Re: verisign certificate



On Oct 29, 6:48 am, vertigo <tekn...@xxxxxxxxxxxxxx> wrote:

We do not want to have self signed certificate anymore because they could
not be trusted
(anybody can create such certificate).

I want to have 10 valid certificates. I want to be sure that our clients
around the
world will not be asked about untrusted certificate.
I fought it would be cheaper to buy one certificate for my CA than 10
certificates
for each server.

You may be able to save money one of two ways:

1) You may be able to obtain a "wildcard" certificate. If all the
servers are in the same domain, a "*.domain.com" certificate could be
used on all the servers. This has some security disadvantages.

2) You may be able to obtain multiple certificates in the same domain
at a discounted price. Once you prove you own "domain.com", you may be
able to use an expedited web interface at a fixed price to assign new,
unique certificates for multiple hosts inside that domain as needed.

However, since real certificates are available for around $20 these
days, just buying ten at that price may be the best deal.

DS

.



Relevant Pages

  • RE: SSL Reverse Proxy
    ... You can install the certificate on both servers. ... We already know the security implications of this approach. ...
    (Security-Basics)
  • RE: Server Certificates
    ... servers it woked fine until I promoted the one server to a domain controller. ... certificate infrastructure just to RDP. ... about Certs with RDP unless you are building custom .rdp files for the ...
    (microsoft.public.windows.server.active_directory)
  • Re: Need help configuring Exchange Server for outgoing messages
    ... Are you sure they require SSL and not TLS? ... They are quite adament that they now require SSL. ... certificate for your machine, though. ... delivering email to the target servers is the default configuration. ...
    (microsoft.public.exchange.admin)
  • Re: DNS Attacks
    ... target domain to find their own name servers and send a query directly ... certificate, or somehow sneaked a false CA certificate into your ... already started caching key host IP addresses and DNS servers that I ...
    (Fedora)
  • Re: Confused about CA deployment options
    ... >3) If the servers are intranet-only, ... >> I am trying to deploy SSL in a multiple domain ... >> trust the CA. Can I use a third party certificate (i.e. ... >> clients automatically trust any certificates I then ...
    (microsoft.public.security)