Re: what is shared SSL
jpf <[email protected]> 20 Jun 2003 14:17:00 -0000
| Newsgroups | gmane.comp.web.oscommerce.laws |
|---|---|
| Message-ID | <277997478ce1ca2c257ca1a0ab5d1fb6@osCommerce-Forums> |
This message was sent from: E-Commerce Laws http://forums.oscommerce.com/viewtopic.php?p=185360#185360 ---------------------------------------------------------------- [quote="cash119uk"]Hi guys, I'm a newbiew too...Could anyone plase tell me what is "shared SSL", and is it necessary that a site have ssl enabled ? Thank u...[/quote] A "shared SSL certificate" is a certificate not owned by you but buy a 3rd party (typically your ISP or payment gateway providers) who has a domain/site wide certificate that he shairs with certain people(members, customers). A SINGLE SSL certificate is for a SINGLE web site: IE: www.store.mywebsite.com but is invalid for www.mywebsite.com or www.test.mywebsite.com or www.test.store.mywebsite.com. A Domain/shared SSL certtificate (cost musch more $$$$ than a single) is vaild for *.mywebsite.com thus it would be valid for www.mywebsite.com AND www.test.mywebsite.com, www.test.store.mywebsite.com. www.store.mywebsite.com - as many as you could fit in one server (multi servers?) Thus if you have www.mystore.com and your ISP (say www.myisp.net) has an available shaired SSL certificate (at www.myispstore.com) he may set you up as www.mystore.myispstore.com but only if you will have "purchased" the hosting package from and setup by www.myisp.net that included this feature. Second part.... SSL is not required [b](but is HIGHLY suggested)[/b] - OSC can use a single non-SSL site. However then ANY information like CREDIT CARDS NUMBER can not be send encripted and [b]could be read by ANY device[/b] [i](server, router, packet sniffer device, local networked PC on the LAN, your ISP, anyone PC who is also on the same node on the Cable DSL line as the customer is on - ie: your next door neigbour.)[/i] between the customer's PC and your website. Not may people would purchase via CREDIT CARD/ONLINE CHECK/E-CASH/PAYPAL etc... [b]with out SSL[/b]. Some payment processor/gateways have a shaired SSL to collect this information - thus you may not need your own. However people do like SSl even to collect personal info like addresses, phone numbers, email addresses... All of which if not done under SSL could be readable. You can self issue a SSL - however then a screen in IE/OPERA/NETSCAPE etc... will come up on anyone tring to access your SSL site - MS-IE AS A MIN SSL ERROR would say: Security Alert ....there is a problem with this site's security certificate. View the certificate to determine weather you want to trust the certifying authority. .... Do you want to proced? Click "View Certificate" and you get: This certificate cannot be verified up to a trusted certification authority..... (AT THIS POINT THE CUSTOMER CAN "INSTALL" THIS CERTIFICATE AS A TRUSTED SITE AND WILL NO LONGER GET THIS SSL ERROR.) Most people will get the heck out your site if they see this - there is no way around this unless you get a "trusted" SSL certificate.