Subscribe:
Showing posts with label RapidSSL Wildcard. Show all posts
Showing posts with label RapidSSL Wildcard. Show all posts

Tuesday, 14 June 2011

Twitter encounters more digital certificate problems


Twitter is having trouble again with a digital certificate that secures communications to its Web site, which has been causing trouble for third-party applications that integrate with it, but the problem may have been fixed.
Some users have reported trouble in using TweetDeck, an application used to post messages to Twitter and organize other streams of messages from the micro blogging service. Users see a message saying that a SSLCertificate issued by Equifax to "*.twitter.com" has expired and/or is invalid.
The certificate apparently expired on Monday and was used for api.twitter.com, which is used by third-party applications to exchange data with the service. Later in the day on Monday, it appeared the certificate had been renewed, with a new expiry date of Aug. 15, 2011.
SSL is an encrypted protocol used to protect information exchanged between a user and a website. Browsers indicate an SSL connection by displaying a padlock.
Efforts to contact TweetDeck were unsuccessful, but Twitter staff posted on its Web site that "some users are seeing a sporadic SSL certificate issue in client apps. We're investigating. So many machines."
On July 13 Twitter posted on its status blog that "we are aware of an SSL issue on our API and are in the process of fixing it. This issue does not pose a threat to account security."
Twitter apparently knew that the certificate was close to expiring. John Adams, an operations engineer for Twitter, wrote in a Google Groups posting in May that they planned to upgrade the certificate use for api.twitter.com.
Twitter also upgraded the certificate for twitter.com to a VeriSign Class 3 EV SSL Certificate, Adams wrote. That certificate uses 256-bit AES (Advanced Encryption Standard) encryption to protect communications.

Tuesday, 7 June 2011

UCC SSL: If You Need SSL on Many different Domains



This means that buying an SSL Certificate for example dot com will not give you SSL security for anotherdomain dot com or secure.example dot com. 

Got multiple subdomains needing SSL security? 

Wildcard SSL is your best option. This solution isn't enough for those who need SSL on multiple domains. What about them? Unified Communications Certificate (UCC) SSL is the answer.

Know the Difference between Wildcard and UCC SSL

A Wildcard in the certificate's Common Name lets one certificate be used on different subdomains. For instance, the Common Name *.example dot com enables you use one wildcard certificate for www.example dot com, work.example dot com, or settings.example dot com, but not on example.net, anothername dot com, or shop.anothername dot com. 

The good thing is that UCC SSL will function just fine in the final example. UCC SSL, instead of using the Common Name field, uses the Subject Alternative Name (SAN) field on the certificate. The SAN let you add more domains that will use one UCC SSL certificate. Only one UCC SSL certificate will be enough for example dot com, secure. Example dot com, another name dot com, anothername.net, and one more dot com. Depending on your deal with the certificate provider, you are allowed to add a specific number of domains or subdomains on the certificate.

Benefits to UCC SSL

The most obvious benefit to using UCC SSL Certificates is to cut costs. If you only use a few domains, you may be fine with typical SSL certificates that cost about $150 each. But once you need five domains, you will need to come up with $750. Think how much you can save on 3 domain names when UCC SSL costs only $300 each.

Sometimes, you can get additional domains on the same certificate at $40 each. Some providers will even let you add a limited number of subdomains on the UCC SSL certificate at no charge as a bonus.

UCC SSL is good for another reason, and that's manageability. Most people will cringe at the thought of having to purchase, set up, and then renew annually several SSL certificates. It's a difficult task to whoever is supposed to manage them. Errors can be easily made when managing a number of certificates. Delays from fixing errors will cost you time and money. Just think about how that compares to worrying about just a single UCC SSL certificate. It's a whole lot easier to manage a single certificate. Errors are easily minimized.


Unlike with Wildcard Certificates, UCC SSL certificates may be used with Extended Verification (EV). In other words, visitors that view the SSL secured pages of your website will see a greed address bar on their browser. This will enhance the confidence of customers or clients when they use your website.

Are There Any Drawbacks?

Using UCC certificates does have some drawbacks. Security is the first that comes to mind. Only one private decryption key is used by all the servers that use a single UCC SSL certificate. Several servers usually host multiple domains. This means that if someone manages to compromise one of your servers and retrieve the decryption key, every on every server that uses the same certificate is also compromised.

If, for some reason, your UCC SSLCertificate is revoked, all domains will not work. That basically means that you have to close your website until you either get a new UCC certificate, or get a certificate for every single domain on your site.