Results 1 to 8 of 8

Thread: SSL without users having to confirm certification

  1. #1
    Join Date
    Dec 2007
    Beans
    485
    Distro
    Ubuntu 11.04 Natty Narwhal

    SSL without users having to confirm certification

    I am looking for the best method to implement SSL for my sites but without users having to accept the CERT and I'm small so I'd want to use the cheapest method like signing my own certs. Is there an automatic way of doing it or best practice?

  2. #2
    Join Date
    Apr 2006
    Location
    Montana
    Beans
    Hidden!
    Distro
    Kubuntu Development Release

    Re: SSL without users having to confirm certification

    There is not a way to easily avoid this with self signed certs.
    There are two mistakes one can make along the road to truth...not going all the way, and not starting.
    --Prince Gautama Siddharta

    #ubuntuforums web interface

  3. #3
    Join Date
    Apr 2011
    Beans
    484

    Re: SSL without users having to confirm certification

    If there was a way for you to avoid it, anyone could avoid it. (AKA, phishing sites.)
    Life is an extraordinarily long concatenation of luck and coincidence.

  4. #4
    Join Date
    Apr 2008
    Location
    Far, far away
    Beans
    2,148
    Distro
    Ubuntu 11.04 Natty Narwhal

    Re: SSL without users having to confirm certification

    The closest to this is to have your users visit a page and click a link to install your (self-signed) CA cert into their browser, before visiting your site requiring client cert access. You might do this if you have a fairly limited user base who somewhat trust your site (friends maybe). But for the general public this doesn't work so well because more astute users are going to balk at the idea of installing your CA cert into their browser (and they should feel uneasy!).

    The page to install your CA cert is easy to setup if that idea works for you. It's just not very satisfactory for general public visitors. You might have visitors go there upon sign-up via an email link or something, with an explanation of why.

    The next best thing I think is to use free certificates from startssl.com. They work well enough and are recognized in browsers without warnings. I've always just been a bit suspicious of them being based in Israel - but I haven't read about any evidence of suspicious behaviour, so who knows.
    Last edited by BkkBonanza; June 13th, 2011 at 07:23 AM.

  5. #5
    Join Date
    Jul 2010
    Location
    Suffolk, UK
    Beans
    31
    Distro
    Ubuntu

    Re: SSL without users having to confirm certification

    COMODO do a free 90 day SSL, no strings!

    http://www.instantssl.com/ssl-certif...rtificate.html

    I got a cheap SSL cert from a host I know.. uh-hosting.co.uk IIRC for £45.

  6. #6
    Join Date
    Jun 2011
    Beans
    3

    Re: SSL without users having to confirm certification

    Well as all said there is no way to avoid it otherwise every one can do like that and get the SSL certificate.

  7. #7
    Join Date
    Jan 2008
    Beans
    294

    Re: SSL without users having to confirm certification

    StartSSL gives a free 1 year cert ...
    I'm a very happy linode.com customer, I'm sure you will be too!

  8. #8
    Join Date
    Jul 2010
    Location
    Suffolk, UK
    Beans
    31
    Distro
    Ubuntu

    Re: SSL without users having to confirm certification

    Quote Originally Posted by i.r.id10t View Post
    StartSSL gives a free 1 year cert ...
    Good to know

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •