Subscribe:
Showing posts with label ssl-wildcard. Show all posts
Showing posts with label ssl-wildcard. Show all posts

Tuesday, 26 July 2011

Protect Your Entire Site With The Same SSL Certificate


The Thawte Wildcard SSL Certificate allows you to secure unlimited subdomains of your main domain with a single Certificate. For example, if you have the domain abc.com, any number of subdomains will be protected by this certificate: mail.abc.com, store.abc.com, etc.. You will not have to buy separate Certificates for each new subdomain as is the case with standard certificates. This solution is ideal if you use SSL for multiple subdomains – only one certificate to install, and in many cases it is more cost-effective. Please note that all subdomains must be on the same Server.

Thawte Wildcard SSL Certificates may use an IP address to all secondary domain names. The same certificate can be used to secure all subdomains associated with a domain name, sharing one IP for all subsequent years. You can configure name based virtual hosts instead of machines.

Reasons for Choosing the Thawte Wildcard SSL Certificate:

• Encryption strength from 40 to 256 bits, according to the ability of browsers clients. 
• Issue in 2 business days, depending on the fulfillment of the requirements by the applicant.
• The ubiquity is the highest available in the browser market.
• High standards of validation, through the intervention of a trusted third party such as Thawte, which guarantees the authenticity of your company and website ownership for Certification. 
• Rigorous Verification and authentication procedures integrated (domain name and identity certificate validation). The prestige of Certificate Authority (CA) authorization. 
• Protocol Secure Socket Layer (SSL), maintaining privacy of messages exchanged between the web Server and its users. 
• Recertification without limit during the lifetime of the Certificate.
• High-strength encryption technology and high reliability of the site signature to protect your transactions.

Read more:-http://www.hostreview.com/news/110726-protect-your-entire-site-with-the-same-ssl-certificate#ixzz1TCIg1zf7

Monday, 18 July 2011

Getting snatch - What Wildcard SSL Certificate Help you?


If you are with security industry or e Commerce business you aware that SSL Certificate Reseller or provider only allow on domain to install ssl certificate. In the sense if you buy SSL Certificate for domain name xyz.com you can’t use it for abc.com domain name. Most of people have one domain name but what about that have more than one domain name. Like e commerce person have more than one domain for different types of business or have different domain and sub domain for different purpose. For that Wildcard Certificate helps to you.
When you think to buy ssl certificate for each domain name than problems come when you have to maintain all separately and renew and all other problems. But in Wildcard SSL Certificate you can install it on main server where your site is hosted. It is secure all your So, Wildcard SSL Certificate is Good news to secure unlimited subdomains as you want
What exactly is a Wildcard SSL?
We should first understand what wildcard means before going any further with wildcard certificates. A wildcard is usually represented by an asterisk (*). In computer terms, it’s a symbol that stands for substitution by any other string or character. In other words, an asterisk symbolcould mean any other word. In our case, *.example dot com is used to represent all subdomains of example dot com: mail.example dot com, user.example dot com, news.example dot com, shop.example dot com etc.
The “Common Name” field in an SSL certificate indicates the domain in which the certificate will be used. Wildcard Certificates are basically certificates with wildcards in the Common Name, like *. bigbusiness dot com. If, in the future, you choose to get a wildcard certificate, you will be asked to supply the Common Name.
Benefits to Wildcard Certificates
The most obvious benefit to using wildcard certificates is to slash in costs. Typical SSL certificates at $150 each may be fine for people who need SSL on only a few subdomains, but what about five subdomains? That’s $750! Wildcard certificates cost about $600, and if you run a big website with ten subdomains, you will save about $900. The websites of big companies will sometimes need SSL on over 30 subdomains.
Wildcard Certificates are popular for another reason – manageability. It’s a daunting task to purchase, set up, and annually renew a dozen or so SSL certificates. It’s an especially daunting task to the person managing the SSL certificates and errors may easily abound. Fixing errors will cost you time, and with websites, downtime costs a lot of money. Compare all of that hassle to having to worry about just one wildcard certificate. Managing just one certificate is a much simpler task. Errors are easily minimized.
Wildcard Certificate Drawbacks
As you may expect, there are some drawbacks to using wildcard certificates. The first among them is security. Big websites are usually run by multiple servers, and by sharing one wildcard certificate, they share a single private decryption key. Let’s say that one of the servers is compromised and a hacker gains access to the decryption key. That hacker now has the ability to read all encrypted messages that are sent to and from the server.
Let’s say the wildcard certificate is revoked. All subdomains that use the same certificate won’t be able to properly function. You will be forced to put your website on down time until you get the wildcard certificate working again, or you get new SSL certificates for every single subdomain that needs SSL security.
Finally, you should know that you cannot get wildcard certificates with Extended Validation SSL (EV). What is EV in the first place? It’s a set of stringent rules that certificate providers use when approving applications for SSL certificates. EV SSL was meant to increase public confidence in SSL. The Common Name field is not allowed to have wildcards according to EV rules. Also note that you won’t get the green address bar feature with wildcard certificates, since it only works with EV Certificates.

Sunday, 17 July 2011

UNLIMITED LICENSING AND LOWER PRICES FROM GEOTRUST


UNLIMITED LICENSING AND LOWER PRICES FROM GEOTRUST, THE #1 SSL CHOSEN BY MORE OF THE WEB'S 1 MILLION MOST POPULAR SITES

GeoTrust's world-class SSL certification is fast, easy and affordable. We now offer the best rates from one of the most experienced, reputable leaders in online security.
THREE REASONS TO CHOOSE GEOTRUST


1. It's Fast And Easy
GeoTrust makes it fast and easy to get the SSL certificate you need. Set up, use, manage and renew your SSL certificates – conveniently and efficiently.
2. We're Inexpensive And Good
·         When you need help, you'll talk to a friendly security expert, not an Internet generalist.
·         Our SSL delivers 256-bit encryption
·         We support 99%+ of browsers
·         We support 99%+ of all popular mobile devices


3. GeoTrust Has Unlimited Server Licensing
With only one certificate you can secure an unlimited number of servers, and reissues are free. If you order www.domain.com, you also get domain.com for free. Plus, if you want to buy a lot of certificates, we'll be happy to work out a flexible pricing arrangement that fits with your business
WHAT TYPE OF CERTIFICATE DO YOU NEED?

What level of validation does your site need?
1) Domain Validation
2) Organization / Business Validation
3) Extended Validation
What product is best for you?
More options?

Looking for UCC? Looking for SAN? Looking for Wildcard Certificate?
Looking for UCC? Looking for SAN? Looking for Wildcard?
START CONDUCTING SECURE ONLINE TRANSACTIONS QUICKLY, EASILY AND AFFORDABLY
QUICKSSL® PREMIUM
With QuickSSL Premium web server certificates, you can start conducting secure online transactions with confidence, quickly and cost-effectively. GeoTrust issues your QuickSSL Premium certificate in minutes, enabling up to 256-bit encryption. With QuickSSL Premium activated visitors see the padlock icon and the https:// and are assured that confidential information and transactions cannot be viewed, intercepted or altered.
CHOOSE THE CERTIFICATETHAT MATCHES THE NEEDS OF YOUR ONLINE BUSINESS
TRUE BUSINESSID
Business-class SSL. Assure your customers that your web site presents a legitimate, authenticated business with a True BusinessID certificate. These versatile and affordable certificates let your customers know that your site is trustworthy and that you take their security serious.. You also get the dynamically date stamped GeoTrust True Site Seal to display so your web site visitors will know instantly that your security is current.
MORE OPTIONS …
TRUE BUSINESSID WILDCARD
If you have numerous hostnames that need to be secured, your best choice is a True BusinessID Wildcard SSL Certificate. With this certificate you get business authentication and high levels of encryption for unlimited hostnames on an unlimited number of servers, all with one certificate. You also get the dynamically date stamped GeoTrust True Site Seal to display so your web site visitors will know instantly that your security is current.
TRUE BUSINESSID MULTI-DOMAIN (SAN) (UC)
You can secure up to 25 different domains by using the SAN multi-domain option with one GeoTrust® True BusinessID® certificate. It's perfect for securing multiple domains with a single certificate. Fully compatible with Microsoft Exchange and Microsoft Communications Servers, a GeoTrust True BusinessID® SAN certificate is ideal for unified communications or securing multiple applications on a single server.
SECURE YOUR SITE WITH THE GREEN ADDRESS BAR, INDICATING THE HIGHEST LEVEL OF ONLINE SECURITY
Web site visitors really notice when the address bar turns green in their browsers and the organization field starts to rotate between your business name and GeoTrust.
TRUE BUSINESSID WITH EV
GeoTrust® True BusinessID with EV SSL is our premium business-class SSL security product, visually confirming the highest level of authentication available among SSL certificates. The powerful visual impact of an EV SSL certificate can increase the number of completed transactions for a web site. You also get the dynamically date stamped GeoTrust True Site Seal to display so your web site visitors will know instantly that your security is current.

MORE OPTIONS …
TRUE BUSINESSID WITH EV MULTI-DOMAIN
You can secure up to 25 different domains by using the SAN multi-domain option with one GeoTrust® True BusinessID® with Extended Validation Certificate. It's perfect for securing multiple domains with a single certificate. A GeoTrust True BusinessID® with EV SAN certificate is ideal for businesses that need to protect multiple e-commerce domains.
TRUE BUSINESSID WITH EV WILDCARD
With a True BusinessID with EV Wildcard certificate, you get the impact of the green address bar in the browser plus high levels of encryption and authentication for unlimited hostnames on an unlimited number of servers, all with one certificate.


Source URL:-https://www.verisignpartnergrabandgo.com/enom/content-modules/geotrust/geotrust-demo

Thursday, 14 July 2011

Wildcard Certificates in Lync Server

Just to set a precedence up front I want to make it clear that I’m still completely against using wildcard certificates in any Lync deployments. Wildcard Certificate entries were never supported in OCS and clearly did not function.  A quick search online of the terms ‘wildcard’ and ‘Exchange’’ will produce mountains of article and forum discussions on what pitfalls can be seen in Unified Messaging scenarios as well.

So now with Lync Server Microsoft does support the use of wildcard entries in certificates, but in limited use and only when configured in certain ways.  On the surface the only mention of this huge shift in support policy within the official Lync TechNet documentation is a single statement on the Certificate Requirements for External Access page.  It states that “you can use a wildcard certificate on the Edge internal”.  Not a lot of detail there.

Lync Behavior


Before diving into wildcards it is appropriate to highlight some of the behavior of Lync Server and how some of the past pitfalls of OCS certificate configuration can be avoided simply by using the Lync wizards.

When using either the Lync Certificate Wizard or the Request-CsCertificate cmdlet Lync will automatically add additional entries to prevent creating improper certificates. (As the Certificate Wizard GUI simply executes cmdlets the behavior and results are the same regardless of which process is used.)

Throughout this article the proper term of Common Name (CN) is used to refer to what most people mistakenly call the Subject Name (SN).  Technically the Subject Name in a certificate is the entire distinguished name (e.g. CN=”Common Name”,O=Organization,L=Location,S=State,C=Country) while the Common Name is only the first entry in the entire path and is a single FQDN.

§  When the Default Type is included in the request then the server/pool FQDN is automatically used as the Common Name.  If any Subject Alternative Name (SAN Certificate) entries are defined then Lync automatically adds the certificate’s Common Name to the SAN field as well.  This is similar to what the OCS certificate wizard did to resolve issues in some environments where systems could potentially ignore the SN field and only reads the SAN field.


§  When the WebServicesInternal Type is defined in the request then Lync automatically adds the Simple URLs to the SAN which were previously defined using the Topology Builder.  Once again, because a SAN entry exists Lync will automatically duplicate the CN as another SAN entry.  Notice that the admin URL is included to provide administrators easy access to the Lync Server Control Panel (LSCP) from internal hosts.


§  When the WebServicesExternal Type is defined then Lync automatically adds the external Simple URLS to the SAN which still include the same meet and dialin entries, in addition to the Reverse Proxy URL (external.mslync.net in this example).  Additionally notice that the admin URL is omitted as one would never want to publish external access to the LSCP.


§  As an example here is what a basic server/pool certificate would look like as typically all three types (Default,WebServiceInternal, WebServciesExternal) would be assigned to the same certificate.  The Lync Standard Edition Server FQDN is the CN and also duplicated in the SAN, while all Simple URLs are included in the SAN as well as thesip entry used for client Automatic Configuration.


Wildcard Support

It is pretty clear that Lync does everything it can to make sure the server/pool FQDN is populated in the proper fields.  The following configuration requirements related to the use of wildcard certificates outline the importance of that behavior:

§  The Lync server/pool FQDN must be configured as the Common Name of the certificate.
§  The Lync server/pool FQDN must be populated as an additional SAN entry (when a SAN field is present). If no SAN is needed on the specific certificate then there is no requirement to create a SAN just to repeat the CN again.
§  Wildcard entries are not supported as the Common Name entry of a RapidSSL Wildcard.
§  Wildcards entries are supported only as a SAN entry, but only when the SAN field also includes the CN as well. (Sound familiar?)

After additional research and discussions with product and support personnel within Microsoft I have complied a list of various limitations and caveats.  As the information came from multiple sources there will be some contradiction even within these items, so let us see what happens when a wildcard certificate steps up to the plate.

§  A wildcard entry can be used in the Subject Alternative Name (SAN) field on a certificate assigned to internal or external web services on Front-End, Director or Reverse Proxy for Simple URLs.  Thus a single entry of *.contoso.com will cover the various Lync Web Services URLs like meet.contoso.com, dialin.contoso.com, etc.  Now typically there are only four of these web service URLS and most third-party certificates authorities bundle the first few SAN entries into the price of a SAN/UCC certificate (usually between 4 and 10 entries) before adding additional cost per entry.  And for certificates issued by internal Windows Enterprise CAs for internal Lync servers there is no cost associated with these.  So this flexibility has limited real-world value for internal servers, but it can reduce the cost of certificates placed on reverse proxy servers to publish the various external Simple URLs.

§  A wildcard entry can be used as the Common Name for a certificate assigned to a Lync Front-End Server/Pool.  But although this works in a pure Lync Server 2010 environment, since LCS/OCS does not support wildcards then any interop scenarios would not be supported.

Strike 1.
§  A wildcard entry can also technically be used on the external Edge certificate(s), but again only in a native Lync environment and until everyone else in the world migrates from LCS/OCS to Lync then the external interop scenarios like Federation are severely crippled. 

Strike 2.
§  A wildcard entry can be used on the internal Edge certificates (noted in the TechNet article link above) but this really has very limited value as the internal Edge certificate should only include the Edge server’s FQDN and also is typically issued by an internal Windows Enterprise CA.  So not only is there no SAN field used or required, even if there were (for load-balanced Edge arrays for example) then there is no cost associated with just adding the additional SAN entries one-by-one. Foul-tip, still Strike 2.

§  Wildcard Certificate entries are not supported by Lync Phone Edition clients. (More details in this blog article.)  This means that in most environments additional SAN entries will be required to provide the exact FQDN used by Automatic Configuration DNS records.  Only in a single-domain namespace deployment where the AD domain used on the Lync Server/Pool FQDN is the same as the SIP domain would Lync Phone Edition clients be able to sign-in.  This scenario would allow the SRV records to point directly to the pool FQDN which matches the Common Name entry.  Remember that the SRV record created in the SIP domain must point to a Host record in the same domain, it cannot point to a Host record in a different domain.  Strike 3. You’re Out!

 

Summary

Now clearly there will be times when a wildcard certificate will be very attractive in terms of cost-savings but this really only applies to large organizations or hosting environments which may have tens to hundreds of domain names to support. But since wildcard SSL Certificate entries are not supported on the external Edge interfaces then there is very limited added-value to even attempting to go that route.  As no-cost private certificates are used for internal services then there really is no compelling argument for using wildcard entries.

Overall it is great that wildcard certificate support is available in now Lync 2010, but the truth is that it will be many years before organizations can realistically take advantage of the simplified deployment and cost benefits due to massive interoperability.






Tuesday, 12 July 2011

Extended Validation SSL Certificate


Extended Validation SSL Certificates deliver a new level of trust to your web site visitors. Starting with Microsoft? Internet Explorer 7, the address bar will turn green confirming your site identity as verified by a Certification Authority (CA) according to the most rigorous industry guidelines established by the CA/Browser Forum.

One Extended Validation Certificate works for one domain or subdomain name. For multiple subdomains please consider using Wildcard SSL certificate. E.g. if you have X-Payments installed on a subdomain (e.g. http://subdomain.domain.com) while X-Cart is located on the main domain (e.g. http://www.domain.com) and you want to enable SSL for both you should buy two Extended Validation Certificates or on Wildcard SSL certificate.

Over 1/3 of your site's visitor’s use a browser made for EV SSL, including IE 7, Firefox 3, and Opera 9.5. Their browsers tell them that you are trustworthy through the presence of a green bar near the address. With one out of three people relying on the green bar to appear in their browser, what would you rather show them about how trustworthy an merchant you are?



The green address bar builds trust and makes a difference between purchasing and abandonment during checkout. People are expecting their browsers to tell them if it's safe to do business with you, and an EV SSL certificate tells them loud and clear. To enable all your visitors to fully trust you an EV SSL certificate is now required for over 1/3 of your visitors and growing.

Key features

·         Recognized by all popular browsers, 99.3%
·         A great price so you make more sales and fit more in your budget. EV Starts at $359 per year.
·         128/256 bit SSL encryption
·         Dedicated account manager + Email and Web support
·         Free priority phone support to make installation easy.
·         30 day refund policy
·         $250,000 warranty
·         Unlimited re-issuance




Pricing:-

GeoTrust True BusinessID with EV$149.00/yr.
More Info
GeoTrust True BusinessID with EV Multi 
Domain
$323.50/yr.
More Info
Secure Site Pro with EV
$1,049.00/yr.
More Info
Secure Site with EV
$699.00/yr.
More Info
SSL Web Server with EV
$459.00/yr.
More Info

Why do I need Extended Validation SSL Certificate?

·         Extended Validation SSL is the next generation of SSL Certificate - stringent verification processes developed by the CA/Browser Forum ensure your web site is visibly more trusted than with other types of SSL Certificates.

·         Maximize your sales by gaining trust - the public is being educated to look for the "Green Address Bar" as a sign of trustworthiness. Make sure you gain competitive edge by displaying this essential trust indicator.

·         Free, patent pending EV Corner of Trust logo - confirming your EV status throughout the web site (not just on secure pages). This exclusive TrustLogo allows web site visitors to obtain your credentials with a simple mouse over (not a click diverting your customer to another web site).


Why Choose a Longer Certificate Term?

·         Significant savings vs. shorter-term certificates
·         Reduced risk of a trust-eroding expired certificate on your site
·         One less thing to do or worry about next year


Source URL:-http://www.x-cart.com/extended-validation-ssl.html