22 August 2008

Which Type of SSL Certificate Should You Purchase?

Extended Validation (EV) SSL certificates have been available for 18 months, but despite the hard sales push, many web sites are continuing to use non-EV certificates. EV certificates cost significantly more but I don't think the case for their use is yet proven.

During 2006, the SSL Certificate Authorities (CAs) and browser vendors approved standard practices for certificate validation and display called the Extended Validation Standard. This was in reaction to the widespread sale of low-cost SSL certificates which did very little, if any, checking of the purchaser's details. The validation process is meant to establish the legal identity as well as the operational and physical presence of website owner, the identity of the individual making the request and that they have full control over the address/URL being used. In Internet Explorer (IE) 7 web browser, the address bar turns green when a trusted and display the organisation's name, current EV SSL certificate is in use (may require an update from Microsoft depending upon your operating system):

Partial screen capture of a web browser showing the green address bar that appears in IE7 when a valid Extended validation SSL certificate is in use

Users of Firefox 3 (and Firefox 2 with an extension) see something similar. But despite steady worldwide growth many UK web sites are continuing to use non-EV certificates:

Partial screen capture of a web browser showing the address bar when a conventional SSL certificate is in use

For an excellent insight into what EV SSL certificates offer, read Ivan Ristic's ModSecurity Blog post "Extended Validation Certificates: A Change for the Better (But Not Enough)".

If your competitors are using EV certificates, it might be worth buying one too, but they are costed at a premium and I don't think consumers are avoiding web sites with conventional certificates. Since some UK online banks aren't using them, I suspect the time to join the bandwagon hasn't yet arrived:

Partial screen capture of a web browser showing the address bar when a conventional SSL certificate is in use by an online bank

Perhaps when the cost differential reduces, more site owners will begin to buy them. This isn't yet something you need to be ahead of the wave on.

Posted on: 22 August 2008 at 08:50 hrs

Comments Comments (1) | Permalink | Send Send | Post to Twitter

Comments

Comments are filtered automatically and should appear shortly after they been checked.

Thanks for the advice! That'll save us a few hundred dollars.
1 Added by Kari Posted on 02 September 2008 at 20:04 hrs
Post a comment
Confirm acceptance and understanding of the terms of use
New posts to this thread will be sent to your email address
Which Type of SSL Certificate Should You Purchase?
http://www.clerkendweller.com/2008/8/22/Which-Type-of-SSL-Certificate-Should-You-Purchase
ISO/IEC 18004:2006 QR code for http://clerkendweller.com

Page http://www.clerkendweller.com/2008/8/22/Which-Type-of-SSL-Certificate-Should-You-Purchase
Requested by 38.107.179.220 on Saturday, 4 February 2012 at 22:42 hrs (London date/time)

Please read our terms of use and obtain professional advice before undertaking any actions based on the opinions, suggestions and generic guidance presented here. Your organisation's situation will be unique and all practices and controls need to be assessed with consideration of your own business context.

Terms of use http://www.clerkendweller.com/page/terms
Privacy statement http://www.clerkendweller.com/page/privacy
© 2008-2012 clerkendweller.com