8 ms·
I just recently enabled SSL on my business website. It was anything but simple. First of all, I had to get a dedicated server, because a bunch of other sites w
by jakobe 13y ago
I just recently enabled SSL on my business website. It was anything but simple.
First of all, I had to get a dedicated server, because a bunch of other sites were running on the same server, and the hosting company doesn't offer additional IP addresses.
Then I wanted to get an SSL certificate. I picked Comodo, because they seemed to offer the cheapest full business validation certificate, but then accidentally bought a domain only certificate because their marketing was so confusing. Their friendly customer service walked me through a complicated process for changing my order.
To get the certificate issued, it took me a week to collect the documents they requested. I had to make sure my business was listed in the yellow pages, so they could send me an automatic phone call for verifying my number.
After every step in the process, they told me to log into their online management area, which was offline from time to time.
I had to confirm my email address by clicking a link about a dozen times. Half of the emails were missing the confirmation link.
Twice I got an email telling me my order will soon be processed, and nothing happened for two days. I had to open tickets in some online support area or send them emails to get them to continue processing.
All in all it took me a month to get SSL working. Now I understand why so many sites do not use HTTPS.
- jiggy2011 13y agoIf you just want the security of SSL, don't bother with the EV certificate. It's hugely easier.
- dangrossman 13y agoI would be willing to bet over 95% of SSL-secured sites don't have business validation certificates. Given virtually nobody visiting your site will know what that means, let alone how to check anything about the certificate you're using, it just doesn't make sense to pay extra for no benefit. A domain-validated certificate costs less while providing the same padlock icon and level of encryption, and takes just minutes to obtain -- pay, paste a CSR, click a link in an e-mail, and you have a cert.
- jakobe 13y agoIn my case, I don't care about encryption. On my website, I only offer software for download. No private data. Payment is handled by a third party. The only reason why I want to support https is so that customers can confirm who they are downloading from. Ideally, I'd like an EV certificate, but I can't afford that. So I chose a business validation cert. A domain only certificate wouldn't really confirm anything. (Also, some of my troubles would have been the same with a domain-only cert. The emails with missing links were those for domain validation, and I had to paste the CSR in the management area that was offline...)
- aleksandrm 13y agoSome if not all payment processing websites, like Stripe, still require that you use SSL to prevent MITM attacks.
- micahflee 13y agoIf you offer software to download HTTPS is a must. Otherwise any active attacker, from a kid at a coffee shop to the NSA at the ISPs, can make it so when people download your software they're also downloading your software with malware attached. Software downloads are one of the most important things to protect, and it saddens me that some websites still exist that offer software downloads that don't use HTTPS.
- ars_technician 13y agoSorry, but you are still wasting your money on a business validation certificate. A domain validation certificate is the only thing that a browser actually validates and ensures the security between you and the website. The rest is just sprinkles on top to make people feel better and to charge website owners extra money.
- mattlutze 13y ago>> so that customers can confirm who they are downloading from This would seem that he was in fact looking to provide "some sprinkles [to] make his customers feel better." Perhaps not a waste of money, then, if it provided what he was looking for?
- dpe82 13y agoSomeone should probably point out: most of your problems were related to doing full business validation from a crappy provider. Business validation is optional and doesn't enhance the transport-layer security benefits of using SSL.
- vacri 13y agoBusiness validation is what you should be using for a business site. It's actually a good thing and means that the company is interested in verifying who you are. I went through the dance with Startcom and agree with the article that the web interface has horrible workflow. However they were clearly doing their best to verify that it actually was a business they were creating an account for. For example, they ignored the phone number I gave them, and instead called on the publicly-listed phone number they found on the internet.
- powertower 13y agoExcept not even 99.9995% of your customers will know or care about the level of your SSL Cert. It really does not add anything to the equation. Just extra costs and work for you. It's been studied and pointed out that a green-bar does nothing to conversions and sales. I suggest skipping it always, but often times a higher business type will override the suggestion of whomever has to implement it and maintain it - simply because they really don't get it or don't care about the cost (which isn't really that much, but still, you have to jump through hoops getting the docs in order).
- uxp 13y agoIt's been studied and pointed out that a green-bar does nothing to conversions and sales. I'm not debating this point, but if you have some citations for this assertion, I'd love to read them. I've always heard and read otherwise. I just completed a multiple-month-long process of converting a dynamic-domain application to support SSL-friendly URIs and implementing SSL on it's web servers based entirely on the concept of adding a green bar for boosting conversions (data isn't quite in yet to verify we did anything). I would really hope that I didn't waste multiple iterations on a pipe dream.
- fmela 13y agoI had a similar experience when I purchased a software signing certificate from Comodo, exacerbated by the fact that we had accidentally transposed two adjacent digits in the phone number we gave in our listing. It ended up taking about two weeks in all to get Dun & Bradstreet to correct the typo and have Comodo verify the update, and then call us at that number. While the delay was not pleasant, I am glad that they make an effort to ensure that a legitimate organization is purchasing the certificate.
- deleted 13y ago[deleted]
- lauriswtf 13y agoYou could have just bought the $7 cert from getssl.me and it would take 2 minutes at most.
- jakobe 13y agoThey just resell Comodo certificates, so I assume I'd have the same issues with broken emails and offline managment area and emails promising "Your order is being processed right now" (the business validation stuff was only a part of the problem) Also, it makes me angry how you have all those beautifully designed landing pages everywhere, and as soon as you have ordered, you have to deal with ugly and confusing websites that barely work at all.
- glazskunrukitis 13y agoYou only receive a validation email from Comodo if you use their services.
- lauriswtf 13y agoYou could have just bought the $7 cert from getssl.me and it would take just 2 minutes at most.
- lauriswtf 13y agoYou could have just bought the $7 cert from getssl.me and it would take just 2 minutes at most.
- lauriswtf 13y agoYou could have just bought the $7 cert from getssl.me and it would take just 2 minutes at most.
- lauriswtf 13y agoYou could have just bought the $7 cert from getssl.me and it would take just 2 minutes at most.
- JoshTriplett 13y agoIf you're willing to write off users of Internet Explorer on Windows XP, you don't need a dedicated IP for SSL; you can simply use Server Name Indication (SNI).
- agwa 13y agoAndroid 2.x also doesn't support SNI.
- astrodust 13y agoAndroid 2.x is rapidly becoming the new "Windows XP".
- jakobe 13y agoBut then I'd need to support SSL for all domains hosted on the server, and this would mean getting 5 certificates instead of one.
- jbrechtel 13y agoThat's not true. Why do you think that?
- uxp 13y agoActually it is, because you'd still have a domain pointed to an IP address listening on 443, and that IP address wouldn't know how to handle the domain that is not configured to listen on 443, so it would serve the default domain (generally the first SSL-configured domain with Apache, or 'default_server' on Nginx). This means you'll be serving a certificate for your default site 'foo.com' when you requested 'bar.org', providing the user with a domain mismatch security warning. The second non-solution would be to configure every domain with self-signed certificates, but then you'd still be sending your clients an untrusted certificate. The only way to truly provide SSL on a shared host is to configure it with a UCC certificate that includes every domain you are pointing at it, or generate cheap/free certificates like StartSSL's for every unique domain and subdomain you listen for.
- lauriswtf 13y agoYou could have just bought the $7 cert from getssl.me and it would take just 2 minutes at most.