SitePoint Sponsor

User Tag List

Results 1 to 4 of 4

Thread: SSL issued by self?

  1. #1
    SitePoint Addict
    Join Date
    Mar 2005
    Location
    California, US
    Posts
    259
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    SSL issued by self?

    I am developing a site for a client and time has come for the client to get me info to install the SSL. I suggested going through godaddy since the client has an account through them.

    They had their host set up an SSL, which was created through SSL manager in cPanel. The thing that has me wondering is that they are not using any certifying authority that I can see. If I go to the site and check the cert info (click on the lock icon in the browser) I get this:

    Issued for: www.clientssite.com
    Issued by: www.clientssite.com

    I have never not gone through a certifying authority. Usually the Issued by is Verisign, geoTrust, godaddy. Etc.

    Is this secure or is it just pretending to be? I would like to voice my opinon on this topic but have not seen this situation before.

  2. #2
    SitePoint Addict
    Join Date
    Mar 2005
    Location
    California, US
    Posts
    259
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    After some more reading I find that anyone can issue an SSL with the right tools.

    Though it will give a warning to the user everytime they are directed to a https page unless the Issued by is a certifying authority. Which is not good because many people will be scared off by this and the site has the high probability to lose users.

  3. #3
    SitePoint Author silver trophybronze trophy
    wwb_99's Avatar
    Join Date
    May 2003
    Location
    Washington, DC
    Posts
    10,441
    Mentioned
    3 Post(s)
    Tagged
    0 Thread(s)
    On a technical level, any SSL certificate is as secure as any other SSL cert of a similar key size. One could argue that self-issued SSL is far and away most secure, since you should trust yourself, no? Self-issued SSL is very handy for a few things, such as intranet applications or development work.

    That said, I would go with a publicly recognized authority for my site for the reason you state. Unless it is just forcing the admin area through the SSL.

  4. #4
    SitePoint Enthusiast
    Join Date
    Sep 2005
    Posts
    66
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    Certificate Authorities

    Quote Originally Posted by Gibberish
    Is this secure or is it just pretending to be?
    This is a good question.
    this article to get an idea about authorities.
    Managed Solutions, dedicated servers and shared hosting in UK.
    Now available in Greece too
    www.guru-host.com

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •