Friday, May 27, 2011

Secure Web Hosting

By Gregory Trune


What is Secure Web Hosting and SSL and what are their benefits:

The World Wide Web is not as safe as it used to be which is due to the amount of data and information online that can be read by other people. There are a large number of people called hackers who uncover secret and confidential data about the people who visit your site. It is even possible for them to obtain information such as credit card details or passwords. Many hackers are able to offer a version of your own website and use this to trick other web users. Their version of your site can be hosted on their own server. This is done to obtain details from them. It is possible to battle these people and this is why SSL or Secure Sockets Layer was created.

Since 1994 when it was developed by Netscape, the SSL has developed into a security technology that is now recognized as an standard across the world. It works in a way to ensure that a secure link between a server and a browser. All OF this adds up to making sure that any information that is passed between parties remains secure. The security can be seen the padlock emblem that appears on screen. Many e-Business companies appreciate this opportunity to safeguard the information of their customers as well as ensuring the confidentiality of any transactions that take place

The Certificate for SSL:

There is a need for the Certificates Authority (CA) to provide the SSL Certificates and this is what web servers need if they desire to use the Secure Sockets Layer protocol. A firm will be asked many different questions about their site and identity if they want to have the SSL present on their server. This is facilitated by the provision of two cryptographic keys which revolves around the Public and the Private keys. Of the two keys, the Public Key should not be a furtive. The key can be found contained in a CSR data file which hosts the date. After his, the user has to have their CSR submitted. Following this, the CA will validate the information that is contained in the CSR and the SSL certificate process. Another SSL certificate is provided with all the users details and this enables the user to use the SSL. The Private Key is then used to match the information of the SSL certificate. This process is offered to allow the web server to establish a secure link between the customer and your very own website.

Although these issues can be troublesome, customers are unable to see any of the issues and protocols. There is the provision of the key logo to their browser which guarantees a user they are covered by SSL and an encrypted session. Customers can see their details and SSL certificate by clicking on the lock icon which is provided on the screen. On the whole, SSL certificates are granted to respected and accountable individuals and companies.

Information contained within the SSL certificate includes company name, the name of your domain, the city, an actual address, pin code, state and country. There is also the addition of the expiration date when the Certificate cannot be used after. There are also other details pertaining to the Certification Authority, the firm that provides the Certificate. If you have a SSL certificate, when you attempt to connect to a secure site, this will find the SSL certificate which is used by the site. A verification process that the SSL certificate of the other site is a genuine one to be trusted and is being used by the site that it has been allocated to. Similarly, the expiration date of the other site will be examined. If at any point an error is returned, a warning message will be provided to the user.

There is no doubt that the golden padlock has been accepted by many customers. It is viewed as a symbol of trust for the site. There is little doubt that the e-Business company can use this as an ideal opportunity to encourage trust and additional expenditure from customers and also turn visitors into customers. There are numerous shopping carts or sites that take information from customers and a large percentage utilize the SLL certificates. Nevertheless, users should recall that if confidential information is sent by email, this information is not naturally secured.

Functions that are new to users:

The SSL v3 has been recently introduced and is an improved version of upon SSL v2. It has been added with SHA-1 based ciphers and provides support for certificate authentication. There were certain flaws in the SSL v2, where indistinguishable cryptographic keys were used for encryption as well as for message authentication. Moreover, the former version had no protection for the handshake, which implies a "Man-in-the-middle downgrade attack" could even go unnoticed.

Another interesting progression has been TLS (Transport Layer Security) superseding SSL. There is no doubt that TLS has been heavily influenced by SSL and is viewed as a key player in Microsoft and Netscape browsers in addition to a whole host web serving products. Today, the SLL utilizes public as well as private keys to provide an encryption service from the RSA that allows users to have a digital certificate.

Do you require an SSL Certificate:

* You will need to purchase the Secure Sockets Layer Certificate if you value privacy and expect others to trust your website and service.

There is a need for offices that have intranet usage where information is being distributed to obtain an SSL certificate.

* SSL Certificates can be a useful tool in an office if confidential data is placed on an intranet system.

* An SSL Certificate helps you to process several sensitive data including date of birth, ID numbers, address, telephone number or license number safely.

There is also a need to use SSL certificates to fully pass security and privacy requirements.

Beneficial data to consider when buying SSL Certificates:

* The Certificate Authority market is quite diverse, but it is better to purchase an SSL Certificate that meets your requirements as well as budget. You can find a number of Secure Sockets Layer Certificate in different price range. The Open Directory Project identifies 22 third parties and offers over 20 root certificates that are included into Firefox and Internet Explorer. However, due to its price, it is dominated only by a few major firms.

* Netcraft conducted a survey in June 2005 to enlist the largest vendors providing SSL Certificates. The Security Space made similar tallies in January 2007, according to which the major vendors are Equifax via its GeoTrust subsidiary (www.equifax.com), VeriSign plus through its Thawte subsidiary (www.verisign.com), GoDaddy/Starfield (www.godaddy.com), Digicert (www.digicert.com) and Comodo (www.comodo.com).

Although some variance will exist due to the way that markets are measured, is is considered that these 6 companies share roughly 95% of the entire industry. The largest firm with a market share of 72% is Verisign and the next is Comodo which contains about 18% of the market share. This is followed by Geotrust that has just under 3.5% and then Entrust who have 2.5% of the market. The last company is GoDaddy which clocks in at around 1%. The remaining firms contain about 3 to 4% on average.




About the Author:



No comments: