certificate ID of the person who certifies (signs) this information. It contains also the public key and finally a hash to ensure that the certificate has not been tampered with. As you made the choice to trust the person who signs this certificate, therefore you also trust this certificate. This is a certificate trust tree or certificate path. Usually your browser or application has already loaded the root certificate of well known Certification Authorities (CA) or root CA Certificates. The CA maintains a list of all signed certificates as well as a list of revoked certificates. A certificate is insecure until it is signed, as only a signed certificate cannot be modified. You can sign a certificate using itself, it is called a self signed certificate. All root CA certificates are self signed.
    More on http://www.tldp.org/HOWTO/SSL-Certif...HOWTO/x64.html

  4. #4
    Paul_KY is offline Senior Member Paul_KY is on a distinguished road
    Join Date
    Aug 2004
    Posts
    1,285

    Default

    So if I'm using http, rather than https, I'm fine with no SSL Cert, correct?
    "There's no such thing as impossible. It's a myth. Don't believe it."

  5. #5
    Duke Guest

    Default

    Should I be using it is really the question?

  6. #6
    novocaine Guest

    Default :)

    It's all about safety and who do you trust. I think it depends on the type of website you run.. it's your choice. Security is always GOOD

  7. #7
    Lanre Guest

    Default Re: SSL

    Quote Originally Posted by novocaine
    The Secure Socket Layer protocol was created by Netscape to ensure secure transactions between web servers and browsers. The protocol uses a third party, a Certificate Authority (CA), to identify one end or both end of the transactions. This is in short how it works.

    1.

    A browser requests a secure page (usually https://).
    2.

    The web server sends its public key with its certificate.
    3.

    The browser checks that the certificate was issued by a trusted party (usually a trusted root CA), that the certificate is still valid and that the certificate is related to the site contacted.
    4.

    The browser then uses the public key, to encrypt a random symmetric encryption key and sends it to the server with the encrypted URL required as well as other encrypted http data.
    5.

    The web server decrypts the symmetric encryption key using its private key and uses the symmetric key to decrypt the URL and http data.
    6.

    The web server sends back the requested html document and http data encrypted with the symmetric key.
    7.

    The browser decrypts the http data and html document using the symmetric key and displays the information
    and

    How do you know that you are dealing with the right person or rather the right web site. Well, someone has taken great length (if they are serious) to ensure that the web site owners are who they claim to be. This someone, you have to implicitly trust: you have his/her certificate loaded in your browser (a root Certificate). A certificate, contains information about the owner of the certificate, like e-mail address, owner's name, certificate usage, duration of validity, resource location or Distinguished Name (DN) which includes the Common Name (CN) (web site address or e-mail address depending of the usage) and the certificate ID of the person who certifies (signs) this information. It contains also the public key and finally a hash to ensure that the certificate has not been tampered with. As you made the choice to trust the person who signs this certificate, therefore you also trust this certificate. This is a certificate trust tree or certificate path. Usually your browser or application has already loaded the root certificate of well known Certification Authorities (CA) or root CA Certificates. The CA maintains a list of all signed certificates as well as a list of revoked certificates. A certificate is insecure until it is signed, as only a signed certificate cannot be modified. You can sign a certificate using itself, it is called a self signed certificate. All root CA certificates are self signed.
    More on http://www.tldp.org/HOWTO/SSL-Certif...HOWTO/x64.html
    Thanks Novo,
    This is quite informative.
    Lanre

  8. #8
    seo4ssl's Avatar
    seo4ssl is offline Junior Member seo4ssl is on a distinguished road
    Join Date
    Nov 2009
    Posts
    1

    Default

    Yea we're running it without a cert for now, it looks like. Luckily for me, the checkout process is done on Google's servers, which are running on the secure layer, so I'm not worried about customers losing their moneys at least.

    As far as stock goes, I don't think we're going to have it managed automagically, here's to hoping it's not going to be me updating it..

  9. #9
    JennyRipley's Avatar
    JennyRipley is offline Senior Member JennyRipley is on a distinguished road
    Join Date
    Nov 2009
    Posts
    110

    Default

    It depends on the type of your site,if your site needs hight security you should use SSL.

Closed Thread

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

     

Similar Threads

  1. XRamp Offers 256-Bit SSL Certificates
    By ovi in forum In The News
    Replies: 1
    Last Post: 02-16-2005, 04:11 PM

Bookmarks

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts

Search Engine Friendly URLs by vBSEO 3.6.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124