Computer Forums

Member Login

Remember Me? Sign Up! | Forgot Password
 
Slogan
 
Computer Forums > Programmers Lounge > Programming Discussions » Importance of SSL Certificates
Closed Thread
Old 11-18-2006, 08:41 AM   #1 (permalink)
 
Banned

Join Date: Nov 2006

Posts: 1

falcon

Default Importance of SSL Certificates

Hello friends,

The SSL protocol allows client/server applications to communicate in a way designed to prevent eavesdropping, tampering, and data forgery. SSL protects network access, online communications, and digital transactions by enabling a secure channel between your servers and your users. With SSL in place, information transmitted from your online store (e.g., via web forms) is encrypted before it is sent over the Internet.

I've got SSL Certificate for my own site and getting advantages of

[SNIPPED]

jenny
falcon is offline  
Old 11-19-2006, 02:37 AM   #2 (permalink)
 
Super Techie

Join Date: Oct 2006

Posts: 263

penfold

Default

It is possible to create one's own secure certificate. While purchasing one from an established company sometimes seems "better," it is definitely more expensive. Creating one's own certificate is just as secure, however.
__________________
---
penfold

www.futurelooks.com/
www.megatechnews.com
penfold is offline  
Old 11-19-2006, 11:35 AM   #3 (permalink)
Chankama's Avatar
 
Monster Techie

Join Date: Jan 2005

Location: Canada

Posts: 1,522

Chankama will become famous soon enough

Default

Quote:
Originally posted by penfold
Creating one's own certificate is just as secure, however.
It is not - with respect to establishing a secure channel.

The whole idea of a PKI is to allow end-clients who have no notion of who you are to establish a trust relationship with you.

Obviously, you can make the key in the certificate just as secure as common root certificates issued by Verisign for example - but how it fits into the PKI system is completely different.

The root certificates are already installed in many applications that ship to home users - like browsers. If you are Company X, with your own generated certificate, a customer will not know whether your certificate is authentic. I could create another certrificate and call it "Company X" and send it to the customer pretending to be you. The communication will be secure of course - but he's communicating with me.. And not you..

When you go to someone like Verisign, they will generate the certificate and "SIGN" it with their private key. Then the customer can verify the authenticity of the certificate since they have Verisign's certificate on their system. There are millions of companies.. Users don't have the certificate of all of them pre-installed. That's why root certificates are important.

Finally, Verisign needs to verify that it is really you by some other means before they actually issue the certificate to Company X. That way I can't go to them and say I am from Company X and that I need a certificate. This happened to Microsoft in the past - twice I believe. They had to revoke those 2 certificates through Certificate Revokation Lists.

Quote:
Originally posted by falcon

I've got SSL Certificate for my own site and getting advantages of

[SNIPPED]
jenny
This is Spam.
Chankama is offline  
 
Closed Thread

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On