Digi-Sign, The Certificate Corporation
Published on Digi-Sign, The Certificate Corporation (http://www2.digi-sign.com)

Home > SSL Security Guide

By Digi-Sign
Created Feb 22 2008 - 15:16

SSL Security Guide

Why you need security for your server?

PDF [1] The Internet has created many new global business opportunities for enterprises conducting online commerce. However, the many security risks associated with conducting e-commerce have resulted in security becoming a major factor for online success or failure.

Over the past 7 years, consumer magazines, industry bodies and security providers have educated the market on the basics of online security. The majority of consumers now expect security to be integrated into any online service they use, as a result they expect any details they provide via the Internet to remain confidential and integral. For many customers, the only time they will ever consider buying your products or a service online is when they are satisfied their details are secure.

This guide explains how you can utilize Digi-SSL™ [2] to activate the core security technology available on your existing web server. You will also learn how Digi-SSL™ allows you to protect your customer's transactions and provide visitors with proof of your digital identity – essential factors in gaining confidence in your services and identity.

Using Digi-SSL™ Certificates to secure your online transactions tells your customers you take their security seriously. They will visibly see that their online transaction will be secure, confidential and integral and give them the confidence that you have removed the risk associated with trading over the Internet.


Using Security helps you realize the benefits of online commerce:

  • Cost effectiveness of online operations and delivery
  • Open global markets – gain customers from all over the world
  • New and exciting ways of marketing directly to your customers
  • Offer new data products and services via the Web



Only if you have visibly secured your site with SSL security technology will your customers have confidence in your online operations. Read on to learn how SSL helps you achieve the confidence essential to successful e-commerce.

What is SSL?

What is Secure Sockets Layer?

PDF [1] Secure Sockets Layer, SSL, is the standard security technology for creating an encrypted link between a web server and a browser. This link ensures that all data passed between the web server and browser remain private and integral. SSL is an industry standard and is used by millions of websites in the protection of their online transactions with their customers. In order to be able to generate an SSL link, a web server requires an SSL Certificate.

When you choose to activate SSL on your web server you will be prompted to complete a number of questions about the identity of your website (e.g. your website's URL) and your company (e.g. your company's name and location).


Private and Public Key

Your web server then creates two cryptographic keys – a Private Key and a Public Key. Your Private Key is so called for a reason – it must remain private and secure. The Public Key does not need to be secret and is placed into a Certificate Signing Request (CSR [3]) – a data file also containing your details. You should then submit the CSR during the SSL Certificate application process to Digi-Sign, the Digi-SSL™ Certification Authority, who will validate your details and issue an SSL Certificate containing your details and allowing you to use SSL.

Your web server will match your issued SSL Certificate to your Private Key. Your web server will then be able to establish an encrypted link between the website and your customer's web browser.


NOTE: For detailed application and installation instructions please refer to our
Digi-SSL™ Support Centre

Displaying SSL

Displaying the SSL secure padlock

PDF [1] The complexities of the SSL protocol remain invisible to your customers. Instead their browsers provide them with a key indicator to let them know they are currently protected by an SSL encrypted session – the Padlock:

IMAGE



As seen by users of Internet Explorer
Clicking on the Padlock displays your SSL Certificate and your details:

IMAGE



All SSL Certificates [4] are issued to either companies or legally accountable individuals. Typically an SSL Certificate will contain your domain name, your company name, your address, your city, your state and your country. It will also contain the expiry date of the Certificate and details of the Certification Authority responsible for the issuance of the Certificate. When a browser connects to a secure site it will retrieve the site's SSL

Certificate and check that it has not expired, it has been issued by a Certification Authority the browser trusts, and that it is being used by the website for which it has been issued. If it fails on any one of these checks the browser will display a warning to the end user.


Why should you use a Digi-SSL™ certificate?

Digi-Sign, the Certification Authority behind Digi-SSL™, is one of the fastest growing SSL Providers in the world. Unlike other Certification Authorities, Digi-Sign does not just provide SSL Certificates – they are a world-renowned security and cryptography service provider. When you are a customer of Digi-Sign, you can feel safe knowing that your website security is provided by experts. Digi-SSL™ Certificates are the most cost-effective fully validated and fully supported

128 bit SSL Certificates you can buy today! You can contact the technical support team between 7:30am - 16:00pm GMT (soon to be 24 hours). You can also feel safe in the knowledge that Digi-Sign will validate your application in accordance with the latest digital signature [5] legislation pertaining to Qualified Certificates. This validation is done effectively and quickly, ensuring you need not wait the traditional 3 working days normally associated with a fully validated SSL Certificate.

For Apache

Why you need security for your server?

PDF [1] The Internet has created many new global business opportunities for enterprises conducting online commerce. However, the many security risks associated with conducting e-commerce have resulted in security becoming a major factor for online success or failure.

Over the past 7 years, consumer magazines, industry bodies and security providers have educated the market on the basics of online security. The majority of consumers now expect security to be integrated into any online service they use, as a result they expect any details they provide via the Internet to remain confidential and integral. For many customers, the only time they will ever consider buying your products or a service online is when they are satisfied their details are secure.

IMAGE



This guide explains how you can utilize Digi-SSL™ to activate the core security technology available on your existing web server. You will also learn how Digi-SSL™ allows you to protect your customer's transactions and provide visitors with proof of your digital identity – essential factors in gaining confidence in your services and identity.

Using Digi-SSL™ Certificates to secure your online transactions tells your customers you take their security seriously. They will visibly see that their online transaction will be secure, confidential and integral and give them the confidence that you have removed the risk associated with trading over the Internet.


Using Security helps you realize the benefits of online commerce:

  • Cost effectiveness of online operations and delivery
  • Open global markets – gain customers from all over the world
  • New and exciting ways of marketing directly to your customers
  • Offer new data products and services via the Web



Only if you have visibly secured your site with SSL security technology will your customers have confidence in your online operations. Read on to learn how SSL helps you achieve the confidence essential to successful e-commerce.

What is SSL?

What is Secure Sockets Layer?

PDF [1] Secure Sockets Layer, SSL, is the standard security technology for creating an encrypted link between a web server and a browser. This link ensures that all data passed between the web server and browser remains private and integral. SSL is an industry standard and is used by millions of websites in the protection of their online transactions with their customers. In order to be able to generate an SSL link, a web server requires an SSL Certificate.

When you choose to activate SSL on your web server you will be prompted to complete a number of questions about the identity of your website (e.g. your website's URL) and your company (e.g. your company's name and location).


Private Key and Public Key

Your web server then creates two cryptographic keys – a Private Key and a Public Key. Your Private Key is so called for a reason – it must remain private and secure. The Public Key does not need to be secret and is placed into a Certificate Signing Request [CSR [3]] – a data file also containing your details. You should then submit the CSR during the SSL Certificate application process to Digi-Sign, the Digi-SSL™ Certification Authority, who will validate your details and issue an SSL Certificate containing your details and allowing you to use SSL.

Your web server will match your issued SSL Certificate to your Private Key. Your web server will then be able to establish an encrypted link between the website and your customer's web browser.


NOTE: For detailed application and installation instructions please refer to section
'Step by step instructions to set up SSL on your web server' of this guide.

Displaying SSL

Displaying the SSL secure padlock

PDF [1] The complexities of the SSL protocol remain invisible to your customers. Instead their browsers provide them with a key indicator to let them know they are currently protected by an SSL encrypted session – the Padlock:

IMAGE



As seen by users of Internet Explorer

Clicking on the Padlock displays your SSL Certificate and your details:

IMAGE



All SSL Certificates [4] are issued to either companies or legally accountable individuals. Typically an SSL Certificate will contain your domain name, your company name, your address, your city, your state and your country. It will also contain the expiry date of the Certificate and details of the Certification Authority responsible for the issuance of the Certificate. When a browser connects to a secure site it will retrieve the site's SSL

Certificate and check that it has not expired, it has been issued by a Certification Authority the browser trusts, and that it is being used by the website for which it has been issued. If it fails on any one of these checks the browser will display a warning to the end user.

Certificate SSL

Why should you use a Digi-SSL™ certificate?

PDF [1] Digi-Sign, the Certification Authority behind Digi-SSL™, is the fastest growing SSL Provider in the world. Unlike other Certification Authorities, Digi-Sign does not just provide SSL Certificates [4] – they are a world-renowned security and cryptography service provider. When you are a customer of Digi-Sign, you can feel safe knowing that your website security is provided by experts. Digi-SSL™ Certificates are the most cost-effective fully validated and fully supported

128 bit SSL Certificates you can buy today! You can contact the technical support team between 7:30am - 16:00pm GMT (soon to be 24 hours). You can also feel safe in the knowledge that
Digi-Sign will validate your application in accordance with the latest digital signature [5] legislation pertaining to Qualified Certificates. This validation is done effectively and quickly, ensuring you need not wait the traditional 3 working days normally associated with a fully validated SSL Certificate.

Digi-SSL™ boasts industry leading browser ubiquity – comparable to Verisign and Thawte, however without the costs associated with other SSL Providers. Digi-SSL™ Certificates are compatible with over 99% of browsers – including Internet Explorer 5.00 and above, Netscape 4.5 and above, AOL 6 and above and Opera 5.00 and above.


Digi-SSL™ benefits summary:

Digi-SSL™ Certificates are the most cost effective SSL Certificates you can buy which
include:

  • Full validation conducted quickly – in many cases you can expect your SSL Certificate to be issued within hours
  • Telephone, email, web support available 7:30am - 16:00pm GMT
  • Over 99% browser compatibility
  • 128-bit strong encryption security

Digi-SSL™ Certificates provide you with the key to successfully using SSL on your web server.



Testing your web server before you buy.

Try a Digi-SSL Trial™ Certificate for FREE

Trial SSL Certificates provide full SSL functionality for 14 days and are fully supported by our expert technical support staff. Unlike test Certificates from other CAs [6],
Digi-SSL Trial™ Certificates are issued using the same Trusted Root CA that issues our end-entity SSL Certificates and provides 99% browser ubiquity, and NOT by a different test CA. This unique service helps you fully test your system prior to your live roll out.

Trial SSL Certificates are ideal for anyone requiring proof of ease of installation, confirmation of high quality technical support and also confirmation of compatibility with the majority of the browsers that exist today. Trial SSL Certificates are also ideal for practicing with Certificates and learning about SSL implementation before committing to installing a Certificate on your live system.

Get your free 14-day Digi-SSL Trial™ Certificate from
https://www.digi-sign.com/product/digi-ssl [7]

Step by Step instructions

Step by step instructions to set up SSL on your Apache web server

PDF [1] There are four stages to set up SSL on your Apache web server:

    1. Create a Certificate Signing Request (CSR [3])
    2. Apply online for a Digi-SSL™ Certificate
    3. Install a Digi-SSL™ Certificate
    4. Display a Secure Digi-Seal™ Site Seal



Create a Certificate Signing Request (CSR)

A CSR is a file containing your certificate application information, including your Public Key. Generate your CSR and then copy and paste the CSR file into the web form in the enrolment process:


Generate keys and certificate:

To generate a pair of private key and public Certificate Signing Request (CSR) for a web server, "server", use the following command:

    128-bit Certificate:

    openssl req -new -newkey rsa:1024 -keyout myserver.key -nodes -out server.csr

    40-bit Certificate:

    openssl req -new -newkey rsa:512 -keyout myserver.key -nodes -out server.csr


This creates a two files. The file myserver.key contains a private key; do not disclose this file to anyone. Carefully protect the private key.

In particular, be sure to backup the private key, as there is no means to recover it should it be lost. The private key is used as input in the command to generate a Certificate Signing Request (CSR).

You will now be asked to enter details to be entered into your CSR.

What you are about to enter is what is called a Distinguished Name or a DN.

For some fields there will be a default value, If you enter '.', the field will be left blank.

    -----
    Country Name (2 letter code) [AU]: GB
    State or Province Name (full name) [Some-State]: Yorks
    Locality Name (eg, city) []: York
    Organization Name (eg, company) [Internet Widgits Pty Ltd]: MyCompany Ltd
    Organizational Unit Name (eg, section) []: IT
    Common Name (eg, YOUR name) []: mysubdomain.mydomain.com
    Email Address []:

    Please enter the following 'extra' attributes to be sent with your certificate request

    A challenge password []:
    An optional company name []:
    -----



Use the name of the web server as Common Name (CN). If the domain name is mydomain.com append the domain to the hostname (use the fully qualified domain name).

The fields email address; optional company name and challenge password can be left blank for a webserver certificate.

Your CSR will now be created. Open the server.csr in a text editor and copy and paste the contents into the online enrolment form when requested.

Online Certificate

Apply online for a Digi-SSL™ Certificate

PDF [1] Visit https://www.digi-sign.com/product/digi-ssl [7] and select your SSL Certificate product type. You will be required to submit the CSR [3] into a web form. When you make your application, make sure you include the CSR in its entirety into the appropriate section of the enrolment form. When you view your CSR it will appear something like:

IMAGE



Be sure to copy the CSR text in its entirety into the application form, including the:

IMAGE



Install a Digi-SSL™ Certificate

    Step one: Copy your certificate to file

    You will receive an email from Digi-Sign with the certificate in the email (yourdomainname.cer). When viewed in a text editor, your certificate will look something like:

    IMAGE



    Copy your Certificate into the directory that you will be using to hold your certificates. In this example we will use /etc/ssl/crt/. Both the public and private key files will already be in this directory. The private key used in the example will be labeled private.key and the public key will be yourdomainname.cer.

    It is recommended that you make the directory that contains the private key file only readable by root.

    Step two: Install the Intermediate Certificates

    You will need to install the chain certificates (intermediates) in order for browsers to trust your certificate. As well as your SSL certificate (yourdomainname.cer) two other certificates, named UTN-USERFirst-Hardware.crt and Digi-SignCADigi-SSLXp.crt or
    Digi-SignCADigi-SSLXs.crt, are also attached to the email from Digi-Sign.

    Apache users will not require these certificates. Instead you can install the intermediate certificates using a 'bundle' method.

    In the Virtual Host settings for your site, in the httpd.conf file, you will need to complete the following:

      1. Copy this ca-bundle file to the same directory as httpd.conf (this contains all of the CA certificates in the chain).

      IMAGE


Apply online Certificate II

Install the Intermediate Certificates

Add the following line to SSL section of the httpd.conf (assuming /etc/httpd/conf is the directory to where you have copied the ca.txt file). if the line already exists amend it to read the following:

    SSLCACertificateFile /etc/httpd/conf/ca-bundle/ca.txt



If you are using a different location and certificate file names you will need to change the path and filename to reflect your server.

The SSL section of the updated httpd config file should now read similar to this example (depending on your naming and directories used):

    SSLCertificateFile /etc/ssl/crt/yourdomainname.cer

    SSLCertificateKeyFile /etc/ssl/crt/private.key

    SSLCACertificateFile /etc/httpd/conf/ca-bundle/ca_new.txt

    Save your httpd.conf file and restart Apache.



Display a Secure Digi-Seal™ Site Seal

As a valued Digi-SSL™ customer we encourage you to display the Digi-SSL™ secure site seal to help promote your secure site to customers. The secure site seal is free to all
Digi-SSL™ customers.

Contact us to discuss our Digi-Seal™ technology and how providing real-time identity assurance to customers to help establish even more confidence and trust with your customers.

Certificate Classes

Different Classes of Digi-SSL™ Certificates

PDF [1] There are four main classes of Digi-SSL™ Certificate and these are explained in the following sub sections:

    Digi-SSL™ Xs
    Digi-SSL™ Xp
    Digi-SSL™ Xg

Digi-SSL™ Xs

The Digi-SSL™ Xs is for low/no value transactions. For corporate users and commercial websites the Digi-SSL™ Xp or higher class Digi-SSL™ is recommended. The Digi-SSL™ Xs should only be used to authenticate your site to visitors and although technically it can also be used for encrypting data submitted through the site, without the additional insurance cover offered by the higher classes of Digi-SSL™ the value of the transaction is not important.

The Digi-Sign Certificate Practice Statement [CPS] [8] v3.7, Sub section 2.4.1.a and 5.32.1 both state that the maximum warranty associated with a Digi-SSL™ Xs certificate is €0.01. So if your information is worth more than €0.01 and you require warranty protection, you should only use the Xs Certificate to authenticate your website. This does not mean you can’t use the Xs for encrypting data, it only means that in the event of a fault in the Digi-SSL™, you have no warranty.

Digi-SSL™ Xp

The maximum warranty associated with the Digi-SSL™ Xp or Xg Certificate is €10,000. The Certificate Practice Statement [8] v3.7, Sub section 2.4.1.b and 5.32.2, both state clearly that this is for corporate or professional use and carries a warranty in the event of failure.

Other Differences between Xp/Xg & Xs would be that

  • Xp/Xg Certificates are replaced free of charge any time during their life cycle. Xs are not.
  • Xp/Xg Certificates provide telephone support. Xs do not.
  • Xp/Xg are issued with the secure Digi-Seal™ for displaying on your website. Xs are not.

Digi-SSL™ Xg ‘Wildcard’

Digi-SSL™ Xg Certificates are only supplied in specific cases where multiple hosting specifications require flexible naming within the Digi-SSL™. This specialist configuration can include multiple Common Names within the same Certificate, wildcard facilities or a combination of these requirements.

Extended Validation

Digi-SSL™ Xe Extended Validation SSL [EV SSL]

PDF [1] Digi-SSL™ Xe Certificates are Extended Validation SSL s[EV SSLs] and were released into the market in 2007 in response to the new initiative from Microsoft® and IE7.0 where the presence of an Digi-SSL™ Xe on the server causes the IE7.0 address bar to turn green as a means of indicating to the user that the SSL is a high assurance EV SSL.

Extended Validation SSL Certificates [4] give high security Web browsers information to clearly identify a website’s identity. When a user, with a Microsoft® Internet Explorer 7, visits the website the address bar turns green. A display next to the green bar will toggle between the organization name listed in the certificate and the Certificate Authority [6] (Digi-Sign, for example). Firefox and Opera have announced their intention to support EV SSL in upcoming releases. Older browsers will display the EV SSL Certificate just as it does existing SSLs 9i.e. no discernible difference, but equally, no errors are caused).

The benefits of EV SSL are easily understood when high profile incidents of fraud and phishing scams and concerns about identity theft are considered. Before the user enters sensitive data, they want proof that the website can be trusted and that their information will be encrypted. Without it, they may decide not to do business with your site. High security browsers and EV SSL Certificates provide the assurance of extended third-party verification combined with a clear visual display that gives consumers the confidence they need to do business with you.

The high assurance SSL or EV SSL offers the website user is a competitive advantage on the internet. For organizations with a high profile, using EV SSL is the most effective defense against phishing and other Internet scams. When users see the green bar and the name of the SSL vendor, their confidence in the security and integrity of the site is naturally improved.

Digi-ISP™ Service

Digi-ISP™ Xs and Xp Service


  • Digi-ISP™ Service Xs
  • PDF [1] The Digi-ISP™ Service is almost identical to the Digi-SSL™ Service but with one important distinction: The internet Service Provider [ISP] conducts the validations [9] process under license from Digi-Sign. Once the AACD™ Contract [10] between the ISP and Digi-Sign is signed, the ISP then has the ability to issue Digi-SSL™ Certificates to any domain it chooses.

    This Service is not limited to ISPs and can include Information & Communication Technology [ICT] companies and IT Professionals that need the flexibility and convenience that Digi-ISP™ Service Xs offers.

    The Digi-ISP™ Service Xs can be operational in a matter of days (depending on the level of customization required) and there is little or no training required as it has been designed so that even ‘non-technical’ people can easily understand how to use it. Combine all of the above benefits with the built-in Account Management facility for customer billing and this becomes a powerful application to any ISP arsenal of services.

  • Digi-ISP™ Service Xp
  • Digi-ISP™ Service Xp is a further enhancement of the basic service whereby a dedicated Intermediate Root in the name of your organization is created according to the SAS70 specification for conducting Root Key Ceremonies. The Certificate Practice Statement [8] [CPS] and Certificate Policy [CP] that you agree with the Digi-CAST1™ Team will determine the type and number of separate Intermediate Roots your organization require.

    Once the CPS and CP are finalized and the Root Key Ceremony(s) is completed, the Digi-ISP™ Service Xp can be operational within 5 – 7 days, subject to Production Schedules. The following sub sections describe this important Key Ceremony in more detail.

Service

Digi-SSL™ Service

PDF [1] You may be seeking a simple solution for getting your manually managed SSL Certificates [4] or perhaps you have a larger and more specific set of requirements. You need many different Digital Certificates [5] for several organizational divisions and locations. Whether your requirement is large or small, Digi-SSL Server™ easily meets your needs.

Traditionally, organizations have to wait hours or even days for SSL Certificates. Other Certificate solutions are cumbersome, labor intensive and expensive. With Digi-SSL™ Service these issues and others are completely removed.

  • Request any Certificate and it is delivered in minutes
  • Multiple organizations, locations, and departments can all use the same system
  • Layered Security Access, enables super users, managers and ‘Read Only’ access
  • Language localization and multiple language interfaces and help files are included
  • Customizable Automated Certificate Renewal notification – no more missed renewal dates!
  • Limitless domain names are added without charge
  • Total Certificate ‘Life Cycle’ Management for all your Digi-SSLs™ using one single system
  • Total Digi-SSL™ Control without the overhead of building, managing and supporting it
  • Automated accounting facility to reduce accounts administration time



You provide us with a list of domains that you need secured and before the Digi-SSL™ Service is activated these names are thoroughly Validated. All domain name validations [9] are provided free-of-charge and once active, the Administrator is able to issue and revoke any Digi-SSL™ for any domain name in the system.


Ease of Migration

Digi-SSL™ Service combined with AACD™ means that there is no migration issue. Your purchase the amount of SSLs you need, install the DSSA™ [11] software and the AACD™ system [12] does everything else for you automatically.

Using SSL

Using Digi-SSL™

PDF [1] Secure Socket Layer [4] [SSL] server Certificates are installed on a server or device. This can be a server that hosts a website like www.digi-sign.com [13], a mail server, a directory or LDAP server, or any other type of server that needs to be authenticated, or that wants to send and receive encrypted data.


Browser Client Compatibility

The following is a list of browsers that are compatible with Digi-SSLs™, Digi-Codes™ and Digi-IDs™:

  • Microsoft® internet Explorer 5.5
  • Microsoft® internet Explorer 6.x+
  • AOL® 5+*
  • Opera 5+*
  • Safari 1.2*
  • Mozilla/5 1.7.2*
  • Firefox 1.0*
  • Netscape 4.x*
  • Netscape 8.1+*



Digi-SSL™ Service

When combined with the Automated & Authenticated Certificate Delivery™ [AACD™] [12] system the complete life cycle of the Digi-SSL™ can be automated. See the AACD™ Flash Presentation [14] for further details.

The Digi-SSL™ Service system is the Administrators’ interface for ordering additional credits for use by the ACCD™. For further information on the Digi-SSL™ Service system visit the Digi-SSL™ Service Online Demo [15].

For IIS

Why do you need security for your server?

PDF [1] The Internet has created many new global business opportunities for enterprises conducting online commerce. However, the many security risks associated with conducting e-commerce have resulted in security becoming a major factor for online success or failure.

Over the past 7 years, consumer magazines, industry bodies and security providers have educated the market on the basics of online security. The majority of consumers now expect security to be integrated into any online service they use, as a result they expect any details they provide via the Internet to remain confidential and integral. For many customers, the only time they will ever consider buying your products or services online is when they are satisfied their details are secure.

This guide explains how you can utilize Digi-SSL™ [2] to activate the core security technology available on your existing web server. You will also learn how Digi-SSL™ allows you to protect your customer's transactions and provide visitors with proof of your digital identity – essential factors in gaining confidence in your services and identity.

IMAGE



Using Digi-SSL™ Certificates to secure your online transactions tells your customers you take their security seriously. They will visibly see that their online transaction will be secure, confidential and integral and give them the confidence that you have removed the risk associated with trading over the Internet.

Using Security helps you realize the benefits of online commerce:

  • Cost effectiveness of online operations and delivery
  • Open global markets – gain customers from all over the world
  • New and exciting ways of marketing directly to your customers
  • Offer new data products and services via the Web



Only if you have visibly secured your site with SSL security technology will your customers have confidence in your online operations. Read on to learn how SSL helps you achieve the confidence essential to successful e-commerce.

What is SSL?

What is Secure Sockets Layer?

PDF [1] Secure Sockets Layer, SSL, is the standard security technology for creating an encrypted link between a web server and a browser. This link ensures that all data passed between the web server and browser remains private and integral. SSL is an industry standard and is used by millions of websites in the protection of their online transactions with their customers. In order to be able to generate an SSL link, a web server requires an SSL Certificate.

When you choose to activate SSL on your web server you will be prompted to complete a number of questions about the identity of your website (e.g. your website's URL) and your company (e.g. your company's name and location).

Private and Public Key

Your web server then creates two cryptographic keys – a Private Key and a Public Key. Your Private Key is so called for a reason – it must remain private and secure. The Public Key does not need to be secret and is placed into a Certificate Signing Request (CSR [3]) – a data file also containing your details. You should then submit the CSR during the SSL Certificate application process to Digi-Sign, the Digi-SSL™ Certification Authority, who will validate your details and issue an SSL Certificate containing your details and allowing you to use SSL.

Your web server will match your issued SSL Certificate to your Private Key. Your web server will then be able to establish an encrypted link between the website and your customer's web browser.


NOTE: For detailed application and installation instructions please refer to section
'Step by step instructions to set up SSL on your web server' of this guide.

Displaying SSL

Displaying the SSL secure padlock

PDF [1] The complexities of the SSL protocol remain invisible to your customers. Instead their browsers provide them with a key indicator to let them know they are currently protected by an SSL encrypted session – the Padlock:

IMAGE



As seen by users of Internet Explorer

Clicking on the Padlock displays your SSL Certificate and your details:

IMAGE



All SSL Certificates [4] are issued to either companies or legally accountable individuals. Typically an SSL Certificate will contain your domain name, your company name, your address, your city, your state and your country. It will also contain the expiry date of the Certificate and details of the Certification Authority responsible for the issuance of the Certificate. When a browser connects to a secure site it will retrieve the site's SSL

Certificate and check that it has not expired, it has been issued by a Certification Authority the browser trusts, and that it is being used by the website for which it has been issued. If it fails on any one of these checks the browser will display a warning to the end user.


Why should you use an Digi-SSL™ certificate?

Digi-Sign, the Certification Authority behind Digi-SSL™, is the fastest growing SSL Provider in the world. Unlike other Certification Authorities, Digi-Sign does not just provide SSL Certificates – they are a world-renowned security and cryptography service provider. When you are a customer of Digi-Sign, you can feel safe knowing that your website security is provided by experts. Digi-SSL™ Certificates are the most cost-effective fully validated and fully supported

128 bit SSL Certificates you can buy today! You can contact the technical support team between 7:30am - 16:00pm GMT (soon to be 24 hours). You can also feel safe in the knowledge that
Digi-Sign will validate your application in accordance with the latest digital signature [5] legislation pertaining to Qualified Certificates. This validation is done effectively and quickly, ensuring you need not wait the traditional 3 working days normally associated with a fully validated SSL Certificate.

Benefits Displaying SSL

PDF [1] Digi-SSL™ boasts industry leading browser ubiquity – comparable to Verisign and Thawte, however without the costs associated with other SSL Providers. Digi-SSL™ Certificates are compatible with over 99% of browsers – including Internet Explorer 5.00 and above, Netscape 4.5 and above, AOL 6 and above and Opera 5.00 and above.


Digi-SSL™ benefits summary:

Digi-SSL™ Certificates are the most cost effective SSL Certificates [4] you can buy which
include:

  • Full validation conducted quickly – in many cases you can expect your SSL
    Certificate to be issued within hours
  • Telephone, email, web support available 7:30am - 16:00pm GMT
  • Over 99% browser compatibility
  • 128-bit strong encryption security


Digi-SSL™ Certificates provide you with the key to successfully using SSL on your web server.


Testing your web server before you buy.

Try a Digi-SSL Trial™ Certificate for FREE

Trial SSL Certificates [4] provide full SSL functionality for 14 days and are fully supported by our expert technical support staff. Unlike test Certificates from other CAs [6],
Digi-SSL Trial™ Certificates are issued using the same Trusted Root CA that issues our end-entity SSL Certificates and provides 99% browser ubiquity, and NOT by a different test CA. This unique service helps you fully test your system prior to your live roll out.

Trial SSL Certificates are ideal for anyone requiring proof of ease of installation, confirmation of high quality technical support and also confirmation of compatibility with the majority of the browsers that exist today. Trial SSL Certificates are also ideal for practicing with Certificates and learning about SSL implementation before committing to installing a Certificate on your live system.

Get your free 14-day Digi-SSL Trial™ Certificate from
https://www.digi-sign.com/product/digi-ssl [7]

Step by Step Instructions

Step by step instructions to set up SSL on your Microsoft IIS 5x web server

PDF [1] There are four stages to set up SSL on your Microsoft IIS 5x web server:

    1. Create a Certificate Signing Request (CSR [3])
    2. Apply online for a Digi-SSL™ Certificate
    3. Install a Digi-SSL™ Certificate
    4. Display a Secure Digi-Seal™ Site Seal



Create a Certificate Signing Request (CSR)

A CSR is a file containing your certificate application information, including your Public Key. Generate your CSR and then copy and paste the CSR file into the web form in the enrolment process:

Generate keys and Certificate Signing Request:

  • Select Administrative Tools
  • Start Internet Services Manager

  • IMAGE


  • Open the properties window for the website the CSR is for. You can do this by right clicking on the Default Website and selecting Properties from the menu
  • Open Directory Security by right clicking on the Directory Security tab

  • IMAGE


  • Click Server Certificate. The following Wizard will appear:

  • IMAGE


  • Click Create a new certificate and click Next.

  • IMAGE


  • Select Prepare the request and click Next.

  • IMAGE


  • Provide a name for the certificate, this needs to be easily identifiable if you are working with multiple domains. This is for your records only.
  • If your server is 40 bit enabled, you will generate a 512 bit key. If your server is 128 bit you can generate up to 1024 bit keys. We recommend you stay with the default of 1024 bit key if the option is available. Click Next


Step by Step

PDF [1]

IMAGE


  • Enter Organization and Organization Unit, these are your company name and department respectively. Click Next.

  • IMAGE


  • The Common Name field should be the Fully Qualified Domain Name (FQDN) or the web address for which you plan to use your Certificate, e.g. the area of your site you wish customers to connect to using SSL. For example, a Digi-SSL™ Certificate issued for
    digi-sign.com will not be valid for secure.digi-sign.com. If the web address to be used for SSL is secure.digi-sign.com, ensure that the common name submitted in the CSR [3] is secure.digi-sign.com. Click Next.

  • IMAGE


  • Enter your country, state and city. Click Next.

  • IMAGE


  • Enter a filename and location to save your CSR. You will need this CSR to enroll for your Certificate. Click Next.

  • IMAGE


  • Check the details you have entered. If you have made a mistake click Back and amend the details. Be especially sure to check the domain name the Certificate is to be "Issued To". Your Certificate will only work on this domain. Click Next when you are happy the details are absolutely correct.

Apply online

Apply online for a Digi-SSL™ Certificate

PDF [1] Visit https://www.digi-sign.com/product/digi-ssl [7] and select your SSL Certificate product type. You will be required to submit the CSR [3] into a web form. When you make your application, make sure you include the CSR in its entirety into the appropriate section of the enrollment form. When you view your CSR it will appear something like:

IMAGE



Be sure to copy the CSR text in its entirety into the application form, including the:

IMAGE



Install a Digi-SSL™ Certificate

Installing the Root & Intermediate Certificates

When your Digi-SSL™ Certificate has been issued you will receive 3 Certificates via email from Digi-Sign Security Services. Save these Certificates to the desktop of the webserver machine, then:


A: To install the UTN-USERFirst-Hardware.crt Certificate:


IMAGE


  • Right click the Trusted Root Certification Authorities, select All Tasks, and select Import.

  • IMAGE


  • Click Next.

  • IMAGE


  • Locate the UTN-USERFirst-Hardware.crt Certificate and click Next.
  • When the wizard is completed, click Finish.



B: To install the Digi-SignCADigi-SSLXp.crt or Digi-SignCADigi-SSLXs.crt:

IMAGE


  • Right click the Intermediate Certification Authorities, select All Tasks, select Import.
  • Complete the import wizard again, but this time locating the Digi-SignCADigi-SSLXp.crt or Digi-SignCADigi-SSLXs.crt when prompted for the Certificate file.
  • Ensure that the UTN-USERFirst-Hardware root certificate appears under Trusted Root Certification Authorities
  • Ensure that the Digi-Sign CA Digi-SSL Xs or Digi-Sign CA Digi-SSL Xp appears under Intermediate Certification Authorities


SSL Certificate Installation

Install a Digi-SSL™ Certificate

  • PDF [1] Select Administrative Tools
  • Start Internet Services Manager

  • IMAGE


  • Open the properties window for the website. You can do this by right clicking on the Default Website and selecting Properties from the menu.
  • Open Directory Security by right clicking on the Directory Security tab

  • IMAGE


  • Click Server Certificate. The following Wizard will appear:

  • IMAGE


  • Choose to Process the Pending Request and Install the Certificate. Click Next.
  • Enter the location of your certificate (you may also browse to locate your certificate), and then click Next.
  • Read the summary screen to be sure that you are processing the correct certificate, and then click Next.
  • You will see a confirmation screen. When you have read this information, click Next.
  • You now have a server certificate installed.



Important: You must now restart the computer to complete the installation

Open the Properties of the default website and ensure that SSL port contains the number 443 (it should default to this number automatically). You may want to test the Web site to ensure that everything is working correctly. Be sure to use https:// when you test connectivity to the site.


Display a Secure Digi-Seal™ Site Seal

As a valued Digi-SSL™ customer we encourage you to display the Digi-SSL™ secure site seal to help promote your secure site to customers. The secure site seal is free to all Digi-SSL™ customers.

Contact us to discuss our Digi-Seal™ technology and how providing real-time identity assurance to customers to help establish even more confidence and trust with your customers.

Reasons for Choosing Digi-SSL™ Service

Read more on why you should choose Digi-Sign [16]

Centralised Management  

Individual SSLs ordered on line on an 'as needed basis' are very difficult to manage. However, the Digi-SSL™ Service system is a capable of delivering multiple SSLs to even the most complex of organisational structures and is easily managed from the 'Control Centre'.

This is because the Digi-CA™ [17] certificate authority system used to run the Digi-SSL™ Service comes complete with a web based ‘system management centre’ for all operated CAs, RAs & LRAs that make it ideal for operating and controlling all your SSLs across the entire organisation

     
Less 'administration' time   With Digi-SSL™ Service, your accounts personnel and managers can have direct access to the system for billing and querying without affect the security or integrity of the security policy in operation.  So there is no time lost filling reports, issuing inter-departmental billing or answering general queries
     
‘futureproof’   By its very design [18], the entire Digi-CA™ system can be in house, totally out sourced or a combination of the two and this can be decided at any stage during the life of the system. So you can purchase what you need today, safe in the knowledge that you can easily migrate [19] and move all or part of the system to meet future demands
     
Easy migration from RSA®, VeriSign®, etc   Digi-CA™ is probably the only commercial CA system specifically designed to migrate [19] any Traditional CA environment (for example RSA®, VeriSign®, etc) into a newly setup Digi-CA™ system by complying with international industry standards
     
Free certificate replacement   Then there's the issue of replacement: with the Digi-SSL™ Service system, every certificate is replaceable, without cost, during its full life cycle. For example: 6 months after you buy one of these cheaper alternatives you upgrade or migrate [19] your service to another server or platform, then you will have to buy new certificates from them but from us, they are replaced free of charge
     
Security & integrity of your SSLs   We still follow best practice when the validating the rightful owner for any SSL. This means that your SSLs are fully vetted and validated before they're issued using the recognised system of on person validating, a second verifying and a third issuing. Cheaper alternatives issue their SSLs automatically and without human intervention. This method, although functionally okay, raises some significant security issues that we have never considered worth the risk
     
Ease of integration   Whether now or in the future, because it is LDAPv3 compliant, Digi-CA™ can publish X.509 certificates and Certificate Revocation Lists [CRL] to other directories. This is a significant factor when considering integration with existing or future environments
     
Scalability   Digi-CA™ is the only software that can scale a ‘live’ production environment from 100s to 1,000,000s of certificates without any service interruption. This is important when considering the future growth an continued operation of your environment and requirements
     
Customisation to your requirements   Custom multi-layer CA hierarchy, RA and LRA distribution is possible and can be modified, extended and changed at any stage, any time, by your trained CA Administrators. This can also be done without affecting the operation of the live environment
     
‘look & feel’ customisation   The entire Digi-CA™ system interfaces and all its levels can be easily changed using Cascade Style Sheet [CSS]. This ability to completely change the ‘look and feel’ of the system eases the deployment to your end users because they know you but may not be familiar with the CA vendor.  It also helps with integrating into web sites and other online systems seamlessly
     
RA Flexibility   Multiple independent Registration Authority [RA] instances from a single system without needing to install multiple applications on multiple servers to run each RA
     
100% browser independent & compatible   100% certificate enrolment web browser platform and operating system independence is a component part of Digi-CA™ as is the compatibility of the Digi-SSL™ certificates when being considered for internet browsers and mobile web browsers
     
Used by many of the world's largest companies   Organisations such as Marsh & Mc Lennan, Vodafone, Securicor/G4S, Axa and many others [20] are long established customers and there are also several letters of reference [21] to further support our bona fides
     
Overall most capable & most competitively priced   Digi-CA™ achieves the best blend of meeting your current requirements and possible future ones too. It’s highly customisable and flexible features means it will meet future demands easily, without incurring downtime, service interruption or unwieldy costs
     

Why you should choose Digi-Sign [16]


Upgrading/Migrating

Getting the best from Digi-SSL™ Service

Unlike any other CA system in the market, Digi-SSL™ is specifically designed to easily migrate any other existing SSL Management system you currently use. By design Digi-CA™ [22], as a entirely self dependent system, allows easy migration of set of data into the system in a seamless manner. The transfer is accomplished physically by the Digi-CAST™ Team [2].

For security reasons, there is no .csv flat file export capability within Digi-SSL™ Service system. This is to protect the security of the data and to avoid service interruption or corruption as a result of data corruption. Therefore, if you are an existing Digi-SSL™ Service user and are upgrading or updating, much of this must be conducted by the Digi-CAST™ Team.

Image [23]

Using the "Search Results Digi-SSL™" component of the system, the Digi-CAST™ Team will reassign Administrators and Reminders for each of your Digi-SSL™ Certificates. This reassignment is carried out on explicit instructions from the Customer/Administrator and is typically conducted from a list of all the hostnames in the system.

For further assistance Digi-SSL™ Service Support Team [24]


Introducing Digi-SSL™

The Corporate Choice

PDF [1] The following sub sections detail the different Types of Certificate and the correct Class depending on your requirement.


Digi-SSL™ Certificates

Digi-SSLs™ are Secure Socket Layer [SSL] [4] Certificates and are used for securing and authenticating the following:

                  • web server
                  • mail server
                  • LDAP directory server
                  • database server



Digi-SSLs™ are the most commonplace Digital Certificate [5] in use today. Web sites and other servers use Digi-SSLs™ in their thousands each year. If your requirement is predominantly for SSL and SSL Management, we recommend the Digi-SSL™ Service. And to completely automate the entire life cycle of your SSL environment, see the Automated & Authenticated Certificate Delivery™ System [12]


Digi-SSL™ Xs, Xp & Xg

Digi-SSL™ provides you with two functions:

  • Website authentication
  • Data encryption



Every application for any class of Digi-SSL™ is subjected to the Triple-Check Validations™ procedure. This means that two or more Validations Officers physically check your details and entitlement to get the Digi-SSL™ before it is issued to you. This rigorous checking procedure protects you from someone else stealing your online identity because the Digi-Sign Triple-Check Validations™ has a 100% track record of never issuing a Digital Certificate to the wrong party. Once this Digi-SSL™ is put on your website, visitors know your site is genuine.

The same Digi-SSL™ that authenticates your site to visitors can also be used for encrypting data and it is here that the Xp/Xg and Xs difference occurs. The main difference between Xp/Xg & Xs is that the Digi-SSL™ Xs is for low/no value transactions and Xp/Xg is for corporate users and commercial websites.

The Digi-Sign Certificate Practice Statement [8] [CPS] v3.7, Sub section 2.4.1.a and 5.32.1 both state that the maximum warranty associated with a Digi-SSL™ Xs certificate is €0.01. So if your information is worth more than €0.01 and you require warranty protection, you should only use the Xs Certificate to authenticate your website. This does not mean you can’t use the Xs for encrypting data, it only means that in the event of a fault in the Digi-SSL™, you have no warranty.

The maximum warranty associated with the Digi-SSL™ Xp or Xg Certificate is €10,000. The CPS v3.7, Sub section 2.4.1.b and 5.32.2, both state clearly that this is for corporate or professional use and carries a warranty in the event of failure.


Other Differences between Xp/Xg & Xs would be that:

  • Xp/Xg Certificates are replaced free of charge any time during their life cycle. Xs are not.

  • Xp/Xg Certificates provide telephone support. Xs do not.

  • Xp/Xg are issued with the secure Digi-Seal™ for displaying on your website. Xs are not.


IMAGE



Digi-SSL™ Xg Certificates are only supplied in specific cases where multiple hosting specifications require flexible naming within the Digi-SSL™. This specialist configuration can include multiple Common Names within the same Certificate, wildcard facilities or a combination of these requirements.

Digi-SSL™ - Site Seal

Giving Your Customers Confidence
PDF [1] The secure site seal for your Digi-SSL™ [2] is an important part of your internet security strategy. It advises visitors to your site that your site is authentic and that it has been validated by a Trusted Third Party [25]. As a result your customers will have the confidence to communicate and transact business with your web site.
Why you should use the Site Seal
  • The Digi-SSL™ Site Seal provides the instant stamp of security for your web site.
  • You can leverage this brand security to make your online customers even more secure and confident that they can trust your business.
  • Allow your visitors to check your Digi-SSL™ Certificates information and status in 'real time'.
  • The Digi-SSL™ Site Seal provides additional protection against the misuse of revoked and expired certificates.
  • Your site visitors can instantly recognize that your website is secure and is a trusted website.
Why users trust the Site Seal
By simply clicking on the Secure Site Seal:
  • Digi-SSL™ Site Seal explains the importance of security on the internet.
  • Site visitors are advised that your site has been carefully validated by an independent third party and determines the validity period for your Business's Digi-SSL™ certificates, thus providing them with total confidence to conduct business on-line.
  • Site visitors know that the Digi-SSL™ Site Seal means it is safe to send secure data to the web site because it is encrypted in transit.
Advice & On Line Buying Options [26]
Multiple Digi-SSL™ Certificates are issued and managed by the Digi-CA™ Service [17] from outside your organisation. If you require 10-20,000 SSLs per annum you may want to consider the installed software (Digi-CA™ Server [27]) system, depending on your requirements.
  • Buy a single Digi-SSL™ On line [26] now
  • Buy Digi-SSL™ Service On line [26] now

More Information >> [28]

Body_Column_1: 

Giving Your Customers Confidence

PDF [1] The secure site seal for your Digi-SSL™ [2] is an important part of your internet security strategy. It advises visitors to your site that your site is authentic and that it has been validated by a Trusted Third Party [25]. As a result your customers will have the confidence to communicate and transact business with your web site.

Why you should use the Site Seal

  • The Digi-SSL™ Site Seal provides the instant stamp of security for your web site.

  • You can leverage this brand security to make your online customers even more secure and confident that they can trust your business.

  • Allow your visitors to check your Digi-SSL™ Certificates information and status in 'real time'.

  • The Digi-SSL™ Site Seal provides additional protection against the misuse of revoked and expired certificates.

  • Your site visitors can instantly recognize that your website is secure and is a trusted website.


Body_Column_2: 

Why users trust the Site Seal

By simply clicking on the Secure Site Seal:

  • Digi-SSL™ Site Seal explains the importance of security on the internet.

  • Site visitors are advised that your site has been carefully validated by an independent third party and determines the validity period for your Business's Digi-SSL™ certificates, thus providing them with total confidence to conduct business on-line.

  • Site visitors know that the Digi-SSL™ Site Seal means it is safe to send secure data to the web site because it is encrypted in transit.


Advice & On Line Buying Options [26]

Multiple Digi-SSL™ Certificates are issued and managed by the Digi-CA™ Service [17] from outside your organisation. If you require 10-20,000 SSLs per annum you may want to consider the installed software (Digi-CA™ Server [27]) system, depending on your requirements.

  • Buy a single Digi-SSL™ On line [26] now
  • Buy Digi-SSL™ Service On line [26] now




More Information >> [28]


  • Security Guide

Source URL: http://www2.digi-sign.com/ssl

Links:
[1] https://www.digi-sign.com/downloads/download.php?id=aacd-digi-ssl-pdf
[2] http://www2.digi-sign.com/digi-ssl
[3] http://www2.digi-sign.com/support/digi-ssl/generate+csr
[4] http://www2.digi-sign.com/ssl+certificate
[5] http://www2.digi-sign.com/digital+certificate
[6] http://www2.digi-sign.com/certificate+authority
[7] https://www.digi-sign.com/product/digi-ssl
[8] http://www2.digi-sign.com/repository/certificate+practice+statement
[9] http://www2.digi-sign.com/validations
[10] http://www2.digi-sign.com/repository/contracts/aacd
[11] http://www2.digi-sign.com/aacd/daemon+server+side+application
[12] http://www2.digi-sign.com/aacd
[13] http://www.digi-sign.com
[14] http://www2.digi-sign.com/demos/aacd
[15] http://www2.digi-sign.com/demos/digi-ssl
[16] http://www2.digi-sign.com/about/choosing+digi-sign
[17] http://www2.digi-sign.com/digi-ca/service
[18] http://www2.digi-sign.com/demos/digi-ca+presentation
[19] http://www2.digi-sign.com/digi-ssl/migration
[20] http://www2.digi-sign.com/about/testimonials
[21] http://www2.digi-sign.com/about/references
[22] http://www2.digi-sign.com/digi-ca
[23] http://www.digi-sign.com/demoexec/digi-ca/rev-digi-ssl1.php
[24] http://www2.digi-sign.com/contact
[25] http://www2.digi-sign.com/digi-trust/trusted+services+provider
[26] http://www2.digi-sign.com/https
[27] http://www2.digi-sign.com/digi-ca/server
[28] http://www2.digi-sign.com/en/aacd/index