|
There are many different types of certificates and many different SSL certificate features that you may need to understand in order to purchase the right SSL certificate.
The most critical distinction to make is whether you need a high assurance certificate, a low assurance certificate, or an EV certificate.
A high assurance certificate is the normal type of certificate that is issued. There are two things that must be verified before you can be issued a
high assurance certificate: ownership of the domain name and valid business registration. Both of these items are listed on the certificate so visitors
be be sure that you are who you say you are. Because it requires manual validation, high assurance certificates can take an hour to a few days to be issued.
certificate authority issues certificates in the form of a tree structure. A root certificate is the top-most certificate of the tree. All certificates below the root
certificate inherit the trustworthiness of the root certificate. Many software applications, such as web browsers, include certain root certificates that are automatically
deemed trustworthy. Any certificate signed by a trusted root certificate will also be trusted. In turn, the signed certificate can sign another certificate and it
will also be trusted as long as the browser has all of the certificates in the chain to link it up to a trusted root certificate.
Any certificate in between your certificate and the root certificate is called a chained or intermediate certificate. These must be installed to the web server with
the primary certificate for your web site so that user's browers can link your certificate to a trusted authority. Most certificate authorities use chained
certificates for security purposes and most web servers and devices support them.
The warranty that you get when you purchase an SSL certificate ($10,000, $250,000, etc...) can be misleading. It is not a warranty to the purchaser
but rather to the end users who use a site secured by an SSL certificate. Basically, if you, the purchaser, turn out to be fraudulent and a user of your
web site loses money because the certificate authority didn't properly validate you, then the certificate authority will compensate the end user.
This practically never happens! It is therefore not very important how big the warranty is when you buy an SSL certificate. Certain certificate authorities
have slightly different policies on warranties that you may wish to look into.
An SSL certificate is a special technology that helps secure a website. When a website is SSL certified, it means that all transactions and data transmissions to and from the website to the web-server are secure and encrypted.
Basically there are two types of SSL certificates – Single Root and Chained Root SSL. Single Root Certificates are generally considered to be more secure certificate and preferred over Chained Root SSL Certificates. However Chained Root SSL Certificates are also quite effective and secure since they are generally based on a Trusted Root Certificate only
Let us get to know what exactly a Chained Root SSL Certificate is.
SSL Certificates are issued by Certification Authorities (CA) who generally own their Trusted Root CA Certificate. When we say Trusted Certificate, it means a Root Certificate that is recognised and already present in all the browsers and other applications that require and accept security certificate. An example of such a CA and Trusted Root CA Certificate would be GeoTrust, which is one of the oldest CAs and owns its Trusted Root CA Certificate.
When such a CA issues an SSL certificate, it is known as a Single Root SSL Certificate. There are several other SSL Certificate Authorities that don’t own a Trusted Root CA Certificate; or if they do, they don’t wish to issue SSL certificates based on that Root Certificate. As a result the CA links up with another CA that owns a Trusted Root Certificate and issues SSL certificates on that Trusted Root Certificate.
So when the browser links with the web-server and website, it actually identifies the Chained Root SSL Certificate as originated from the Trusted Root Certificate and accepts it. Unlike the identification process of the Single Root SSL Certificate which takes less than a second, Chained Root SSL Certificates take longer time to be recognised by the browser because they have to pass through two root levels.
A CA that issues Chained Root SSL Certificates is usually not recognised by the browsers and so they have to bank on those CAs that have browser recognition. This can sometimes create a problem in the sense that if the CA with the Trusted Root CA Certificate goes defunct, the Chained Root SSL Certificates issued will automatically become invalid.
Additionally the owner of the Trusted Root CA Certificate has full authority to make any changes they wish to their certificate without intimating the Chained Root SSL Certificate issuing CA. Any such changes can directly affect the Chained Root SSL Certificate. You might also face a few issues with installing the Chained Root SSL Certificate on the web-server; it might require deeper technical knowledge.With all the setbacks, there are also certain benefits of Chained Root SSL Certificates. The first is that Chained Root SSL Certificates cost comparatively lower than the Single Root SSL Certificates. So if you don’t have the budget for a Single Root Certificate, a Chained Root Certificate can easily fulfill your requirements.
Being based on a Trusted Root CA Certificate, Chained Root SSL Certificates generally work on industry standard 128 Bit encryption and security. This makes them just as secure as Single Root SSL Certificate.
If you are a start-up e-commerce website or a comparatively smaller one looking to grow, you can definitely get started with a Chained Root SSL Certificate. Though ideally you would be looking to get a Single Root SSL Certificate as it is the best you can get for your website.
Заказ продукта безопасности
|
Trusted Root – what is that?
This is a question that might stump most people, even those who might be well acquainted with the internet.
The reason for this is that Trusted Root is not an oft used term. Trusted Root refers to Trusted Root Certificate which is related to website security.
A Root Certificate is either an unsigned public key certificate or a self-signed certificate. It is generally part of a public key infrastructure scheme. A company that owns a Root Certificate is generally called a Certification Authority because it normally has rights to issue multiple certificates based on its Root Certificate. When the Root Certificate is widely recognised and trusted, it automatically becomes a Trusted Root Certificate.
Every website that involves online transactions, either monetary or information related requires a secure way of transmitting data. This is achieved through data encryption which is also known as “Secured Socket Layer” or SSL. When a website is SSL secured, the indication for this is generally in the form of an SSL certificate.
SSL Certificates can only be issued by the Certification Authorities. As stated above, the CAs would normally own a Trusted Root CA Certificate. For an SSL certificate to be really effective, the Trusted Root CA Certificate on which it is based must be recognised and present in all web browsers.
Let us understand the reason behind this…
When a website with an SSL certificate is loaded into the web browser, it is the web browser that decided whether to accept the SSL certificate or not. For this decision, the web browser generally turns to its internal records of Trusted Root Certificates. Every browser comes with a list of Trusted Root Certificates which are pre-recorded and recognised by the browser vendor. another is chained root certificate .
If the Trusted Root CA Certificate of an SSL Certificate is present in the web browser, the SSL Certificate will be recognised and accepted by the browser. The more number of browsers in which the Trusted Root CA Certificate is present, the higher the acceptance of the SSL Certificates issued by that CA! This is known as “browser ubiquity”.
Most of the major current CAs such as VeriSign, GeoTrust, Thawte, RapidSSL, etc. can claim 99.9% browser recognition rates. This is because they have been around for a long time and have now formed relations with most browser vendors who recognise these CAs are being trustworthy and stable.
As a result, whenever the browser vendors create a new version of their browsers, they automatically include the Trusted Root CA Certificates of these CAs in the list of recognised Trusted Root Certificates.
When an SSL certificate is based on a Trusted Root CA Certificate, the website into which it is integrated becomes that much more trustworthy and secure. The stability and trustworthiness of the CA in turn carries through to the website and inspires trust in website visitors.
If you have a website for which you are looking to get an SSL certificate, you should ensure that the SSL certificate you opt for is issued by a CA that owns its Trusted Root CA Certificate. Only such an SSL certificate can provide you industry standard security.
The debate over Chained Root SSL Certificates and Single Root SSL Certificate has been waging ever since SSL Certificates came into existence. Most website owners prefer to get a Single Root SSL Certificate for their website because of the fact that such certificates provide additional benefits and have certain plus points over Chained Root SSL Certificates.
Single Root SSL Certificates are generally issued by Certification Authorities (CA) that own their Trusted Root CA Certificates. This makes Single Root SSL Certificates much more trusted and secure. On the other hand, CAs that issue Chained Root SSL Certificates may or may not own their Trusted Root CA Certificate.
Single Root SSL Certificates are preferable on account of the numerous benefits they carry. Chained Root SSL Certificates are viable only if you have a very low budget for an SSL certificate.
There are several other similar points of differentiation that give Single Root SSL Certificates an edge over Chained Root SSL Certificates. Check those out below:
Ми забезпечуемо для українських споживачів:
- Можливість придбання будь-яких цифрових сертифікатів
- Техпідтримку на українській та російській мові
- Прийом платежів за сертифікати на території України
- Видачу необхідної бухгалтерськой документації
- Прийом оплати в гривні, рублях та валюті
- Прийом документації на українській та російській мові
- Прийом документації на території України
- Експертиза наданої документації
- Верифікацію компанії з України
- Підготовка документації для сертифікаційного центру
- Відправлення документації в сертифікаційний центр
- Наши менеджери здійснять повний супровід Ваших спеціалістів
на етапі вибору, замовлення, тестування та встановлення продукта
|