» »

Kateri SSL certifikat kupiti?

Kateri SSL certifikat kupiti?

Marat ::

Odločam se za nakup SSL certifikata za spletno stran (za podjetje). Zdi se mi, da je pri teh certifikatih dosti bulšita... Torej v smislu, da ponudniki certifikatov garantirajo ne vem kakšno varnost, če kupiš kak drag certifikat, ker te pokličejo in kako drugače dodatno preverijo, da si legit (kot da social engineering ne obstaja).

Trenutno se mi zdi, da je najboljše kupiti najcenejši certifikat, ker ti nudi ravno toliko "varnosti", kot kateri koli dražji. Seveda pa dopuščam možnost, da se motim, zato me zanima še kako mnenje koga, ki ima tu več izkušenj (in ki seveda ne prodaja certifikatov).

Kaj menite o tem Comodovem najcenejšem certifikatu? https://www.namecheap.com/security/ssl-...

pegasus ::

cen1 ::

Seveda da ni vse "bullshit".. odvisno za kaj certifikat rabiš. Dražji kot je, več preverjanja se zgodi na strani organizacije ki ti bo tak certifikat izdala. Če ni nič resnega bo tudi najcenejši dovolj za securanje domene, lahko ga dobiš celo zastonj pri startssl.

Več tipov certifikatov obstaja:

What are the different types of SSL Certificates?

Over the last few years the number of organizations using SSL Certificates has increased dramatically. The applications for which SSL is being used have also expanded. For example:

Some organizations need SSL simply for confidentiality, e.g. encryption

Some organizations wish to use SSL to enhance trust in their security and identity, e.g. they want to show customers they have been vetted and are a legitimate organization

As the applications for SSL have started to become wider, three types of SSL Certificates have emerged:

Extended Validation (EV) SSL Certificates: where the Certificate Authority (CA) checks the right of the applicant to use a specific domain name PLUS it conducts a THOROUGH vetting of the organization. The issuance process of EV SSL Certificates is strictly defined in the EV Guidelines, as formally ratified by the CA/Browser forum in 2007, that specify all the steps required for a CA before issuing a certificate, and includes:

Verifying the legal, physical and operational existence of the entity

Verifying that the identity of the entity matches official records

Verifying that the entity has exclusive right to use the domain specified in the EV SSL Certificate

Verifying that the entity has properly authorized the issuance of the EV SSL Certificate

EV SSL Certificates are available for all types of businesses, including government entities and both incorporated and unincorporated businesses. A second set of guidelines, the EV Audit Guidelines, specify the criteria under which a CA needs to be successfully audited before issuing EV SSL Certificates. The audits are repeated yearly to ensure the integrity of the issuance process.

Organization Validation (OV) SSL Certificates: where the CA checks the right of the applicant to use a specific domain name PLUS it conducts some vetting of the organization. Additional vetted company information is displayed to customers when clicking on the Secure Site Seal, giving enhanced visibility in who is behind the site and associated enhanced trust.

Domain Validation (DV) SSL Certificates: where the CA checks the right of the applicant to use a specific domain name. No company identity information is vetted and no information is displayed other than encryption information within the Secure Site Seal.

Zgodovina sprememb…

  • spremenilo: cen1 ()


Vredno ogleda ...

TemaSporočilaOglediZadnje sporočilo
TemaSporočilaOglediZadnje sporočilo
»

[Opera] Unable to complete secure transaction

Oddelek: Slo-Tech
243372 (2116) pegasus
»

Izdajanje ponarejenih CA certifikatov

Oddelek: Novice / Zasebnost
338418 (6277) denial
»

Kateri SSL certifikat

Oddelek: Izdelava spletišč
234643 (4403) Poldi112
»

SSL certifikat

Oddelek: Izdelava spletišč
81525 (1381) jinzo
»

Apache server - certifikati

Oddelek: Operacijski sistemi
62101 (1950) Ezekiel

Več podobnih tem