Friday, May 27, 2011

An Explanation of SSL Certificates

By Gregory Trune


What is Secure Web Hosting and SSL and what are their benefits:

Internet is no longer a safe place, as information passed on through online can also be read by other people. There are a number of malevolent people known as hackers, who can easily reveal the confidential information that visitors exchange with your website. They can even obtain these types of sensitive information such as, passwords or credit card numbers. It is also possible that these hackers present a customized version of your website, which is hosted on their server to your innocent customers. In most of the cases, this is done to collect some confidential and important information from them. To fight against these hackers, a special Internet protocol called Secure Sockets Layer or SSL was created and thus secure web hosting was born .

The Secure Sockets Layer or SSL is a world wide standard security technology, which is developed by Netscape in 1994. It facilitates to establish an encrypted link between a browser and a web server. This link makes it certain that all the data, which passed between the web server and browser remains secure and private. It is recognized by a secured padlock that appears in the browser of the consumers. This protocol is used by a huge number of e-Business providers in order to shield their customer's important information as well as to ensure that the online transactions remain confidential.

SSL Certificate:

A SSL Certificate offered by the Certification Authorities (also known as CA) is essential for any web server that wishes to use the protocol of the Secure Sockets Later. Many questions will be asked about your firm and its identity and from here you can choose to run the SSL on your own web server. Two cryptographic keys are generated, one is a Public Key, one is a Private Key, both originate from the web server. The public key does not allow backdoor entry or hidden methods. The key is held in a data file with the rest of your information; this data file is called a CSR, a Certificate Signing Request. The next task will be to submit this CSR. The CA will then go about verifying the information contained within the CSR and this will undertake the SSL Certificates process. After this, another certificate from SSL will be provided and this certificate will hold all the details and information to enable SSL use. The certificate for SSL is linked by the web server to the Private Key. This means a secure and coded link will be created between the visitors' browser and your very own site.

Although these issues can be troublesome, customers are unable to see any of the issues and protocols. There is the provision of the key logo to their browser which guarantees a user they are covered by SSL and an encrypted session. Customers can see their details and SSL certificate by clicking on the lock icon which is provided on the screen. On the whole, SSL certificates are granted to respected and accountable individuals and companies.

These SSL Certificates usually contains your company name, domain name, and your address, city, pin code, state and country. It further includes the expiration date of the Certificate as well as the other details of the Certification Authority, who is in charge for the issuance of the Certificate. Whenever the browser connects to a secure site, your SSL Certificate will recover the site's SSL Certificate. It will check that the other site's SSL Certificate has been issued by a trustworthy Certification Authority and that it is being utilized by the website for which it has been allotted. It will also check the expiry date of that certificate. If the other certificate fails on any one of these checks, the browser will display a warning message to the end user.

There is no doubt that the golden padlock has been accepted by many customers. It is viewed as a symbol of trust for the site. There is little doubt that the e-Business company can use this as an ideal opportunity to encourage trust and additional expenditure from customers and also turn visitors into customers. There are numerous shopping carts or sites that take information from customers and a large percentage utilize the SLL certificates. Nevertheless, users should recall that if confidential information is sent by email, this information is not naturally secured.

The new functions:

Many users may be aware of the SSL v2 version but the SSL v3 is a much improved version. The SHA-1 based cipher has been added and this offers assistance with regards to authenticating certificates. SSL v2 had some flaws like when cryptographic keys were utilized for both the authenticating messages and encryption. In addition to this, SSL v2 did not provide any level of protection for the handshake, leaving it open to "man in the middle downgrade attacks" occurring without anyone noticing.

Another improvement has come with the Transport Layer Security taking over from the Secure Sockets Layer. The TSL has been clearly influenced by SSL and has taken many uses and styles that are synonymous with Microsoft and Netscape browsers in addition to a great number of products utilizing Web server capabilities. Today, it is common for SSL to utilize public and private key encryption that is able to provide a digital certificate.

Do you have a need for an SSL Certificate? People who appreciate privacy and ask for it from others need to buy SSL:

* If privacy of others and yourself as well as a need to have trust in your site is important, then the purchase of the SSL certificate is vital.

* If you have an online store or accept online orders through credit cards you will need an SSL Certificate in order to safeguard the confidential information of your customers.

* SSL Certificates can be a useful tool in an office if confidential data is placed on an intranet system.

* An SSL Certificate helps you to process several sensitive data including date of birth, ID numbers, address, telephone number or license number safely.

There is also a need to use SSL certificates to fully pass security and privacy requirements.

Some helpful information about purchasing SSL Certificates:

* The Certificate Authority market is quite diverse, but it is better to purchase an SSL Certificate that meets your requirements as well as budget. You can find a number of Secure Sockets Layer Certificate in different price range. The Open Directory Project identifies 22 third parties and offers over 20 root certificates that are included into Firefox and Internet Explorer. However, due to its price, it is dominated only by a few major firms.

* A survey undertaken in June of 2005 by Netcraft set out to find the names of the biggest providers of SSL certificates. This was backed up in 2007 when Security Space attempted a similar search. The top ranker was found to be Equifax, through its Geotrust arm (www.equifax.com), the next was VeriSign plus which utilized their Thawte subsidiary (www.verisign.com) as well as GoDaddy/Starfield (www.godaddy.com),, Comodo (www.comodo.com) and Digicert (www.digicert.com).

It can be seen that depending on what form of measurement is used, these six providers cover 95% of the market in this industry. The largest market share is held by Verisign with about 72% market share with Comodo coming next with around 18%. Geotrust has around 3.4% market share and GoDaddy and Entrust contain about 1% and 2.5% of the market share. The remaining providers comprise about 3 or 4% on average of the market.




About the Author:



No comments:

Post a Comment

Related Posts Plugin for WordPress, Blogger...