Find out what Secure Sockets Layer is and how it can benefit you:
The World Wide Web is not as safe as it used to be which is due to the amount of data and information online that can be read by other people. There are a large number of people called hackers who uncover secret and confidential data about the people who visit your site. It is even possible for them to obtain information such as credit card details or passwords. Many hackers are able to offer a version of your own website and use this to trick other web users. Their version of your site can be hosted on their own server. This is done to obtain details from them. It is possible to battle these people and this is why SSL or Secure Sockets Layer was created.
The Secure Sockets Layer or SSL is a world wide standard security technology, which is developed by Netscape in 1994. It facilitates to establish an encrypted link between a browser and a web server. This link makes it certain that all the data, which passed between the web server and browser remains secure and private. It is recognized by a secured padlock that appears in the browser of the consumers. This protocol is used by a huge number of e-Business providers in order to shield their customer’s important information as well as to ensure that the online transactions remain confidential.
The Certificate for SSL:
A SSL Certificate offered by the Certification Authorities (also known as CA) is essential for any web server that wishes to use the protocol of the Secure Sockets Later. Many questions will be asked about your firm and its identity and from here you can choose to run the SSL on your own web server. Two cryptographic keys are generated, one is a Public Key, one is a Private Key, both originate from the web server. The public key does not allow backdoor entry or hidden methods. The key is held in a data file with the rest of your information; this data file is called a CSR, a Certificate Signing Request. The next task will be to submit this CSR. The CA will then go about verifying the information contained within the CSR and this will undertake the SSL Certificates process. After this, another certificate from SSL will be provided and this certificate will hold all the details and information to enable SSL use. The certificate for SSL is linked by the web server to the Private Key. This means a secure and coded link will be created between the visitors’ browser and your very own site.
None of these actions are witnessed by the visitor. They will be able to see they key symbol that will inform them that SSL encryption is providing a level of protection for them. If they wish to find out more details about the SSL certificate they can click on the lock icon which can be found in the right hand bottom corner of their screen. It is usually with people who can be held accountable and firms who are legally registered that these certificates are provided to.
These SSL Certificates usually contains your company name, domain name, and your address, city, pin code, state and country. It further includes the expiration date of the Certificate as well as the other details of the Certification Authority, who is in charge for the issuance of the Certificate. Whenever the browser connects to a secure site, your SSL Certificate will recover the site’s SSL Certificate. It will check that the other site’s SSL Certificate has been issued by a trustworthy Certification Authority and that it is being utilized by the website for which it has been allotted. It will also check the expiry date of that certificate. If the other certificate fails on any one of these checks, the browser will display a warning message to the end user.
The consumers are now much more comfortable with the golden padlock, which appears within their browser display. It is now considered as an indication of trust in the web site. In fact, this simple fact gives an e-Business provider an opportunity to influence the increased trust level in order to transform visitors into paying customers. All kinds of ecommerce shopping carts and sites that allow you to collect secure information on your website use SSL Certificates. However, it is also essential to keep in mind that while you use a secure server certificate with a form and get the result emailed to you, the email is not secure at all.
The new functions:
The SSL v3 has been recently introduced and is an improved version of upon SSL v2. It has been added with SHA-1 based ciphers and provides support for certificate authentication. There were certain flaws in the SSL v2, where indistinguishable cryptographic keys were used for encryption as well as for message authentication. Moreover, the former version had no protection for the handshake, which implies a “Man-in-the-middle downgrade attack” could even go unnoticed.
Furthermore, the Secure Sockets Layer has been recently been succeeded by Transport Layer Security TLS. This TLS is based itself on SSL and has been incorporated as an integral part of Netscape and Microsoft browsers as well as of most of the Web server products. In present days, the Secure Sockets Layer uses private and public key encryption system from RSA that also includes the utilization of a digital certificate.
Do you require an SSL Certificate:
* If privacy of others and yourself as well as a need to have trust in your site is important, then the purchase of the SSL certificate is vital.
* Those who have online shopping facilities and accept credit cards require the SSL certificate to provide a level of security about customer information.
* It is also advisable to get an SSL Certificate in case you have offices, which share confidential information over an intranet.
For businesses that have a number of partners who share and provide information on an extranet system, having an SSL certificate is able to offer more protection from hackers.
* If anyone in your firm utilizes an extranet, the SSL certificate is an additional layer of security from those wanting to hack your site.
Some helpful information about purchasing SSL Certificates:
* The Certificate Authority market is quite diverse, but it is better to purchase an SSL Certificate that meets your requirements as well as budget. You can find a number of Secure Sockets Layer Certificate in different price range. The Open Directory Project identifies 22 third parties and offers over 20 root certificates that are included into Firefox and Internet Explorer. However, due to its price, it is dominated only by a few major firms.
* Netcraft conducted a survey in June 2005 to enlist the largest vendors providing SSL Certificates. The Security Space made similar tallies in January 2007, according to which the major vendors are Equifax via its GeoTrust subsidiary (www.equifax.com), VeriSign plus through its Thawte subsidiary (www.verisign.com), GoDaddy/Starfield (www.godaddy.com), Digicert (www.digicert.com) and Comodo (www.comodo.com).
It can be seen that depending on what form of measurement is used, these six providers cover 95% of the market in this industry. The largest market share is held by Verisign with about 72% market share with Comodo coming next with around 18%. Geotrust has around 3.4% market share and GoDaddy and Entrust contain about 1% and 2.5% of the market share. The remaining providers comprise about 3 or 4% on average of the market.
Gregory Trune is a staff writer for WebHostingMadness.com and web hosting industry blogger. Visit WebHostingMadness.com to read his reviews and ratings of the top web hosting companies each month.