Red Squirrel

No Lifer
May 24, 2003
67,907
12,375
126
www.anyf.ca
I'm toying with the idea of using HTTPS for my site when I redesign it. At very least the forum. The site will also consist of a central authentication login which the forum will be one of many things that uses that same login, so idealy I need to secure anything else (different sub/domains) that uses a login form. Goal is to not send the user login through clear text, obviously.

Been looking up certs real quick and there's a lot of different features and prices. Given I want to secure multiple sub/domains, possibly servers, but am not a high profile e-commerce site, what is my best bet? I'm thinking just paying for multiple single domain certs and basically getting the cheapest I can find. Any features I should look for to ensure I have? Most of the sub domains are on the same server but there is the possibility that changes. But if I get individual certs then I should not have to worry about that right, I'd just generate a new cert when I switch servers?

There are also free options like Let's Encrypt, is that worth looking at or am I better off going with one of the more known/trusted CAs like Comodo?

Also if I want to secure an internal communication channel, ex: one server using HTTP queries to another server, I can use self signed for that right? I have a game server which I will want to tie the login to the central authentication system, so I'm thinking it would probably just use a http query string with a reply that says if it's valid or not and possibly other info, which I obviously would want to encrypt.

Moved to Networking - Programming Moderator Ken g6
 
Last edited by a moderator:

John Connor

Lifer
Nov 30, 2012
22,840
617
121
I'd just go with Lets Encrypt. They are backed by many companies.

Server to server, yeah, self-signed should work. I know webmin uses self-signed.

I use a combination of StartSSL and Lets encrypt. When the StartSSL Certs expire I'll migrate to Lets Encrypt since cPanel will automatically update the Cert for me. I think you can do that with a command in terminal as well. Read the Lets Encrypt page. I seen the commands there.
 

razel

Platinum Member
May 14, 2002
2,337
90
101
You don't need to buy an SSL cert just now. You can create self signed certs to test your needs. The only difference after you buy is you no longer will get a warning message in the browser, app, etc, that your SSL is bunk. Browsers are making it harder for you to proceed into a site with a bunk SSL cert, but it is not impossible. It just takes a few more clicks.
 

Red Squirrel

No Lifer
May 24, 2003
67,907
12,375
126
www.anyf.ca
Yeah I will do self signed when in testing phase, done it before, but I still want to go with a proper one once the new site goes live. I'm leaning towards let's encrypt, don't like the idea that they expire so short but you can script it to auto renew, so I'll just set that up.
 

razel

Platinum Member
May 14, 2002
2,337
90
101
If it's just for your needs you really don't need a validated SSL cert. The validation is just to confirm the ownership of the SSL to other people. If it's just you and your apps, APIs allow you to continue then your HTTPS connection will still be highly encrypted.
 

JackMDS

Elite Member
Super Moderator
Oct 25, 1999
29,480
387
126
The issue of what to use is Not security per-se. When using a None main stream Certs, in most cases when connection is made Security warnings would popup. None knowable users usually get scared by it, for others it is just a nuisance and at times might destabilized the connection.

Thus, if you are the only one connecting and you are willing to endure the hassle it does not matter much what to use, what is comfortable to you would do.

Otherwise use a commercial cert. If security is really important to you it worse the relative small expense.



 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |