Introduction People are getting smart about online security. More and more of them are looking for the padlock icon, the “https” prefix and a green address bar in their browser before submitting personal information online. If your Web site doesn’t have an SSL Certificate, visitors may leave before making a purchase, creating an account or even signing up for a newsletter. But you can change all that with an SSL Certificate. Installing an SSL Certificate from GoDaddy.com on your ecommerce Web site allows you to secure your online business and build customer confidence by securing all online transactions with up to 256bit encryption. An SSL Certificate on your business’ Web site will ensure that sensitive data is kept safe from prying eyes. With a GoDaddy.com SSL Certificate, customers will place more trust in your site. Before issuing a certificate, GoDaddy.com rigorously authenticates the requestor’s domain control and, in the case of Deluxe High Assurance SSL Certificates, the identity and, if applicable, the business records of the certificaterequesting entity. The authentication process ensures that customers and business partners can rest assured that a Web site protected with a GoDaddy.com certificate can be trusted. Additionally, GoDaddy.com Premium Extended Validation SSL Certificates provide the highest level of online assurance – perfect for highvalue ecommerce – where our standardized vetting process verifies the legitimacy and status of your registered business. A GoDaddy.com SSL Certificate provides the security your business needs and the protection your customers deserve. With a GoDaddy.com SSL Certificate, customers will know that your site is secure. Why You Need a GoDaddy.com SSL CertificateIn the rapidly expanding world of electronic commerce, security is paramount. Despite booming Internet sales, widespread consumer fear that Internet shopping is not secure still keeps millions of potential shoppers from buying online. Only if your customers trust that their credit card numbers and personal information will be kept safe from tampering can you run a successful online business. For online retailers, securing their shopping sites is vital. If consumers perceive that their credit card information might be compromised online, they are unlikely to do their shopping on the Internet. A GoDaddy.com SSL Certificate helps you build an impenetrable fortress around your customers’ credit card information. A GoDaddy.com SSL Certificate provides an easy, costeffective and secure means to protect customer information and build trust. An SSL Certificate enables Secure Sockets Layer (SSL) encryption of your business’ online transactions, allowing you to build an impenetrable fortress around your customers’ credit card information. GoDaddy.com SSL certificates bring the highest level of trust to your online business. A GoDaddy.com SSL Certificate ensures that all sensitive transactions are kept securely encrypted and safe from prying eyes, and rigorous authentication guarantees that GoDaddy.com certificates are issued only to entities whose existence and domains can be verified. GoDaddy.com SSL Certificates offer industryleading security and versatility:
What is an SSL Certificate?An SSL certificate is a digital certificate that authenticates the identity of a Web site to visiting browsers and encrypts information for the server via Secure Sockets Layer (SSL) technology. A certificate serves as an electronic “passport” that establishes an online entity’s credentials when doing business on the Web. When an Internet user attempts to send confidential information to a Web server, the user’s browser will access the server’s digital certificate and establish a secure connection. A certificate serves as an electronic “passport” that establishes an online entity’s credentials when doing business on the Web. Information contained in the certificate includes:
To obtain an SSL certificate, one must generate and submit a Certificate Signing Request (CSR) to a trusted Certification Authority, such as GoDaddy.com, which will authenticate the requestor’s identity, existence and domain registration ownership before issuing a certificate. Public and Private Keys When you create a CSR, the Web server software with which the request is being generated creates two unique cryptographic keys: A public key, which is used to encrypt messages to your (i.e., the certificate holder’s) server and is contained in your certificate, and a private key, which is stored on your local computer and “decrypts” the secure messages so they can be read by your server. In order to establish an encrypted link between your Web site and your customer’s Web browser your Web server will match your issued SSL certificate to your private key. Because only the Web server has access to its private key, only the server can decrypt SSLencrypted data. *Deluxe High Assurance Certificates and Premium Extended Validation Certificates only. Standard SSL Certificates only contain the domain name and no information on who purchased the certificate. Enabling Safe and Convenient Online ShoppingA GoDaddy.com SSL Certificate ensures safe, easy and convenient Internet shopping. Once an Internet user enters a secure area – where, for example, credit card information, email address or other personal data is collected – the shopping site’s SSL certificate enables the browser and Web server to build a secure, encrypted connection. The SSL “handshake” process, which establishes the secure session, takes place discreetly behind the scenes, ensuring an uninterrupted shopping experience for the consumer. A “padlock” icon in the browser’s status bar and the “https://” prefix in the URL are the only visible indications of a secure session in progress. (Premium Extended Validation Certificates also display a green address bar color when displaying a secured page.) A “padlock” icon in the browser’s status bar (Firefox) or in the navigation bar indicates that a secure session is in progress. ![]() By contrast, if a user attempts to submit personal information to an unsecured Web site (i.e., a site that is not protected with a valid SSL certificate), the browser’s builtin security mechanism will trigger a warning to the user, reminding him/her that the site is not secure and that sensitive data might be intercepted by third parties. Faced with such a warning, most Internet users likely will look elsewhere to make a purchase. Up to 256Bit Encryption GoDaddy.com SSL certificates support both industrystandard 128bit (used by all banking infrastructures to safeguard sensitive data) and highgrade 256bit SSL encryption to secure online transactions. The actual encryption strength on a secure connection using a digital certificate is determined by the level of encryption supported by the user’s browser and the server that the Web site resides on. For example, the combination of a Firefox browser and an Apache 2.X Web server enables up to 256bit AES encryption with GoDaddy.com certificates. Encryption strength is measured in key length — number of bits in the key. To decipher an SSL communication, one needs to generate the correct decoding key. Mathematically speaking, 2n possible values exist for an nbit key. Thus, 40bit encryption involves 240 possible values. 128and 256bit keys involve a staggering 2128 and 2256 possible combinations, respectively, rendering the encrypted data de facto impervious to intrusion. Even with a bruteforce attack (the process of systematically trying all possible combinations until the right one is found) cracking a 128or 256bit encryption is computationally unfeasible. Stringent Authentication — A Matter of TrustBefore GoDaddy.com issues an SSL Certificate, the applicant’s company or personal information undergoes a rigorous authentication procedure that serves to preempt online theft and to verify the domain control and, if applicable, the existence and identity of the requesting entity. Only through thorough validation of submitted data can the online customer rest assured that online businesses that utilize SSL certificates from GoDaddy.com indeed are to be trusted. A Deluxe High Assurance GoDaddy.com certificate guarantees that the entity that owns the certificate is who it claims to be and has a legal right to use the domain from which it operates. A Premium Extended Validation Certificate verifies your organization’s identity, the validity of your request and the overall legitimacy of your business. SSL Certificates are only issued to entities whose domain control and, depending on certificate type, business credentials and contact information have been verified. Thus, a GoDaddy.com SSL certificate guarantees that the entity that owns the certificate is who it claims to be and has a legal right to use the domain from which it operates. GoDaddy.com issues three types of SSL Certificates, each of which relies on authentication of a number of elements: Medium Assurance (i.e., Standard SSL) Certificate GoDaddy.com will authenticate that: ■ The requesting entity controls the domain in the request. Deluxe High Assurance Certificate GoDaddy.com will authenticate that:
Premium Extended Validation Certificate More extensive than any existing SSL vetting process:
http://www.MyPersonalDomain.com/ shop.MyPersonalDomain.com register.MyPersonalDomain.com ■ The Multiple Domain (UCC) version secures up to 100 domain names with one certificate. This certificate works exceptionally well with Microsoft®Exchange Server 2007 and Office Communications Server 2007, which often incorporate multiple domains. Examples: http://www.MyPersonalDomain.com/ http://www.MyPersonalDomain.net/ http://www.MyPersonalDomain.org/ shop.MyPersonalDomain.com Phishing and Pharming — How SSL Can HelpPhishing and, recently, pharming pose constant threats to Internet users whose sensitive information is under siege by crackers and other cyber crooks. An SSL certificate from GoDaddy.com can clip the wings of Internet criminals and help prevent Internet users from being victimized by phishing and pharming schemes when attempting to visit your Web site. Phishing schemes – attempts to steal and exploit sensitive personal information – typically try to trick victims into accessing fraudulent sites that pose as legitimate, trusted entities, such as online businesses and banks. Because perpetrators of such attacks will be using and registering domains that resemble those of the spoofed sites, GoDaddy.com, through its stringent fraudprevention measures, will detect the schemes and deny certificate requests for suspicious domains. An SSL certificate from GoDaddy.com can help prevent Internet users from being victimized by phishing and pharming schemes. More sophisticated than phishing, pharming revolves around the concept of hijacking an Internet Service Provider’s (ISP) domain name server (DNS) entries. When a “pharmer” succeeds in such DNS “poisoning” every computer using that ISP for Internet access is directed to the wrong site when the user types in a URL (e.g., www.ebay.com). SSL certificate technology can help prevent pharming attacks, as well. In essence, a “pharmer” simply will not be able to obtain an SSL certificate from GoDaddy.com, as he/she does not control the domain for which the certificate is requested. By protecting your Web site with a GoDaddy.com SSL certificate, Internet users that attempt to access a site that poses as yours will be instantly alerted that there is a problem with the supposedly secure connection:
Phishing or pharming sites will not be able to obtain SSL certificates from a trusted CA. The alert Internet user will instantly abandon his/her activities/ transactions when presented with such warnings. Thus, a GoDaddy.com SSL certificate provides business owners and wary, savvy Internet users with an effective weapon against phishing, pharming and similar cyber swindles. Establishing a Secure Connection — How SSL WorksAn SSLencrypted connection is established via the SSL “handshake” process, which transpires within seconds – transparently to the end user. In essence, the SSL “handshake” works thus:
Conclusion — The Key to Online SecurityDemand for reliable online security is increasing. Despite booming online sales many consumers continue to believe that shopping online is less safe than doing so at oldfashioned brickandmortar stores. The key to establishing a successful online business is to build customer trust. Only when potential customers trust that their credit card information and personal data is safe with your business, will they consider making purchases on the Internet. With a GoDaddy.com SSL Certificate your customers will know that they can trust your business. A GoDaddy.com SSL Certificate provides a convenient, cost effective and reliable means to secure your business’s online transactions. Once installed on your business’ Web site the certificate will safeguard sensitive data by securing online transactions with up to 256bit SSL encryption. With a GoDaddy.com SSL Certificate your customers will know that they can trust your business. Applying a GoDaddy.com SSL Certificate to your online business today will secure your online sales. For more information visit Official Website. |