<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/">
	<channel>
		<title><![CDATA[Filetruth Forum - SSL Certificates]]></title>
		<link>https://filetruth.com/forum/</link>
		<description><![CDATA[Filetruth Forum - https://filetruth.com/forum]]></description>
		<pubDate>Thu, 01 Oct 2026 03:51:31 +0000</pubDate>
		<generator>MyBB</generator>
		<item>
			<title><![CDATA[What is  SSL TLS certificate?]]></title>
			<link>https://filetruth.com/forum/Thread-What-is-SSL-TLS-certificate</link>
			<pubDate>Sun, 16 Jan 2022 14:34:21 +0000</pubDate>
			<guid isPermaLink="false">https://filetruth.com/forum/Thread-What-is-SSL-TLS-certificate</guid>
			<description><![CDATA[<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">An SSL certificate is a digital certificate that authenticates a website's identity and enables an encrypted connection. SSL stands for Secure Sockets Layer, a security protocol that creates an encrypted link between a web server and a web browser.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font"><span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">Companies and organizations need to add SSL certificates to their websites to secure online transactions and keep customer information private and secure.</span></span></span><br />
</span></span></span><br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">In short: SSL keeps internet connections secure and prevents criminals from reading or modifying information transferred between two systems. When you see a padlock icon next to the URL in the address bar, that means SSL protects the website you are visiting.</span></span></span><br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font"><span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">Since its inception about 25 years ago, there have been several versions of SSL protocol, all of which at some point ran into security troubles. A revamped and renamed version followed — TLS (Transport Layer Security), which is still in use today. However, the initials SSL stuck, so the new version of the protocol is still usually called by the old name.</span></span></span></span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font"><span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font"><span style="color: #444444;" class="mycode_color"><span style="font-size: large;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">How do SSL certificates work?</span></span></span><br />
</span></span></span></span></span></span><br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">SSL works by ensuring that any data transferred between users and websites, or between two systems, remains impossible to read. It uses encryption algorithms to scramble data in transit, which prevents hackers from reading it as it is sent over the connection. This data includes potentially sensitive information such as names, addresses, credit card numbers, or other financial details.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">The process works like this:</span></span></span><br />
<br />
<ol type="1" class="mycode_list">
</li>
<li><span style="color: #535353;" class="mycode_color">A browser or server attempts to connect to a website (i.e., a web server) secured with SSL.</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">The browser or server requests that the web server identifies itself.</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">The web server sends the browser or server a copy of its SSL certificate in response.</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">The browser or server checks to see whether it trusts the SSL certificate. If it does, it signals this to the webserver.</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">The web server then returns a digitally signed acknowledgment to start an SSL encrypted session.</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Encrypted data is shared between the browser or server and the webserver.</span><br />
</li></ol>
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">This process is sometimes referred to as an "SSL handshake." While it sounds like a lengthy process, it takes place in milliseconds.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">When a website is secured by an SSL certificate, the acronym HTTPS (which stands for HyperText Transfer Protocol Secure) appears in the URL. Without an SSL certificate, only the letters HTTP – i.e., without the S for Secure – will appear. A padlock icon will also display in the URL address bar. This signals trust and provides reassurance to those visiting the website.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">To view an SSL certificate's details, you can click on the padlock symbol located within the browser bar. Details typically included within SSL certificates include:</span></span></span><br />
<ul class="mycode_list">
</li>
<li><span style="color: #535353;" class="mycode_color">The domain name that the certificate was issued for</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Which person, organization, or device it was issued to</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Which Certificate Authority issued it</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">The Certificate Authority's digital signature</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Associated subdomains</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Issue date of the certificate</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">The expiry date of the certificate</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">The public key (the private key is not revealed)</span><br />
</li></ul>
<span style="color: #444444;" class="mycode_color"><span style="font-size: large;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">Why you need an SSL certificate</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">Websites need SSL certificates to keep user data secure, verify ownership of the website, prevent attackers from creating a fake version of the site, and convey trust to users.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">If a website is asking users to sign in, enter personal details such as their credit card numbers, or view confidential information such as health benefits or financial information, then it is essential to keep the data confidential. SSL certificates help keep online interactions private and assure users that the website is authentic and safe to share private information with.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">More relevant to businesses is the fact that an SSL certificate is required for an HTTPS web address. HTTPS is the secure form of HTTP, which means that HTTPS websites have their traffic encrypted by SSL. Most browsers tag HTTP sites – those without SSL certificates – as "not secure." This sends a clear signal to users that the site may not be trustworthy – incentivizing businesses who have not done so to migrate to HTTPS.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">An SSL certificate helps to secure information such as:</span></span></span><br />
<ul class="mycode_list">
</li>
<li><span style="color: #535353;" class="mycode_color">Login credentials</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Credit card transactions or bank account information</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Personally identifiable information — such as full name, address, date of birth, or telephone number</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Legal documents and contracts</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Medical records</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Proprietary information</span><br />
</li></ul>
<span style="color: #444444;" class="mycode_color"><span style="font-size: large;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">Types of SSL certificate</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">There are different types of SSL certificates with different validation levels. The six main types are:</span></span></span><br />
<br />
<ol type="1" class="mycode_list">
</li>
<li><span style="color: #535353;" class="mycode_color">Extended Validation certificates (EV SSL)</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Organization Validated certificates (OV SSL)</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Domain Validated certificates (DV SSL)</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Wildcard SSL certificates</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Multi-Domain SSL certificates (MDC)</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Unified Communications Certificates (UCC)</span><br />
</li></ol>
<span style="color: #444444;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">Extended Validation certificates (EV SSL)</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">This is the highest-ranking and most expensive type of SSL certificate. It tends to be used for high profile websites which collect data and involve online payments. When installed, this SSL certificate displays the padlock, HTTPS, name of the business, and the country on the browser address bar. Displaying the website owner's information in the address bar helps distinguish the site from malicious sites. To set up an EV SSL certificate, the website owner must go through a standardized identity verification process to confirm they are authorized legally to the exclusive rights to the domain.</span></span></span><br />
<br />
<span style="color: #444444;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">Organization Validated certificates (OV SSL)</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">This version of SSL certificate has a similar assurance similar level to the EV SSL certificate since to obtain one; the website owner needs to complete a substantial validation process. This type of certificate also displays the website owner's information in the address bar to distinguish from malicious sites. OV SSL certificates tend to be the second most expensive (after EV SSLs), and their primary purpose is to encrypt the user's sensitive information during transactions. Commercial or public-facing websites must install an OV SSL certificate to ensure that any customer information shared remains confidential.</span></span></span><br />
<br />
<span style="color: #444444;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">Domain Validated certificates (DV SSL)</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">The validation process to obtain this SSL certificate type is minimal, and as a result, Domain Validation SSL certificates provide lower assurance and minimal encryption. They tend to be used for blogs or informational websites – i.e., which do not involve data collection or online payments. This SSL certificate type is one of the least expensive and quickest to obtain. The validation process only requires website owners to prove domain ownership by responding to an email or phone call. The browser address bar only displays HTTPS and a padlock with no business name displayed.</span></span></span><br />
<br />
<span style="color: #444444;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">Wildcard SSL certificates</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">Wildcard SSL certificates allow you to secure a base domain and unlimited sub-domains on a single certificate. If you have multiple sub-domains to secure, then a Wildcard SSL certificate purchase is <span style="text-decoration: line-through;" class="mycode_s">much</span> less expensive than buying individual SSL certificates for each of them. Wildcard SSL certificates have an asterisk * as part of the common name, where the asterisk represents any valid sub-domains that have the same base domain. For example, a single Wildcard certificate for *website can be used to secure:</span></span></span><br />
<ul class="mycode_list">
</li>
<li><span style="color: #535353;" class="mycode_color">payments.yourdomain.com</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">login.yourdomain.com</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">mail.yourdomain.com</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">download.yourdomain.com</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">anything.yourdomain.com</span><br />
</li></ul>
<span style="color: #444444;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">Multi-Domain SSL Certificate (MDC)</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">A Multi-Domain certificate can be used to secure many domains and/or sub-domain names. This includes the combination of completely unique domains and sub-domains with different TLDs (Top-Level Domains) except for local/internal ones.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">For example:</span></span></span><br />
<ul class="mycode_list">
</li>
<li><span style="color: #535353;" class="mycode_color">www.example.com</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">example.org</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">mail.this-domain.net</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">example.anything.com.au</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">checkout.example.com</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">secure.example.org</span><br />
</li></ul>
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">Multi-Domain certificates do not support sub-domains by default. If you need to secure both <a href="http://www.example.com" target="_blank" class="mycode_url">http://www.example.com</a> and example.com with one Multi-Domain certificate, then both hostnames should be specified when obtaining the certificate.</span></span></span><br />
<br />
<span style="color: #444444;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">Unified Communications Certificate (UCC)</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">Unified Communications Certificates (UCC) are also considered Multi-Domain SSL certificates. UCCs were initially designed to secure Microsoft Exchange and Live Communications servers. Today, any website owner can use these certificates to allow multiple domain names to be secured on a single certificate. UCC Certificates are organizationally validated and display a padlock on a browser. UCCs can be used as EV SSL certificates to give website visitors the highest assurance through the green address bar.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">It is essential to be familiar with the different types of SSL certificates to obtain the right type of certificate for your website.</span></span></span><br />
<br />
<span style="color: #444444;" class="mycode_color"><span style="font-size: large;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">How to obtain an SSL certificate</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">SSL certificates can be obtained directly from a Certificate Authority (CA). Certificate Authorities – sometimes also referred to as Certification Authorities – issue millions of SSL certificates each year. They play a critical role in how the internet operates and how transparent, trusted interactions can occur online.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">The cost of an SSL certificate can range from free to hundreds of dollars, depending on the level of security you require. Once you decide on the type of certificate you require, you can then look for Certificate Issuers, which offer SSLs at the level you require.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">Obtaining your SSL involves the following steps:</span></span></span><br />
<ul class="mycode_list">
</li>
<li><span style="color: #535353;" class="mycode_color">Prepare by getting your server set up and ensuring your <a href="https://www.whois.net/" target="_blank" class="mycode_url"><span style="color: #006d5c;" class="mycode_color">WHOIS</span></a> record is updated and matches what you are submitting to the Certificate Authority (it needs to show the correct company name and address, etc.)</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Generating a Certificate Signing Request (CSR) on your server. This is an action your hosting company can assist with.</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Submitting this to the Certificate Authority to validate your domain and company details</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Installing the certificate they provide once the process is complete.</span><br />
</li></ul>
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">Once obtained, you need to configure the certificate on your web host or on your own servers if you host the website yourself.</span></span></span><br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font"><span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font"><span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">How quickly you receive your certificate depends on what type of certificate you get and which certificate provider you procure it from. Each level of validation takes a different length of time to complete. A simple Domain Validation SSL certificate can be issued within minutes of being ordered, whereas Extended Validation can take as long as a full week.</span></span></span><br />
<br />
<span style="color: #444444;" class="mycode_color"><span style="font-size: large;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">Can an SSL certificate be used on multiple servers?</span></span></span><br />
</span></span></span></span></span></span><br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">It is possible to use one SSL certificate for multiple domains on the same server. Depending on the vendor, you can also use one SSL certificate on multiple servers. This is because of Multi-Domain SSL certificates, which we discussed above.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">As the name implies, Multi-Domain SSL Certificates work with multiple domains. The number is left up to the specific issuing Certificate Authority. A Multi-Domain SSL Certificate is different from a Single Domain SSL Certificate, which – again, as the name implies – is designed to secure a single domain.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">To make matters confusing, you may hear Multi-Domain SSL Certificates, also referred to as SAN certificates. SAN stands for Subject Alternative Name. Every multi-domain certificate has additional fields (i.e., SANs), which you can use to list additional domains that you want to cover under one certificate.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">Unified Communications Certificates (UCCs) and Wildcard SSL Certificates also allow for multi-domains and, in the latter case, an unlimited number of subdomains.</span></span></span><br />
<br />
<span style="color: #444444;" class="mycode_color"><span style="font-size: large;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">What happens when an SSL certificate expires?</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">SSL certificates do expire; they don't last forever. <span style="color: #006d5c;" class="mycode_color">The Certificate Authority/Browser Forum</span>, which serves as the de facto regulatory body for the SSL industry, states that SSL certificates should have a lifespan of <span style="color: #006d5c;" class="mycode_color">no more than 27 months</span>. This essentially means two years plus you can carry over up to three months if you renew with time remaining on your previous SSL certificate.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">SSL certificates expire because, as with any form of authentication, information needs to be periodically re-validated to check it is still accurate. Things change on the internet, as companies and also websites are bought and sold. As they change hands, the information relevant to SSL certificates also changes. The purpose of the expiry period is to ensure that the information used to authenticate servers and organizations is as up-to-date and accurate as possible.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">Previously, SSL certificates could be issued for as long as five years, which was subsequently reduced to three and most recently to two years plus a potential extra three months. In 2020, Google, Apple, and Mozilla announced <span style="color: #006d5c;" class="mycode_color">they would enforce one-year SSL certificates</span>, despite this proposal being voted down by the Certificate Authority Browser Forum. This took effect from September 2020. It is possible that in the future, the length of validity will reduce still further.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">When an SSL certificate expires, it makes the site in question unreachable. When a user's browser arrives at a website, it checks the SSL certificate's validity within milliseconds (as part of the SSL handshake). If the SSL certificate has expired, visitors will receive a message to the effect of — "This site is not secure. Potential risk ahead".</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">While users do have the option to proceed, it is not advisable to do so, given the cybersecurity risks involved, including the possibility of <span style="color: #006d5c;" class="mycode_color">malware</span>. This will significantly impact bounce rates for website owners, as users rapidly click off the homepage and go elsewhere.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">Keeping on top of when SSL certificates expire presents a challenge for larger businesses. While smaller and <span style="color: #006d5c;" class="mycode_color">medium-sized businesses (SMEs)</span> may have one or only a few certificates to manage, <span style="color: #006d5c;" class="mycode_color">enterprise-level organizations</span> that potentially transact across markets – with numerous websites and networks – will have many more. At this level, allowing an SSL certificate to expire is usually the result of oversight rather than incompetence. The best way for larger businesses to stay on top of when their SSL certificates expire is by using a certificate management platform. There are various products on the market, which you can find using an online search. These allow enterprises to see and manage digital certificates across their entire infrastructure. If you do use one of these platforms, it is important to log in regularly so you can be aware of when renewals are due.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">If you allow a certificate to expire, the certificate becomes invalid, and you will no longer be able to run secure transactions on your website. The Certification Authority (CA) will prompt you to renew your SSL certificate before the expiration date.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">Whichever Certificate Authority or SSL service you use to obtain your SSL certificates from will send you expiration notifications at set intervals, usually starting at 90 days out. Try to ensure that these reminders are being sent to an email distribution list — rather than a single individual, who may have left the company or moved to another role by the time the reminder is sent. Think about which stakeholders in your company are on this distribution list to ensure the right people see the reminders at the right time.</span></span></span><br />
<br />
<span style="color: #444444;" class="mycode_color"><span style="font-size: large;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">How to tell if a site has an SSL certificate</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">The easiest way to see if a site has an SSL certificate is by looking at the address bar in your browser:</span></span></span><br />
<ul class="mycode_list">
</li>
<li><span style="color: #535353;" class="mycode_color">If the URL begins with HTTPS instead of HTTP, that means the site is secured using an SSL certificate.</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Secure sites show a closed padlock emblem, which you can click on to see security details – the most trustworthy sites will have green padlocks or address bars.</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Browsers also show warning signs when a connection is not secure — such as a red padlock, a padlock which is not closed, a line going through the website's address, or a warning triangle on top of the padlock emblem.</span><br />
</li></ul>
<span style="color: #444444;" class="mycode_color"><span style="font-size: large;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">How to ensure your online session is safe</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font"><span style="font-weight: bold;" class="mycode_b">Only submit your personal data and online payment details to websites with EV or OV certificates</span>. DV certificates are not suitable for eCommerce websites. You can tell if a site has an EV or OV certificate by looking at the address bar. For an EV SSL, the organization's name will be visible in the address bar itself. For an OV SSL, you can see the organization's name's details by clicking on the padlock icon. For a DV SSL, only the padlock icon is visible.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font"><span style="font-weight: bold;" class="mycode_b">Read the website's privacy policy</span>. This enables you to see how your data will be used. Legitimate companies will be transparent about how they collect your data and what they do with it.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font"><span style="font-weight: bold;" class="mycode_b">Look out for trust signals or indicators on websites</span>.<br />
As well as SSL certificates, these include reputable logos or badges which show the website meets specific security standards. Other signs that can help you determine if a site is real or not include checking for a physical address and telephone number, checking their returns or refunds policy, and making sure prices are believable and not too good to be true.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font"><span style="font-weight: bold;" class="mycode_b">Stay alert to phishing scams</span>.<br />
Sometimes cyber attackers create websites that mimic existing websites to trick people into purchasing something or logging in to their phishing site. It is possible for a <span style="color: #006d5c;" class="mycode_color">phishing</span> site to obtain an SSL certificate and therefore encrypt all the traffic that flows between you and it. A growing proportion of phishing scams occur on HTTPS sites — deceiving users who feel reassured by the padlock icon's presence.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">To avoid these kinds of attacks:</span></span></span><br />
<ul class="mycode_list">
</li>
<li><span style="color: #535353;" class="mycode_color">Always examine the domain of the site you are on and ensure it is spelled correctly. The URL of a fake site might differ by only one character – e.g., amaz0n.com instead of amazon.com. If in doubt, type the domain directly into your browser to make sure you are connecting to the website you intend to visit.</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Never enter logins, passwords, banking credentials, or any other personal information on the site unless you are sure of its authenticity.</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Always consider what a particular site is offering, whether it looks suspicious, and whether you really need to register on it.</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Make sure your devices are well protected: <span style="color: #006d5c;" class="mycode_color"> Internet Security </span>checks URLs against an extensive database of phishing sites, and it detects scams regardless of how "safe" the resource looks.</span><br />
</li></ul>
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font"><span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font"><span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">Cybersecurity risks continue to evolve but understanding the types of SSL certificates to look out for and how to distinguish a safe site from a potentially dangerous one will help internet users avoid scams and protect their personal data from cybercriminals.</span></span></span></span></span></span></span></span></span>]]></description>
			<content:encoded><![CDATA[<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">An SSL certificate is a digital certificate that authenticates a website's identity and enables an encrypted connection. SSL stands for Secure Sockets Layer, a security protocol that creates an encrypted link between a web server and a web browser.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font"><span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">Companies and organizations need to add SSL certificates to their websites to secure online transactions and keep customer information private and secure.</span></span></span><br />
</span></span></span><br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">In short: SSL keeps internet connections secure and prevents criminals from reading or modifying information transferred between two systems. When you see a padlock icon next to the URL in the address bar, that means SSL protects the website you are visiting.</span></span></span><br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font"><span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">Since its inception about 25 years ago, there have been several versions of SSL protocol, all of which at some point ran into security troubles. A revamped and renamed version followed — TLS (Transport Layer Security), which is still in use today. However, the initials SSL stuck, so the new version of the protocol is still usually called by the old name.</span></span></span></span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font"><span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font"><span style="color: #444444;" class="mycode_color"><span style="font-size: large;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">How do SSL certificates work?</span></span></span><br />
</span></span></span></span></span></span><br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">SSL works by ensuring that any data transferred between users and websites, or between two systems, remains impossible to read. It uses encryption algorithms to scramble data in transit, which prevents hackers from reading it as it is sent over the connection. This data includes potentially sensitive information such as names, addresses, credit card numbers, or other financial details.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">The process works like this:</span></span></span><br />
<br />
<ol type="1" class="mycode_list">
</li>
<li><span style="color: #535353;" class="mycode_color">A browser or server attempts to connect to a website (i.e., a web server) secured with SSL.</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">The browser or server requests that the web server identifies itself.</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">The web server sends the browser or server a copy of its SSL certificate in response.</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">The browser or server checks to see whether it trusts the SSL certificate. If it does, it signals this to the webserver.</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">The web server then returns a digitally signed acknowledgment to start an SSL encrypted session.</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Encrypted data is shared between the browser or server and the webserver.</span><br />
</li></ol>
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">This process is sometimes referred to as an "SSL handshake." While it sounds like a lengthy process, it takes place in milliseconds.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">When a website is secured by an SSL certificate, the acronym HTTPS (which stands for HyperText Transfer Protocol Secure) appears in the URL. Without an SSL certificate, only the letters HTTP – i.e., without the S for Secure – will appear. A padlock icon will also display in the URL address bar. This signals trust and provides reassurance to those visiting the website.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">To view an SSL certificate's details, you can click on the padlock symbol located within the browser bar. Details typically included within SSL certificates include:</span></span></span><br />
<ul class="mycode_list">
</li>
<li><span style="color: #535353;" class="mycode_color">The domain name that the certificate was issued for</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Which person, organization, or device it was issued to</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Which Certificate Authority issued it</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">The Certificate Authority's digital signature</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Associated subdomains</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Issue date of the certificate</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">The expiry date of the certificate</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">The public key (the private key is not revealed)</span><br />
</li></ul>
<span style="color: #444444;" class="mycode_color"><span style="font-size: large;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">Why you need an SSL certificate</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">Websites need SSL certificates to keep user data secure, verify ownership of the website, prevent attackers from creating a fake version of the site, and convey trust to users.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">If a website is asking users to sign in, enter personal details such as their credit card numbers, or view confidential information such as health benefits or financial information, then it is essential to keep the data confidential. SSL certificates help keep online interactions private and assure users that the website is authentic and safe to share private information with.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">More relevant to businesses is the fact that an SSL certificate is required for an HTTPS web address. HTTPS is the secure form of HTTP, which means that HTTPS websites have their traffic encrypted by SSL. Most browsers tag HTTP sites – those without SSL certificates – as "not secure." This sends a clear signal to users that the site may not be trustworthy – incentivizing businesses who have not done so to migrate to HTTPS.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">An SSL certificate helps to secure information such as:</span></span></span><br />
<ul class="mycode_list">
</li>
<li><span style="color: #535353;" class="mycode_color">Login credentials</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Credit card transactions or bank account information</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Personally identifiable information — such as full name, address, date of birth, or telephone number</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Legal documents and contracts</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Medical records</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Proprietary information</span><br />
</li></ul>
<span style="color: #444444;" class="mycode_color"><span style="font-size: large;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">Types of SSL certificate</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">There are different types of SSL certificates with different validation levels. The six main types are:</span></span></span><br />
<br />
<ol type="1" class="mycode_list">
</li>
<li><span style="color: #535353;" class="mycode_color">Extended Validation certificates (EV SSL)</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Organization Validated certificates (OV SSL)</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Domain Validated certificates (DV SSL)</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Wildcard SSL certificates</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Multi-Domain SSL certificates (MDC)</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Unified Communications Certificates (UCC)</span><br />
</li></ol>
<span style="color: #444444;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">Extended Validation certificates (EV SSL)</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">This is the highest-ranking and most expensive type of SSL certificate. It tends to be used for high profile websites which collect data and involve online payments. When installed, this SSL certificate displays the padlock, HTTPS, name of the business, and the country on the browser address bar. Displaying the website owner's information in the address bar helps distinguish the site from malicious sites. To set up an EV SSL certificate, the website owner must go through a standardized identity verification process to confirm they are authorized legally to the exclusive rights to the domain.</span></span></span><br />
<br />
<span style="color: #444444;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">Organization Validated certificates (OV SSL)</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">This version of SSL certificate has a similar assurance similar level to the EV SSL certificate since to obtain one; the website owner needs to complete a substantial validation process. This type of certificate also displays the website owner's information in the address bar to distinguish from malicious sites. OV SSL certificates tend to be the second most expensive (after EV SSLs), and their primary purpose is to encrypt the user's sensitive information during transactions. Commercial or public-facing websites must install an OV SSL certificate to ensure that any customer information shared remains confidential.</span></span></span><br />
<br />
<span style="color: #444444;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">Domain Validated certificates (DV SSL)</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">The validation process to obtain this SSL certificate type is minimal, and as a result, Domain Validation SSL certificates provide lower assurance and minimal encryption. They tend to be used for blogs or informational websites – i.e., which do not involve data collection or online payments. This SSL certificate type is one of the least expensive and quickest to obtain. The validation process only requires website owners to prove domain ownership by responding to an email or phone call. The browser address bar only displays HTTPS and a padlock with no business name displayed.</span></span></span><br />
<br />
<span style="color: #444444;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">Wildcard SSL certificates</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">Wildcard SSL certificates allow you to secure a base domain and unlimited sub-domains on a single certificate. If you have multiple sub-domains to secure, then a Wildcard SSL certificate purchase is <span style="text-decoration: line-through;" class="mycode_s">much</span> less expensive than buying individual SSL certificates for each of them. Wildcard SSL certificates have an asterisk * as part of the common name, where the asterisk represents any valid sub-domains that have the same base domain. For example, a single Wildcard certificate for *website can be used to secure:</span></span></span><br />
<ul class="mycode_list">
</li>
<li><span style="color: #535353;" class="mycode_color">payments.yourdomain.com</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">login.yourdomain.com</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">mail.yourdomain.com</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">download.yourdomain.com</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">anything.yourdomain.com</span><br />
</li></ul>
<span style="color: #444444;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">Multi-Domain SSL Certificate (MDC)</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">A Multi-Domain certificate can be used to secure many domains and/or sub-domain names. This includes the combination of completely unique domains and sub-domains with different TLDs (Top-Level Domains) except for local/internal ones.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">For example:</span></span></span><br />
<ul class="mycode_list">
</li>
<li><span style="color: #535353;" class="mycode_color">www.example.com</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">example.org</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">mail.this-domain.net</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">example.anything.com.au</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">checkout.example.com</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">secure.example.org</span><br />
</li></ul>
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">Multi-Domain certificates do not support sub-domains by default. If you need to secure both <a href="http://www.example.com" target="_blank" class="mycode_url">http://www.example.com</a> and example.com with one Multi-Domain certificate, then both hostnames should be specified when obtaining the certificate.</span></span></span><br />
<br />
<span style="color: #444444;" class="mycode_color"><span style="font-size: small;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">Unified Communications Certificate (UCC)</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">Unified Communications Certificates (UCC) are also considered Multi-Domain SSL certificates. UCCs were initially designed to secure Microsoft Exchange and Live Communications servers. Today, any website owner can use these certificates to allow multiple domain names to be secured on a single certificate. UCC Certificates are organizationally validated and display a padlock on a browser. UCCs can be used as EV SSL certificates to give website visitors the highest assurance through the green address bar.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">It is essential to be familiar with the different types of SSL certificates to obtain the right type of certificate for your website.</span></span></span><br />
<br />
<span style="color: #444444;" class="mycode_color"><span style="font-size: large;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">How to obtain an SSL certificate</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">SSL certificates can be obtained directly from a Certificate Authority (CA). Certificate Authorities – sometimes also referred to as Certification Authorities – issue millions of SSL certificates each year. They play a critical role in how the internet operates and how transparent, trusted interactions can occur online.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">The cost of an SSL certificate can range from free to hundreds of dollars, depending on the level of security you require. Once you decide on the type of certificate you require, you can then look for Certificate Issuers, which offer SSLs at the level you require.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">Obtaining your SSL involves the following steps:</span></span></span><br />
<ul class="mycode_list">
</li>
<li><span style="color: #535353;" class="mycode_color">Prepare by getting your server set up and ensuring your <a href="https://www.whois.net/" target="_blank" class="mycode_url"><span style="color: #006d5c;" class="mycode_color">WHOIS</span></a> record is updated and matches what you are submitting to the Certificate Authority (it needs to show the correct company name and address, etc.)</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Generating a Certificate Signing Request (CSR) on your server. This is an action your hosting company can assist with.</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Submitting this to the Certificate Authority to validate your domain and company details</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Installing the certificate they provide once the process is complete.</span><br />
</li></ul>
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">Once obtained, you need to configure the certificate on your web host or on your own servers if you host the website yourself.</span></span></span><br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font"><span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font"><span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">How quickly you receive your certificate depends on what type of certificate you get and which certificate provider you procure it from. Each level of validation takes a different length of time to complete. A simple Domain Validation SSL certificate can be issued within minutes of being ordered, whereas Extended Validation can take as long as a full week.</span></span></span><br />
<br />
<span style="color: #444444;" class="mycode_color"><span style="font-size: large;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">Can an SSL certificate be used on multiple servers?</span></span></span><br />
</span></span></span></span></span></span><br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">It is possible to use one SSL certificate for multiple domains on the same server. Depending on the vendor, you can also use one SSL certificate on multiple servers. This is because of Multi-Domain SSL certificates, which we discussed above.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">As the name implies, Multi-Domain SSL Certificates work with multiple domains. The number is left up to the specific issuing Certificate Authority. A Multi-Domain SSL Certificate is different from a Single Domain SSL Certificate, which – again, as the name implies – is designed to secure a single domain.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">To make matters confusing, you may hear Multi-Domain SSL Certificates, also referred to as SAN certificates. SAN stands for Subject Alternative Name. Every multi-domain certificate has additional fields (i.e., SANs), which you can use to list additional domains that you want to cover under one certificate.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">Unified Communications Certificates (UCCs) and Wildcard SSL Certificates also allow for multi-domains and, in the latter case, an unlimited number of subdomains.</span></span></span><br />
<br />
<span style="color: #444444;" class="mycode_color"><span style="font-size: large;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">What happens when an SSL certificate expires?</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">SSL certificates do expire; they don't last forever. <span style="color: #006d5c;" class="mycode_color">The Certificate Authority/Browser Forum</span>, which serves as the de facto regulatory body for the SSL industry, states that SSL certificates should have a lifespan of <span style="color: #006d5c;" class="mycode_color">no more than 27 months</span>. This essentially means two years plus you can carry over up to three months if you renew with time remaining on your previous SSL certificate.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">SSL certificates expire because, as with any form of authentication, information needs to be periodically re-validated to check it is still accurate. Things change on the internet, as companies and also websites are bought and sold. As they change hands, the information relevant to SSL certificates also changes. The purpose of the expiry period is to ensure that the information used to authenticate servers and organizations is as up-to-date and accurate as possible.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">Previously, SSL certificates could be issued for as long as five years, which was subsequently reduced to three and most recently to two years plus a potential extra three months. In 2020, Google, Apple, and Mozilla announced <span style="color: #006d5c;" class="mycode_color">they would enforce one-year SSL certificates</span>, despite this proposal being voted down by the Certificate Authority Browser Forum. This took effect from September 2020. It is possible that in the future, the length of validity will reduce still further.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">When an SSL certificate expires, it makes the site in question unreachable. When a user's browser arrives at a website, it checks the SSL certificate's validity within milliseconds (as part of the SSL handshake). If the SSL certificate has expired, visitors will receive a message to the effect of — "This site is not secure. Potential risk ahead".</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">While users do have the option to proceed, it is not advisable to do so, given the cybersecurity risks involved, including the possibility of <span style="color: #006d5c;" class="mycode_color">malware</span>. This will significantly impact bounce rates for website owners, as users rapidly click off the homepage and go elsewhere.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">Keeping on top of when SSL certificates expire presents a challenge for larger businesses. While smaller and <span style="color: #006d5c;" class="mycode_color">medium-sized businesses (SMEs)</span> may have one or only a few certificates to manage, <span style="color: #006d5c;" class="mycode_color">enterprise-level organizations</span> that potentially transact across markets – with numerous websites and networks – will have many more. At this level, allowing an SSL certificate to expire is usually the result of oversight rather than incompetence. The best way for larger businesses to stay on top of when their SSL certificates expire is by using a certificate management platform. There are various products on the market, which you can find using an online search. These allow enterprises to see and manage digital certificates across their entire infrastructure. If you do use one of these platforms, it is important to log in regularly so you can be aware of when renewals are due.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">If you allow a certificate to expire, the certificate becomes invalid, and you will no longer be able to run secure transactions on your website. The Certification Authority (CA) will prompt you to renew your SSL certificate before the expiration date.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">Whichever Certificate Authority or SSL service you use to obtain your SSL certificates from will send you expiration notifications at set intervals, usually starting at 90 days out. Try to ensure that these reminders are being sent to an email distribution list — rather than a single individual, who may have left the company or moved to another role by the time the reminder is sent. Think about which stakeholders in your company are on this distribution list to ensure the right people see the reminders at the right time.</span></span></span><br />
<br />
<span style="color: #444444;" class="mycode_color"><span style="font-size: large;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">How to tell if a site has an SSL certificate</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">The easiest way to see if a site has an SSL certificate is by looking at the address bar in your browser:</span></span></span><br />
<ul class="mycode_list">
</li>
<li><span style="color: #535353;" class="mycode_color">If the URL begins with HTTPS instead of HTTP, that means the site is secured using an SSL certificate.</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Secure sites show a closed padlock emblem, which you can click on to see security details – the most trustworthy sites will have green padlocks or address bars.</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Browsers also show warning signs when a connection is not secure — such as a red padlock, a padlock which is not closed, a line going through the website's address, or a warning triangle on top of the padlock emblem.</span><br />
</li></ul>
<span style="color: #444444;" class="mycode_color"><span style="font-size: large;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">How to ensure your online session is safe</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font"><span style="font-weight: bold;" class="mycode_b">Only submit your personal data and online payment details to websites with EV or OV certificates</span>. DV certificates are not suitable for eCommerce websites. You can tell if a site has an EV or OV certificate by looking at the address bar. For an EV SSL, the organization's name will be visible in the address bar itself. For an OV SSL, you can see the organization's name's details by clicking on the padlock icon. For a DV SSL, only the padlock icon is visible.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font"><span style="font-weight: bold;" class="mycode_b">Read the website's privacy policy</span>. This enables you to see how your data will be used. Legitimate companies will be transparent about how they collect your data and what they do with it.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font"><span style="font-weight: bold;" class="mycode_b">Look out for trust signals or indicators on websites</span>.<br />
As well as SSL certificates, these include reputable logos or badges which show the website meets specific security standards. Other signs that can help you determine if a site is real or not include checking for a physical address and telephone number, checking their returns or refunds policy, and making sure prices are believable and not too good to be true.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font"><span style="font-weight: bold;" class="mycode_b">Stay alert to phishing scams</span>.<br />
Sometimes cyber attackers create websites that mimic existing websites to trick people into purchasing something or logging in to their phishing site. It is possible for a <span style="color: #006d5c;" class="mycode_color">phishing</span> site to obtain an SSL certificate and therefore encrypt all the traffic that flows between you and it. A growing proportion of phishing scams occur on HTTPS sites — deceiving users who feel reassured by the padlock icon's presence.</span></span></span><br />
<br />
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">To avoid these kinds of attacks:</span></span></span><br />
<ul class="mycode_list">
</li>
<li><span style="color: #535353;" class="mycode_color">Always examine the domain of the site you are on and ensure it is spelled correctly. The URL of a fake site might differ by only one character – e.g., amaz0n.com instead of amazon.com. If in doubt, type the domain directly into your browser to make sure you are connecting to the website you intend to visit.</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Never enter logins, passwords, banking credentials, or any other personal information on the site unless you are sure of its authenticity.</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Always consider what a particular site is offering, whether it looks suspicious, and whether you really need to register on it.</span><br />
<br />
</li>
<li><span style="color: #535353;" class="mycode_color">Make sure your devices are well protected: <span style="color: #006d5c;" class="mycode_color"> Internet Security </span>checks URLs against an extensive database of phishing sites, and it detects scams regardless of how "safe" the resource looks.</span><br />
</li></ul>
<span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font"><span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font"><span style="color: #8f8f8f;" class="mycode_color"><span style="font-size: medium;" class="mycode_size"><span style="font-family: MuseoSans, Arial, Helvetica, sans-serif;" class="mycode_font">Cybersecurity risks continue to evolve but understanding the types of SSL certificates to look out for and how to distinguish a safe site from a potentially dangerous one will help internet users avoid scams and protect their personal data from cybercriminals.</span></span></span></span></span></span></span></span></span>]]></content:encoded>
		</item>
	</channel>
</rss>