Beginners Guide To Ssl Certificates

User Manual:

Open the PDF directly: View PDF PDF.
Page Count: 8

DownloadBeginners-guide-to-ssl-certificates
Open PDF In BrowserView PDF
WHITE PAPER:
BEGINNER’S GUIDE TO
SSL CERTIFICATES

White Paper

Beginner’s Guide to
SSL Certificates
Making the Best Choice When Considering
Your Online Security Options

White Paper: Beginner’s Guide to SSL Certificates

Beginner’s Guide to SSL Certificates
Making the Best Choice When Considering
Your Online Security Options
CONTENTS
Introduction .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 3
What is an SSL Certificate? .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 3
How Does SSL Encryption Work? .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 3
How Do I Know That a Site Has a Valid SSL Certificate?  .  .  .  .  .  .  .  .  .  .  .  .  .  . 4
Where Would I Use an SSL Certificate?  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 5
Different Types of SSL Certificate  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 5
Tech Talk Made simple  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 6
Conclusion  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 7

2

White Paper: Beginner’s Guide to SSL Certificates

Introduction
Whether you are an individual or a company, you should approach online security
in the same way that you would approach physical security for your home or
business. Not only does it make you feel safer but it also protects people who
visit your home, place of business, or website. It is important to understand the
potential risks and then make sure you are fully protected against them. In the
fast-paced world of technology, it is not always easy to stay abreast of the latest
advancements. For this reason it is wise to partner with a reputable Internet
security company.
This guide will de-mystify the technology involved and give you the information
you need to make the best decision when considering your online security options.
For a glossary of terms, please see “Tech Talk Made Simple” at the end of
this document.
What Is an SSL Certificate?
An SSL certificate is a digital computer file (or small piece of code) that has two
specific functions:
1.	 Authentication and Verification: The SSL certificate has information about
the authenticity of certain details regarding the identity of a person, business or
website, which it will display to visitors on your website when they click on the
browser’s padlock symbol or trust mark (e.g., the Norton™ Secured Seal). The
vetting criteria used by Certificate Authorities to determine if an SSL certificate
should be issued is most stringent with an Extended Validation (EV) SSL
certificate; making it the most trusted SSL certificate available.

SSL stands for “Secure Socket
Layer.” It is a technology that
establishes a secure session
link between the visitor’s web
browser and your website so that
all communications transmitted
through this link are encrypted and
are, therefore, secure. SSL is also
used for transmitting secure email,
secure files, and other forms of
information.
Would you send your private
information or banking details to
someone on the back of a postcard?

SSL creates a safe and private
channel for you to communicate.

2.	 Data Encryption: The SSL certificate also enables encryption, which means that
the sensitive information exchanged via the website cannot be intercepted and
read by anyone other than the intended recipient.
In the same way that a identity document or passport may only be issued by the
country’s government officials, an SSL certificate is most reliable when issued by a
trusted Certificate Authority (CA). The CA has to follow very strict rules and policies
about who may or may not receive an SSL certificate. When you have a valid SSL
certificate from a trusted CA, there is a higher degree of trust by your customers,
clients or partners.
How Does SSL Encryption Work?
In the same way that you lock and unlock doors using a key, encryption makes use
of keys to lock and unlock your information. Unless you have the right key, you will
not be able to “open” the information.
Each SSL session consists of two keys:
• The public key is used to encrypt (scramble) the information.
• The private key is used to decrypt (un-scramble) the information and restore it
to its original format so that it can be read.

3

White Paper: Beginner’s Guide to SSL Certificates

The Process: Every SSL certificate that is issued for a CA-verified entity is issued
for a specific server and website domain (website address). When a person uses
their browser to navigate to the address of a website with an SSL certificate, an
SSL handshake (greeting) occurs between the browser and server. Information
is requested from the server – which is then made visible to the person in their
browser window. You will notice changes to indicate that a secure session has been
initiated – for example, a trust mark will appear.If you click on the trust mark, you
will see additional information such as the validity period of the SSL certificate, the
domain secured, the type of SSL certificate, and the issuing CA. All of this means
that a secure link is established for that session, with a unique session key, and
secure communications can begin.
How Do I Know That a Site Has a Valid SSL Certificate?
1.	 A standard website without SSL security displays “http:// ” before the website
address in the browser address bar. This moniker stands for “Hypertext
Transfer Protocol,” and is the conventional way to transmit information over
the Internet.

However, a website that is secured with a SSL certificate will display “https:// ”
before the address. This stands for “Secure HTTP.”

2.	 You will also see a padlock symbol on the top or bottom of the Internet browser
(depending on which browser you are using).
3.	 Often, you will also notice a trust mark displayed on the website itself.
Symantec™ customers use the Norton Secured Seal trust mark on their
websites. When you click on the Norton Secured Seal or the padlock symbol
on the page, it will display details of the certificate with all the company
information as verified and authenticated by the CA.
4.	 By clicking the closed padlock in the browser window, or certain SSL trust marks
such as the Norton Secured Seal, the website visitor sees the authenticated
organization name. In high-security browsers, the authenticated organization
name is prominently displayed and the address bar turns green when an
4

White Paper: Beginner’s Guide to SSL Certificates

Extended Validation (EV) SSL certificate is detected. If the information does
not match, or the certificate has expired, the browser displays an error
message or warning.
Where Would I Use an SSL Certificate?
The short answer to this question is that you would use an SSL certificate anywhere
that you wish to transmit information securely.
Here are some examples:
• Securing communication between your website and your customer’s Internet
browser.
• Securing internal communications on your corporate intranet.
• Securing email communications sent to and from your network (or private email
address).
• Securing information between servers (both internal and external).
• Securing information sent and received via mobile devices.
Different Types of SSL Certificates
There are a number of different SSL certificates on the market today.
• The first type of SSL certificate is a self-signed certificate. As the name implies,
this is a certificate that is generated for internal purposes and is not issued by a
CA. Since the website owner generates their own certificate, it does not hold the
same weight as a fully authenticated and verified SSL certificate issued by a CA.
• A Domain Validated certificate is considered an entry-level SSL certificate
and can be issued quickly. The only verification check performed is to ensure
that the applicant owns the domain (website address) where they plan to use
the certificate. No additional checks are done to ensure that the owner of the
domain is a valid business entity.
• A fully authenticated SSL certificate is the first step to true online security and
confidence building. Taking slightly longer to issue, these certificates are only
granted once the organization passes a number of validation procedures and
checks to confirm the existence of the business, the ownership of the domain,
and the user’s authority to apply for the certificate.
All Symantec SSL Certificates are fully authenticated.
• Even though an SSL certificate is capable of supporting 128-bit or 256-bit
encryption, certain older browsers and operating systems still cannot connect
at this level of security. SSL certificates with a technology called Server-Gated
Cryptography (SGC) enable 128- or 256-bit encryption to over 99.9 percent of
website visitors. Without an SGC certificate on the Web server, browsers and
operating systems that do not support 128-bit strong encryption will receive
only 40- or 56-bit encryption. Users with certain older browsers and operating
systems will temporarily step-up to 128-bit SSL encryption if they visit a
website with an SGC-enabled SSL certificate. For more information about SGC
please visit: http://go.symantec.com/ssl-certificates.
5

White Paper: Beginner’s Guide to SSL Certificates

• A domain name is often used with a number of different host suffixes. For this
reason, you may employ a Wildcard certificate that allows you to provide full
SSL security to any host of your domain – for example, host.your_domain.com
(where “host” varies but the domain name stays constant).
• Similar to a Wildcard certificate, but a little more versatile, the SAN (Subject
Alternative Name) SSL certificate allows for more than one domain to be added
to a single SSL certificate.
• Code signing certificates are specifically designed to ensure that the software
you have downloaded was not tampered with while en route. There are many
cybercriminals who tamper with software available on the Internet. They may
attach a virus or other malicious software to an innocent package as it is being
downloaded. These certificates make sure that this doesn’t happen.
• Extended Validation (EV) SSL certificates offer the highest industry standard
for authentication and provide the best level of customer trust available. When
consumers visit a website secured with an EV SSL certificate, the address bar
turns green (in high-security browsers) and a special field appears with the
name of the legitimate website owner along with the name of the security
provider that issued the EV SSL certificate. It also displays the name of the
certificate holder and issuing CA in the address bar. This visual reassurance has
helped increase consumer confidence in e-commerce.
Tech Talk Made Simple
Encryption: Information is “scrambled” so that it cannot be used by anyone other
than the person for whom it is intended.
Decryption: “Un-scrambling” information and put it back in its original format.
Key: A mathematical formula, or algorithm, that is used to encrypt or decrypt your
information. In the same way that a lock with many different combinations is more
difficult to open, the longer the length of the encryption key (measured in number
of bits), the stronger the encryption.
Browser: A software program that you use to access the Internet. Examples
include: Microsoft Internet Explorer (IE); Mozilla Firefox, Apple Safari, RockMelt,
and Google Chrome.

6

White Paper: Beginner’s Guide to SSL Certificates

Conclusion
Trust makes all the difference in the world of online business. Investment in
technology to protect customers and earn their trust is a critical success factor
for any company that does business online or hosts an e-commerce website. The
effective implementation of SSL certificates and correct placement and use of trust
marks are proven tools in the establishment of customer trust.
With the acquisition of VeriSign Authentication Services, Symantec is now the
leading provider of SSL certificates globally, helping to assure customers that
they are safe from search to browse to buy and sign in*. Symantec secures more
than one million web servers worldwide, more than any other CA.* Symantec also
secures over two-thirds of websites using Extended Validation SSL – including the
biggest names in e-commerce and banking.* When you choose Symantec, you can
rest assured that your website and your reputation are protected by the CA with a
proven track record and the most recognized trust mark on the Internet.
For more information, visit us at http://go.symantec.com/ssl-certificates.

*Includes Symantec subsidiaries, affiliates, and resellers.

7

White Paper: Beginner’s Guide to SSL Certificates

More Information
Visit our website
http://go.symantec.com/ssl-certificates
To speak with a Product Specialist in the U.S.
Call toll-free 1 (866) 893-6565
To speak with a Product Specialist outside the U.S.
For specific country offices and contact numbers, please visit our website.
About Symantec
Symantec is a global leader in providing security, storage, and systems
management solutions to help consumers and organizations secure and manage
their information-driven world. Our software and services protect against more
risks at more points, more completely and efficiently, enabling confidence
wherever information is used or stored.
Symantec Corporation World Headquarters
350 Ellis Street
Mountain View, CA 94043 USA
1 (866) 893 6565
www.symantec.com

Copyright © 2012 Symantec Corporation. All rights reserved. Symantec, the Symantec Logo, and the Checkmark Logo are trademarks or registered trademarks of Symantec Corporation or its affiliates in
the U.S. and other countries. VeriSign and other related marks are the trademarks or registered trademarks of VeriSign, Inc. or its affiliates or subsidiaries in the U.S. and other countries and licensed to
Symantec Corporation. Other names may be trademarks of their respective owners.



Source Exif Data:
File Type                       : PDF
File Type Extension             : pdf
MIME Type                       : application/pdf
PDF Version                     : 1.4
Linearized                      : Yes
Tagged PDF                      : Yes
XMP Toolkit                     : Adobe XMP Core 4.2.2-c063 53.352624, 2008/07/30-18:05:41
Create Date                     : 2012:02:08 18:53:25+05:30
Metadata Date                   : 2012:02:08 18:53:27+05:30
Modify Date                     : 2012:02:08 18:53:27+05:30
Creator Tool                    : Adobe InDesign CS4 (6.0.6)
Thumbnail Format                : JPEG
Thumbnail Width                 : 256
Thumbnail Height                : 256
Thumbnail Image                 : (Binary data 7634 bytes, use -b option to extract)
Instance ID                     : uuid:8b55f07b-6637-cd49-809f-7e4c3a419e8f
Original Document ID            : xmp.did:F77F11740720681192B0A87C657E6D65
Document ID                     : xmp.did:D584622B0B206811871F93F5E5725CAE
Rendition Class                 : proof:pdf
History Action                  : created, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved, saved
History Instance ID             : xmp.iid:F77F11740720681192B0A87C657E6D65, xmp.iid:F97F11740720681195C4DD9117A33965, xmp.iid:FA7F11740720681195C4DD9117A33965, xmp.iid:FB7F11740720681195C4DD9117A33965, xmp.iid:FC7F11740720681195C4DD9117A33965, xmp.iid:FD7F11740720681195C4DD9117A33965, xmp.iid:FE7F11740720681195C4DD9117A33965, xmp.iid:FF7F11740720681195C4DD9117A33965, xmp.iid:008011740720681195C4DD9117A33965, xmp.iid:9EA54A262120681195C4DD9117A33965, xmp.iid:9FA54A262120681195C4DD9117A33965, xmp.iid:A0A54A262120681195C4DD9117A33965, xmp.iid:A1A54A262120681195C4DD9117A33965, xmp.iid:A4A54A262120681195C4DD9117A33965, xmp.iid:0A80117407206811994C8936E977B2EF, xmp.iid:4A89369914206811994C8936E977B2EF, xmp.iid:FC7F117407206811A961DA2AAC8A7AFE, xmp.iid:BF5E88F837206811A961DA2AAC8A7AFE, xmp.iid:3487D6BC44206811A961DA2AAC8A7AFE, xmp.iid:3687D6BC44206811A961DA2AAC8A7AFE, xmp.iid:3787D6BC44206811A961DA2AAC8A7AFE, xmp.iid:3887D6BC44206811A961DA2AAC8A7AFE, xmp.iid:3987D6BC44206811A961DA2AAC8A7AFE, xmp.iid:3A87D6BC44206811A961DA2AAC8A7AFE, xmp.iid:F0D373884C206811A961DA2AAC8A7AFE, xmp.iid:A1DD37DD5320681192B0A181C9E9762E, xmp.iid:2C0E82D57220681192B0A181C9E9762E, xmp.iid:4504FB228220681192B0A181C9E9762E, xmp.iid:4604FB228220681192B0A181C9E9762E, xmp.iid:4704FB228220681192B0A181C9E9762E, xmp.iid:4804FB228220681192B0A181C9E9762E, xmp.iid:F77F11740720681192B0F7840042BC9D, xmp.iid:31A436AF3E2068118A50E4FD3E6EE0E2, xmp.iid:3AA436AF3E2068118A50E4FD3E6EE0E2, xmp.iid:5ED55B225B2068118A50E4FD3E6EE0E2, xmp.iid:DDB859C07B2068118A50E4FD3E6EE0E2, xmp.iid:DEB859C07B2068118A50E4FD3E6EE0E2, xmp.iid:E0B859C07B2068118A50E4FD3E6EE0E2, xmp.iid:E1B859C07B2068118A50E4FD3E6EE0E2, xmp.iid:E2B859C07B2068118A50E4FD3E6EE0E2, xmp.iid:4FE6205C242068119457CF6A080A1626, xmp.iid:598788F40E20681192B0F96E9A0C1034, xmp.iid:5A8788F40E20681192B0F96E9A0C1034, xmp.iid:5B8788F40E20681192B0F96E9A0C1034, xmp.iid:EC9D12861420681192B0F96E9A0C1034, xmp.iid:ED9D12861420681192B0F96E9A0C1034, xmp.iid:EE9D12861420681192B0F96E9A0C1034, xmp.iid:EF9D12861420681192B0F96E9A0C1034, xmp.iid:2F1D43AC122068119109F59BCDD9DEEF, xmp.iid:018011740720681192B0D1B3F3E15034, xmp.iid:028011740720681192B0D1B3F3E15034, xmp.iid:038011740720681192B0D1B3F3E15034, xmp.iid:068011740720681192B0D1B3F3E15034, xmp.iid:098011740720681192B0D1B3F3E15034, xmp.iid:D484622B0B206811871F93F5E5725CAE, xmp.iid:D584622B0B206811871F93F5E5725CAE, xmp.iid:59A651513620681192B0ED4E23C4929F
History When                    : 2011:04:05 15:47:04-07:00, 2011:12:12 16:30:44+05:30, 2011:12:12 16:30:44+05:30, 2011:12:12 16:39:36+05:30, 2011:12:12 16:50:45+05:30, 2011:12:12 16:50:45+05:30, 2011:12:12 17:59:39+05:30, 2011:12:12 18:21:53+05:30, 2011:12:12 18:55:42+05:30, 2011:12:12 19:04:22+05:30, 2011:12:12 19:13:10+05:30, 2011:12:12 19:14:19+05:30, 2011:12:12 19:14:19+05:30, 2011:12:12 19:28:22+05:30, 2011:12:13 15:50:50+05:30, 2011:12:13 15:55:03+05:30, 2011:12:14 11:22:35+05:30, 2011:12:14 16:04:40+05:30, 2011:12:14 17:34:40+05:30, 2011:12:14 17:45:39+05:30, 2011:12:14 17:45:39+05:30, 2011:12:14 18:15:02+05:30, 2011:12:14 18:15:26+05:30, 2011:12:14 18:15:26+05:30, 2011:12:14 18:17:36+05:30, 2011:12:14 21:46:48+05:30, 2011:12:14 23:45:26+05:30, 2011:12:15 00:57:38+05:30, 2011:12:15 00:58+05:30, 2011:12:15 00:58:21+05:30, 2011:12:15 00:58:21+05:30, 2011:12:15 02:22:32+05:30, 2011:12:16 20:42:33+05:30, 2011:12:16 23:47:07+05:30, 2011:12:16 23:47:43+05:30, 2011:12:17 03:49:42+05:30, 2011:12:17 03:52:01+05:30, 2011:12:17 04:03:21+05:30, 2011:12:17 04:04:43+05:30, 2011:12:17 04:05:03+05:30, 2011:12:20 04:29:41+05:30, 2011:12:20 14:29:39+05:30, 2011:12:20 14:34:54+05:30, 2011:12:20 14:38:32+05:30, 2011:12:20 15:03:25+05:30, 2011:12:20 15:05:58+05:30, 2011:12:20 15:06:31+05:30, 2011:12:20 15:07:19+05:30, 2011:12:20 19:38:08+05:30, 2011:12:22 00:24:02+05:30, 2011:12:22 00:26:18+05:30, 2011:12:22 00:28:20+05:30, 2011:12:22 00:32:51+05:30, 2011:12:22 00:37:48+05:30, 2011:12:23 17:30:34+05:30, 2011:12:23 17:30:34+05:30, 2012:02:08 18:53:14+05:30
History Software Agent          : Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0, Adobe InDesign 6.0
History Changed                 : /, /metadata, /, /metadata, /;/metadata, /, /, /, /, /, /metadata, /, /, /, /, /, /, /, /metadata, /;/metadata, /, /metadata, /, /, /, /, /, /, /metadata, /, /, /, /, /, /, /, /, /, /, /, /, /, /, /, /, /, /, /, /, /, /, /, /, /metadata, /, /
Derived From Instance ID        : xmp.iid:D484622B0B206811871F93F5E5725CAE
Derived From Document ID        : xmp.did:4804FB228220681192B0A181C9E9762E
Derived From Original Document ID: xmp.did:F77F11740720681192B0A87C657E6D65
Derived From Rendition Class    : default
Manifest Link Form              : ReferenceStream, ReferenceStream, ReferenceStream, ReferenceStream, ReferenceStream
Manifest Placed X Resolution    : 72.00, 72.00, 72.00, 72.00, 72.00
Manifest Placed Y Resolution    : 72.00, 72.00, 72.00, 72.00, 72.00
Manifest Placed Resolution Unit : Inches, Inches, Inches, Inches, Inches
Manifest Reference Instance ID  : uuid:534878c5-fd8c-ad48-b80a-d1fd49952ac3, uuid:8ada429f-90e4-6b4c-96f5-cedd00e3adc5, xmp.iid:1D1B07B9152068118C14D298BD6554CB, uuid:8ada429f-90e4-6b4c-96f5-cedd00e3adc5, xmp.iid:1D1B07B9152068118C14D298BD6554CB
Manifest Reference Document ID  : xmp.did:42CE26FACB2068118083FBF49E24B9DB, xmp.did:02801174072068118C14927657A86954, xmp.did:1D1B07B9152068118C14D298BD6554CB, xmp.did:02801174072068118C14927657A86954, xmp.did:1D1B07B9152068118C14D298BD6554CB
Safety                          : None
Trim                            : 8.5" x 11"
Bleed                           : None
Doc Change Count                : 1636
Format                          : application/pdf
Producer                        : Adobe PDF Library 9.0
Trapped                         : False
Page Count                      : 8
Creator                         : Adobe InDesign CS4 (6.0.6)
EXIF Metadata provided by EXIF.tools

Navigation menu