Free Ssl Certificate



             


Saturday, January 31, 2009

SSL Certificates Requirement Of Online Booking Sites

Customers are concerned about their safety and they look for the pad-lock icon at the bottom right of you browser.

Why would a website with online bookings need SSL?

An SSL certificate ensures that all data passed between the web server and browsers will remain private and confidential. SSL is an industry standard and is used by millions of websites to protect customers` online transactions and their valuable information.

• SSL certificates helps customers to make fast decisions and they are more likely to make an online booking as it develops trust between you and your visitors.
• To meet privacy, security and safety standards and to protect personal and sensitive data.
• Secured Socket Layer helps in increased visibility and accountability of your company.
• SSL Certificates are the most preferred method to secure credit card transactions and other sensitive data.
• SSL ensures the security of your credit card information when your customers book online.
• SSL makes your customers' information secure and safe from third parties.
• SSL encrypts your customers' name, credit card number and expiry date before they transmit over the Internet, which ensures the security of payment made for online bookings.
• SSL on your website shows your concern towards your customers' safety, which builds a positive image and goodwill.

Consequences of not deploying an SSL Certificate on a online bookings website -

Before making any online booking visitors check the availability of SSL, which can be proved through

• The padlock symbol at the bottom line of your browser
• URL address shown at the top will begin with an https://
• Checking the File and then Properties of your website that will confirm that your browser and the website share the same security attributes.

Protecting your valuable customers' credit card and personal information is our number one priority which can only be done through SLS certificate, If you will not value your customer's security it may result into -

• Your prospective customers will go to your Competitors and do their bookings.
• Hackers and criminals may track the valuable information.
• Your prospective customers may loose confidence on you which can harm your goodwill.
• It may decrease your visitor conversion rates and may effect your over all profitability

www.sslgenie.com the Trusted First Global Certification authority, in India, having the highest level of security, 256 bits. SSLGenie sells the cost effective SSL at just $14.95 per year

Labels: , , , ,

Saturday, July 5, 2008

Digital Certificates and Secure Web Access


Digital Certificates and Secure Web Access

Introduction

This paper describes the use of Digital Certificates as a mechanism for strongly authenticating users to web sites where identity information is required. Before the advent of digital certificates the only option for authenticating users to a site was to assign a username and password. Digital certificates on the other hand provide for much more robust access control and have a number of benefits over username and password.

Username and password authentication

Using username and password the process is generally as follows: each time a user wishes to access a web service the user navigates to the site and authenticate themselves to the application using unique username and password. This data is passed to the server (hopefully in an encrypted form), the application looks up the username and the password (or a representation of the password) in some form of access control list and provided the information matches the user is granted access.

This method has some obvious limitations:

* The username and password are passed over the web (encrypted or unencrypted) with the typical security concerns of interception.
* The systems administrator normally has unrestricted access to all usernames and passwords with associated security and liability concerns for the service provider (especially with confidential data)
* The user needs to remember as many usernames and passwords as are required by their applications leading to inevitable support issues to recover lost access data

Digital Certificate Authentication

The typical digital certificate web access process is:

The user navigates to the website. Before allowing access it checks the certificate against the access database. The user enters the password locally to confirming their access right to the certificate and is allowed to the website.

Benefits of certificates over username and password:

* General security is enhanced: the user needs both the certificate itself and the password to the certificate to gain access.
* The password is never passed over the web, not even during account set-up.
* At no stage do systems administrators have access to user passwords.
* The certificate can electronically sign data on the website with the benefit of non-repudiation.
* The user uses one digital identity with one password to access a range of applications (reduces passwords to remember).

Implementing Digital Certificates

All major web servers support client authentication via certificates. An SSL certificate on the web server (to support https) enables configuration of client authentication and only requires specification of the access rights for each directory served by the web server. Amend the web application to support client authentication by certificates. If any code was developed to handle user name and password, then the certificate credentials can be looked up in an access control list in just the same way. Client certificates are issued via a Public Key Infrastructure (PKI) You can choose implement your own or use the services of a Managed Service Provider such as Diginus Ltd.

Wider Use

Once customers or employees have digital certificates, the same certificates can be used to digitally sign email, PDF and web forms and Microsoft Word documents. With a few small steps a corporate website can be transformed into the centre of a powerful web services infrastructure, with single sign on to multiple web applications, signed email and forms data exchange, all the time knowing exactly who is accessing the resources and data.

Jonathan Gay BA(hons) CISA MBCS, is an IS Security professional specialising in identity management and Public Key Infrastructure (PKI) related matters. Jonathan works for Diginus Ltd the e-identity solutions company.

You can contact Jonathan via the Diginus Ltd web site www.diginus.com

Labels: , , , ,

Friday, May 23, 2008

Web SSL Certificate Unleashed

Today, Internet is not a very safe place. Information transmitted through online sometimes read by other people. There are many ways that malicious people (known as crackers) can learn the information visitors are exchanging with your website, and obtain sensitive information (for example, passwords or credit card numbers). It could also be possible that they presented to unaware customers a modified version of your website hosted on their server, in order to collect some important information from them.

In order to fight this, a special Internet protocol called SSL (Secure Sockets Layer was created (when speaking of viewing Web pages over SSL, often the term HTTPS is used).

SSL is a global standard security technology developed by Netscape in 1994. SSL is all about encryption. It creates an encrypted link between a web server and a web browser. The link ensures that all data passed between the web server and browser remains private and secure and is recognized by millions of consumers by a secure padlock, which appears in their browser.

The SSL protocol is used by millions of e-Business providers to protect their customers ensuring their online transactions remain confidential. In order to be able to use the SSL protocol, a web server requires the use of an SSL Certificates are provided by Certification Authorities (CA) who in most cases also offers additional products and services to aid e-Businesses to demonstrate that they are trustworthy. Consumers have grown to associate the 'golden padlock', that appears within their browser display, as an indication of trust in the web site. This simple fact allows e-Business providers an opportunity to leverage that increased trust level to turn visitors into paying customers - so long as you know which type to choose.

SSL certificates are generally used with ecommerce shopping carts, or anywhere you want to collect information from a user securely on your website. If you use a secure server certificate with a form; and that form emails the results to you; keep in mind that the email is not secure.

Online transactions are not considered to be safe by most of the users. With the advent of hacking incidents, and unauthorized sharing of personal data with third parties, the users are even more careful about making online transactions. So for businesses which have ecommerce presence or have corporate intranet where the users and company’s data security is of paramount importance, the most significant way is SSL certificate.

You would require a Web SSL Certificate, if:
• You have an online store or accept online orders and credit cards.
• Your business partners log in to confidential information on an extranet
• You have offices that share confidential information over an intranet.
• You process sensitive data such as address, birth date, license, or ID numbers.
• You need to comply with privacy and security requirements.
• You value privacy and expect others to trust you.

Although the certificate authority market is quite diverse you purchase the same according to your need and budget; there are many offerings in different price ranges, with the Open Directory Project identifying 22 third parties offering the service and more than 20 root certificates bundled into Internet Explorer and Firefox—it is dominated by a few major firms.

According to a June 2005 survey from Netcraft and similar January 2007 tallies from Security Space, the largest vendors are: VeriSign plus its Thawte subsidiary (www.verisign.com), Equifax via its GeoTrust subsidiary (www.equifax.com), Comodo (www.comodo.com), GoDaddy/Starfield (www.godaddy.com), Entrust.net (entrust.net), and Digicert (www.digicert.com). Together these six have approx 95% of the market, depending on the measurement methodology, while Verisign Still holds the largest market share of 72%, While comodo approx 18%, Geotrust 3.43%, Entrust approx 2.5 %, GoDaddy approx 1% and rest about 3 to 4%.

Although there is no functional difference between the SSL certificates issued by these recognized CAs. Vendors do establish product distinctions through a variety of added features and in the level of company validation.

As with most services, competition has proven beneficial for Web site operators, with the abundance of vendors pushing costs for business-class certificates down. Given their potential abuse by phishers and scam artists, businesses should avoid using the bargain basement, domain-only products, while those wishing to provide the highest level of security to their users should consider the new EV certificates.

Shakir Husein is the CEO of Dynamic Intel. Dynamic specializes in secured ecommerce solutions and content management systems. More articles on ecommerce and CMS can be accessed at Pacific Articles .

Labels: , , , , , , ,