Showing posts with label Thawte SSL. Show all posts
Showing posts with label Thawte SSL. Show all posts

Monday, 24 April 2017

SSL Certificate for e-Commerce portal

The phenomenon of online shopping has been spreading across the globe with a growing number of organizations putting their wares on sale online. Online shopping is one avenue that is convenient for the shopper and cost effective for the manufacturer. While the medium is effective, it is also vulnerable to data theft and online attacks. hence the necessity for SSL certificate for e-Commerce portal,to  protect customer data and win their trust. The discussions around making SSL compulsory for e-Commerce has been growing every day and sooner or later online shops will have to comply with SSL validations. Search giants like Google have been actively endorsing SSL validation and have started tagging HTTP websites as “unsecured” since the beginning of 2017. To stay relevant and competitive in a tough market it is important to get an SSL certificate.



If you do not store any financial information you may not need an SSL certificate, however this is unheard of in the e-Commerce arena. Every online shop either stores or needs sensitive data to process payments; this makes SSL an absolute necessity for online stores. Here is a list of things that may negatively affect you if you are an online store and do not have an SSL validation (or is still an HTTP website):

Why SSL certificate for e-Commerce portal

• Online customers may lose trust in you because chrome tags you as “unsecured” for sensitive data
• Your online search ranking may fall thus leading to drop in online traffic and stuck inventory
• It means you do not have data encryption and attackers can steal or divert information from your website
• Anti-online entities may “spoof” your store because there is no registration of you being the real owner of the domain or manufacturer of the good and services sold on your website
• You are a sitting duck for an attacker who may simple include a code in your website to divert customer’s email address, social media information, or other online account for malicious activities
• The lack of SSL makes you vulnerable to theft of personal or financial data stored on your server
• In an event that your website is under attack, there can be public and or potential financial backlash
SSL stands for Secure Sockets Layer, and is the industry standard when it comes to safe and secure online transactions between websites and users. The PCI DSS makes it mandatory for online shopping websites to have a SSL certification. PCI DSS stands for Payment Card Industry Data Security Standard that makes websites that process, store or transmit credit card information maintain a secure environment.

Depending on the business you can decide on the level of validation you require. There are three types – Domain validation (this covers encryption only), Organizational validation (a bit costlier than domain validation but includes Authentication in its coverage), and finally Extended Validation ( an EV  SSL certificate for e-Commerce portal is a must for Banks and eCommerce businesses). Similarly, depending on the complexity of the website you can decide on the type of certification you need. A simple Single-name SSL certificate will enable you to provide encryption and validation for users and cover one domain or server. A single SSL Wildcard Certificate can secure all related (unlimited number of) first-level subdomains of the principal domain, thus eliminating the need of buying an SSL certification for each of them. The more complex and vast certification is the SAN certificates (also called UC or multi-domain certificates) that uses Subject Alternative Names to secure a certain number of domains, sites, and subdomains with one certificate.
To get a free trial certificate for your e-Commerce portal, kindly visit https.in

Tuesday, 11 April 2017

BENEFITS OF WILDCARD SSL CERTIFICATE

The merits of switching from HTTP (or Hyper Text Transfer Protocol) to HTTPS (or HTTP Secure) are limitless however this can be a daunting task for new company that decides to have multiple subdomains of a single domain. Wildcard SSL Certificate are proving to be a boon for such websites saving them time and costs.
Typically, organizations resort to getting the Secure Sockets Layer (SSL) certification for their domains to ensure data protection and to restore faith in consumers’ mind. SSL is a standard security technology that enables organizations to establish an encrypted link between a web server and a client. This makes it impossible for attackers to intercept the data flow (between a web server and a client) and use the information. SSL is an absolute necessity for e-commerce or for organizations that collect sensitive data.


A Website is an organization’s face with the consumers – a very commonly accessed touch-point. The design, page layout, security features such as the SSL certification of the websites is a reflection of the company’s persona. Most organizations know this and dedicate a lot of efforts on the upkeep, it is therefore important that companies have a website that assures the customers security. A growing trend in the recent past has been getting the SSL certification. According to published reports, the number of organizations migrating from an HTTP website to a HTTPS website has doubled in just two years. This single touch-point often has several sub-layers that demand equal security.
A single Wildcard SSL Certificate can secure all related (unlimited number of) first-level subdomains of the principal domain, thus eliminating the need of buying an SSL certification for each of them. It lets you specify additional host names such as email addresses, IP addresses, URLs, DNS names etc. to be protected by a single certificate. In a nutshell, using a Wildcard SSL Certificate you can secure unlimited sub domains on a single domain name and the base domain for as little as 100 USD a year.
There is a borderline difference between SAN certificates and Wildcard SSL certificates. According to the OpenSRS blog, a wildcard certificate allows for unlimited subdomains to be protected with a single certificate. For example, you could use a wildcard certificate for the domain name opensrs.com and that cert would also work for mail.opensrs.com, ftp.opensrs.com and any other subdomain. The wildcard refers to the fact that the cert is provisioned for *.opensrs.com. A SAN certificate allows for multiple domain names to be protected with a single certificate. For example, you could get a certificate for opensrs.com, and then add more SAN values to have the same certificate protect opensrs.org, opensrs.net and even tucows.com.
Wildcard SSL Certificates not only save you costs while securing unlimited sub-domains, they also make the things easier to manage. If you have say 15 different SSL certificates, deploying them will be a hassle even with a managed interface. Further you will have to repeat the exercise at every renewal, thus blocking a lot of your resources.
The only drawback of Wildcard SSL Certificates is that since it has one common private key across all servers, one server being compromised can make others vulnerable to the threat. However this is very unlikely to happen given the complexity of the encryption.
You can visit Here if you would like to know more about Wildcard SSL Certificate.

Tuesday, 28 March 2017

SSL to rank better in 2017




Google has been actively endorsing SSL certification since 2014. In their official webmasters blog titled, “HTTPS as a ranking signal”, which was published in August 2014, they had recommended HTTPS encryption for all. The blog also states that, “Security is a top priority for Google. We invest a lot in making sure that our services use industry-leading security, like strong HTTPS encryption by default…”, adding further that, “For these reasons, over the past few months we’ve been running tests taking into account whether sites use secure, encrypted connections as a signal in our search ranking algorithms…” This made it clear that websites with SSL certificate will have an advantage for SEO ranking. In 2015, Google’s Gary Illes made a statement that “HTTPS May Break Ties Between Two Equal Search Results” This pushed a lot of digital marketers towards SSL products and towards switching form HTTP toHTTPS. 



Again in 2016, Google announced that “Beginning in January 2017 (Chrome 56), we’ll mark HTTP pages that collect passwords or credit cards as non-secure, as part of a long-term plan to mark all HTTP sites as non-secure”. This essentially means if your website is not SSL certified, Chrome users will get a notification that they are on a “non-secure” website – this can negatively impact your business and customer perception. According to Google, “A substantial portion of web traffic has transitioned to HTTPS so far, and HTTPS usage is consistently increasing. We recently hit a milestone with more than half of Chrome desktop page loads now served over HTTPS. In addition, since the time we released our HTTPS report in February, 12 more of the top 100 websites have changed their serving default from HTTP to HTTPS.” This can be validated by looking at of 2017, a growing number of websites are SSL validated and are winning their customers’ trust. Many examples of websites that moved have noticed that their keyword ranking and their overall page visibility has increased significantly. It is thus evident that 2017 will be the year of HTTPS and SSL certifications. SSL certifications have managed to change the internet forever.
Google terming a website “not secure” does not necessary mean the site is blocked but it will certainly put a question mark in the users mind if they should be viewing this site or should they exchange any information either with the site or through the site. Chances are the user may plainly prefer to avoid using these sites. This makes it imperative for organizations or websites to have the SSL certification to conduct business and maintain consumer trust.
Popular open-source Content Managements Systems (CMS) like WordPress also wants websites to move towards SSL. In their blog dated December 2016, they have clearly stated that, “First, early in 2017, we will only promote hosting partners that provide a SSL certificate by default in their accounts. Later we will begin to assess which features, such as API authentication, would benefit the most from SSL and make them only enabled when SSL is there”. Other popular CMS may also follow suit making it absolutely necessary for website to get SSL validation.
Many theories also suggest that not all users pay attention to the lock on their chrome bar and proceed browsing the website that has been flagged unsafe by Chrome. Moreover, it is just chrome that is tagging an HTTP site as unsafe other browsers do not have any such restrictions. Chances are that in the near future they will follow suit and may even block websites. Sooner or later websites will have to migrate to a HTTPS website or get the SSL certification. 

Monday, 20 March 2017

Switching from HTTP to HTTPS

In today’s connected world consumers are overwhelmingly looking for security. They very well know and understand that a breach with one device can infect other connected devices. This also makes them conscious of accessing only those links that ensure cyber-security. Organizations too are rapidly embracing cyber-security to ensure their business data, consumer data and a consumer’s faith in their organization are protected from cybercrimes. For organizations it is not just a matter of business continuity but a matter of survival. 



To ensure data protection and to restore faith in consumers’ mind, a growing number of organizations are getting Secure Sockets Layer (SSL) to their domains. Though symbolic of moving from HTTP (or Hyper Text Transfer Protocol) to HTTPS (or HTTP Secure), SSL is a standard security technology that enables organizations to establish an encrypted link between a web server and a client. This makes it impossible for attackers to intercept the data flow (between a web server and a client) and use the information. SSL is an absolute necessity for e-commerce or for organizations that collect sensitive data. 

There are numerous benefits of switching to HTTPS. Web-search giant, Google has been explicitly endorsing the move as they believe HTTPS protects the domain from “eavesdroppers” thus protecting information about the user’s browsing activities. Google in its HTTPS website migration guide has clearly stated that data sent using HTTPS is secured via Transport Layer Security protocol (TLS), thus the data cannot be altered or rerouted without being detected. Google’s open endorsement to HTTPS website also shows their preference and is evident in their listing of search results – HTTPS sites are ranked higher than others. Switching to HTTPS may thus give you a small boost in ranking today and possibly a larger boost in the future. 

Switching from HTTP to HTTP is easy and cost effective considering the business benefits it gives. To have a HTTPS domain you have to first get an SSL certification either from your hosting company or from a third party website. But before you go buy, you have to decide on what exactly you would want to be SSL validated – Domain validation (this covers encryption only), Organizational validation (a bit costlier than domain validation but includes Authentication in its coverage), and finally Extended Validation (it ensures best security and is a must for Banks and eCommerce businesses). 

In most cases the SSL certification vendor also helps portals to install validations; it best to enquire this before buying from the vendor. Once this is over, you need to create a link map of your sites and redirections. This can be a time consuming step and depends on the complexity of your website. Ensure to update your internal links too. The images, stylesheets and scripts also need to be updated with the HTTPS tag just to ensure that all files used on your site have the https link. 

A freshly created HTTPS link may not show Google traffic, this is because Google still only recognizes the HTTP site. To overcome this, you need to re-add the new website to Google Webmaster Tool and submit the new site map as well in the listings. A quick test should throw bugs that can be fixed to ensure traffic.
Switching from HTTP to HTTPS can be a daunting task for new companies; however, the merits are limitless. It is best to get an expert on board to help you with the transition. This will allow you to focus on your core activities while getting an SSL certified domain in the market that is trustworthy in your consumers’ mind.