successfully installed openssl on hosted server - host says there i sno security unless I buy separate certificate - is that right?

This is a discussion on successfully installed openssl on hosted server - host says there i sno security unless I buy separate certificate - is that right? within the Linux Security forums, part of the System Security and Security Related category; I successfully installed openssl on hosted server. The host company says that offers no security or encryption unless I buy ...


Go Back   Usenet Forums > System Security and Security Related > Linux Security

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 12-19-2005
NotGiven
 
Posts: n/a
Default successfully installed openssl on hosted server - host says there i sno security unless I buy separate certificate - is that right?

I successfully installed openssl on hosted server. The host company says
that offers no security or encryption unless I buy a certificate from them
or a third party like verisign.

If I try to open my site using httpS://, a prompt pops up telling me the
cert is not certified by anyone and do I want to accept it.

I accept it and there is a locked key in the browser.

Is the traffic encrypted (thus the tech is wrong)?

It is interesting in that the hosting company's login has the SAME prompt
when logging in.


Reply With Quote
  #2 (permalink)  
Old 12-19-2005
prg
 
Posts: n/a
Default Re: successfully installed openssl on hosted server - host says there i sno security unless I buy separate certificate - is that right?


NotGiven wrote:
> I successfully installed openssl on hosted server. The host company says
> that offers no security or encryption unless I buy a certificate from them
> or a third party like verisign.
>
> If I try to open my site using httpS://, a prompt pops up telling me the
> cert is not certified by anyone and do I want to accept it.


This is standard (and "the" standard) behavior. Ie., do _you_ trust
that this is a legit cert?

> I accept it and there is a locked key in the browser.


And the protocol in the browser's url is https -- note the added "s"
(as in secure) -- so long as you're using ssl/https.

> Is the traffic encrypted (thus the tech is wrong)?


The tech is clueless :-) Try sniffing the traffic with ethereal.

> It is interesting in that the hosting company's login has the SAME prompt
> when logging in.


Anyone can generate a certificate with whatever location, etc. info
they please. The purpose of a "trusted" third party is to _verify_
that the certificate "owner" is who they say they are and that they are
relatively trustworthy (ie., sufficient score on credit report and/or
authorized to request certificate verification on behalf of the
organization).

For your own use (or a relatively small number of people) there is no
reason to obtain some
"seal of approval" from a third party. In fact, you might be surprised
how many organiztions have not renewed their expired certs.

hth,
prg

Reply With Quote
  #3 (permalink)  
Old 12-20-2005
NotGiven
 
Posts: n/a
Default Re: successfully installed openssl on hosted server - host says there i sno security unless I buy separate certificate - is that right?

"prg" <rdgentry1@cablelynx.com> wrote in message
news:1135032922.921937.36430@z14g2000cwz.googlegro ups.com...
>
> NotGiven wrote:
>> I successfully installed openssl on hosted server. The host company says
>> that offers no security or encryption unless I buy a certificate from
>> them
>> or a third party like verisign.
>>
>> If I try to open my site using httpS://, a prompt pops up telling me the
>> cert is not certified by anyone and do I want to accept it.

>
> This is standard (and "the" standard) behavior. Ie., do _you_ trust
> that this is a legit cert?
>
>> I accept it and there is a locked key in the browser.

>
> And the protocol in the browser's url is https -- note the added "s"
> (as in secure) -- so long as you're using ssl/https.
>
>> Is the traffic encrypted (thus the tech is wrong)?

>
> The tech is clueless :-) Try sniffing the traffic with ethereal.
>
>> It is interesting in that the hosting company's login has the SAME prompt
>> when logging in.

>
> Anyone can generate a certificate with whatever location, etc. info
> they please. The purpose of a "trusted" third party is to _verify_
> that the certificate "owner" is who they say they are and that they are
> relatively trustworthy (ie., sufficient score on credit report and/or
> authorized to request certificate verification on behalf of the
> organization).
>
> For your own use (or a relatively small number of people) there is no
> reason to obtain some
> "seal of approval" from a third party. In fact, you might be surprised
> how many organiztions have not renewed their expired certs.
>
> hth,
> prg



Thanks!


Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 04:44 AM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0