Difference between revisions of "SSL FAQs"

From Support Wiki
Jump to navigation Jump to search
(40 intermediate revisions by 2 users not shown)
Line 2: Line 2:
  
 
==What is SSL?==
 
==What is SSL?==
SSL (Secure Socket Layer), commonly known as HTTPS, is a communication method for the internet which protects website visitors’ information from being stolen while it is being sent from their computer to a website. This is done by verifying the server identity and encrypting the data.
+
SSL (Secure Socket Layer), commonly known as HTTPS, is a communication method for the internet which protects website visitors’ information from being stolen or modified while it is being sent from their computer to a website. This is done by verifying the server identity and encrypting the data.
  
 
==Who can get SSL?==
 
==Who can get SSL?==
Line 8: Line 8:
  
 
==Why would I want SSL?==
 
==Why would I want SSL?==
SSL gives consumers confidence that sensitive information like their credit card numbers will not be intercepted.  Having an SSL certificate for your domain also has benefits in relation to search engine optimization and general consumer trust.  In addition, beginning in January 2017 Google will be releasing [https://security.googleblog.com/2016/09/moving-towards-more-secure-web.html Chrome version 56] which will alert users when they are on webpages that collects either credit card numbers or passwords that are not served over SSL. Eventually, Google will have a strong warning for all webpages not using the HTTPS protocol.
+
SSL gives consumers confidence that sensitive information like their credit card numbers will not be intercepted.  Having an SSL certificate for your domain also has benefits in relation to search engine optimization and general consumer trust.  In addition, in January 2017 Google released [https://security.googleblog.com/2016/09/moving-towards-more-secure-web.html Chrome version 56] which alerts users when they are on webpages that collect either credit card numbers or passwords that are not served over SSL. Eventually, Google will have a strong warning for all webpages not using the HTTPS protocol.
  
==Where do I get an SSL Certificate?==
+
==How do I get an SSL Certificate?==
Your association will need to purchase an SSL Certificate from a Certifying Authority, or ‘CA’. There are many CA’s on the web and prices for SSL Certificates vary. Once purchased, you will need to ask the CA for the SSL Certificate file which will be installed on our server by MicroNet.
+
Contact support@growthzone.com so that we can provide helpful, personalized direction in this process. Your solution is determined by which website host and which Content Management System (CMS) you have.
  
==What certificate options do I need to look for?==
+
'''SmartCMS Customers:'''
SmartCMS customers will need an SSL certificate for a single domain (i.e. your main domain). Customers not using SmartCMS will need either a wildcard certificate or two single domain certificates, one for your sub-domain and one for your main domain.
+
* SSL certificate installed by GrowthZone that covers your entire domain
 +
* Domain-level Validation
 +
* No additional SSL certificate necessary (in most cases)
 +
* One time $99 fee
  
The level of validation offered with SSL certificates, Extended, Domain and Organization validationis not critical to our configuration but is up to you and your web master.
+
'''LiveEdit Aurora customers:'''
 +
* SSL certificate installed by GrowthZone that covers your subdomain (i.e. members.yourdomain.com or business.yourdomain.com)
 +
* An additional SSL certificate is required for your main domain and will be obtained from CloudFlare.com and installed by GrowthZone unless other arrangements are made
 +
* Domain-level Validation
 +
* One time $99 fee
  
 +
'''All other customers:'''
 +
* SSL certificate will be installed that covers your subdomain (i.e. members.yourdomain.com or business.yourdomain.com)
 +
* Domain-level Validation
 +
* One time $99 fee
 +
* An additional SSL certificate must be obtained for your main domain
 +
* Recommend contacting your website host for info/cost of securing your main domain
  
==What is the cost of installing the SSL Certificate?==
+
==What certificate options are available?==
Outside the cost of an SSL Certificate, installing the SSL Certificate on our server is free.
 
  
==How do I get the SSL Certificate installed on my website?==
+
With GrowthZone Customer Service providing the install, setup and maintenance of your sub-domain SSL certificate, an understanding of the following information is not required but could be helpful overall.  
You can email your SSL Certificate file to [mailto:support@micronetonline.com support@micronetonline.com]
 
Your MicroNet contact will work with you on getting SSL in place for your website.
 
  
Once the SSL Certificate is installed, a security ‘lock’ icon is visible on popular website browsers, indicating the SSL Certificate is in place and the website is secure.
+
'''Validation levels:'''
 +
The level of validation offered with SSL certificates (Domain, Organization and Extended validation) is not critical to our configuration. The solution provided by GrowthZone will provide Domain Validation. Organization or Extended Validation provide additional information about who owns the domain, often desired by larger corporations or business in the security industry. All validation levels provide the same level of security. 
 +
 
 +
* DV (Domain Validated) where the Certificate Authority (CA) checks the right of the applicant to use a specific domain name. No company identity information is vetted and no information is displayed other than encryption information within the Secure Site Seal.
 +
 
 +
* OV (Organization Validation) where the CA checks the right of the applicant to use a specific domain name PLUS it conducts some vetting of the organization. Additional vetted company information is displayed to customers when clicking on the Secure Site Seal, giving enhanced visibility in who is behind the site and associated enhanced trust.
 +
 
 +
* EV (Extended Validation) where the Certificate Authority (CA) checks the right of the applicant to use a specific domain name PLUS it conducts a THOROUGH vetting of the organization. The issuance process of EV SSL Certificates is strictly defined in the EV Guidelines, as formally ratified by the CA/Browser forum in 2007, that specify all the steps required for a CA before issuing a certificate.
 +
 
 +
==What does it mean to "verify that my website is SSL-ready?"==
 +
 
 +
Before enabling SSL access to your site, URLs and all references on the website will need mapped from HTTP to HTTPS, which includes all internal website links, images, JavaScript, CSS and other elements.  Readiness varies on each site but is likely understood by your webmaster.
 +
 
 +
Also note, if your website has any widgets that were generated using the Internet Settings Control Panel (ISCP), they will need to be re-generated and updated on your website prior to enabling SSL.
  
 
==Noteworthy Information==
 
==Noteworthy Information==

Revision as of 23:07, 28 November 2017


What is SSL?

SSL (Secure Socket Layer), commonly known as HTTPS, is a communication method for the internet which protects website visitors’ information from being stolen or modified while it is being sent from their computer to a website. This is done by verifying the server identity and encrypting the data.

Who can get SSL?

This is available for all customer websites - both SmartCMS sites and non-SCMS sites.

Why would I want SSL?

SSL gives consumers confidence that sensitive information like their credit card numbers will not be intercepted. Having an SSL certificate for your domain also has benefits in relation to search engine optimization and general consumer trust. In addition, in January 2017 Google released Chrome version 56 which alerts users when they are on webpages that collect either credit card numbers or passwords that are not served over SSL. Eventually, Google will have a strong warning for all webpages not using the HTTPS protocol.

How do I get an SSL Certificate?

Contact support@growthzone.com so that we can provide helpful, personalized direction in this process. Your solution is determined by which website host and which Content Management System (CMS) you have.

SmartCMS Customers:

  • SSL certificate installed by GrowthZone that covers your entire domain
  • Domain-level Validation
  • No additional SSL certificate necessary (in most cases)
  • One time $99 fee

LiveEdit Aurora customers:

  • SSL certificate installed by GrowthZone that covers your subdomain (i.e. members.yourdomain.com or business.yourdomain.com)
  • An additional SSL certificate is required for your main domain and will be obtained from CloudFlare.com and installed by GrowthZone unless other arrangements are made
  • Domain-level Validation
  • One time $99 fee

All other customers:

  • SSL certificate will be installed that covers your subdomain (i.e. members.yourdomain.com or business.yourdomain.com)
  • Domain-level Validation
  • One time $99 fee
  • An additional SSL certificate must be obtained for your main domain
  • Recommend contacting your website host for info/cost of securing your main domain

What certificate options are available?

With GrowthZone Customer Service providing the install, setup and maintenance of your sub-domain SSL certificate, an understanding of the following information is not required but could be helpful overall.

Validation levels: The level of validation offered with SSL certificates (Domain, Organization and Extended validation) is not critical to our configuration. The solution provided by GrowthZone will provide Domain Validation. Organization or Extended Validation provide additional information about who owns the domain, often desired by larger corporations or business in the security industry. All validation levels provide the same level of security.

  • DV (Domain Validated) where the Certificate Authority (CA) checks the right of the applicant to use a specific domain name. No company identity information is vetted and no information is displayed other than encryption information within the Secure Site Seal.
  • OV (Organization Validation) where the CA checks the right of the applicant to use a specific domain name PLUS it conducts some vetting of the organization. Additional vetted company information is displayed to customers when clicking on the Secure Site Seal, giving enhanced visibility in who is behind the site and associated enhanced trust.
  • EV (Extended Validation) where the Certificate Authority (CA) checks the right of the applicant to use a specific domain name PLUS it conducts a THOROUGH vetting of the organization. The issuance process of EV SSL Certificates is strictly defined in the EV Guidelines, as formally ratified by the CA/Browser forum in 2007, that specify all the steps required for a CA before issuing a certificate.

What does it mean to "verify that my website is SSL-ready?"

Before enabling SSL access to your site, URLs and all references on the website will need mapped from HTTP to HTTPS, which includes all internal website links, images, JavaScript, CSS and other elements. Readiness varies on each site but is likely understood by your webmaster.

Also note, if your website has any widgets that were generated using the Internet Settings Control Panel (ISCP), they will need to be re-generated and updated on your website prior to enabling SSL.

Noteworthy Information

  • The implementation of SSL on our servers uses a technology called Server Name Identification (SNI) which is not supported by older web browsers such as Internet Explorer version 7 and older, or for any users of IE that have the Windows XP operating system.
  • SSL is designed to protect only info in transit, not to be confused with protection for the server where the website is hosted.
  • Particularly sensitive information such as credit card information being sent from your website to our server is already secured on the ChamberMaster / MemberZone servers. Having an SSL certificate for your domain will secure ALL information (not just the sensitive information) while it is being sent to our server.
  • If you purchase the eCommerce module, we strongly recommend purchasing an SSL Certificate, which will secure all information (not just sensitive information). The security 'lock' will appear in main browsers for all pages, indicating a secure site to the consumer.