Security and Cryptography
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationSecurity and Cryptography

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old July 29th, 2009, 04:27 AM
ryan14 ryan14 is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jul 2009
Posts: 5 ryan14 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 27 m 38 sec
Reputation Power: 0
Question SSL - Building SSL website

If i get a company to build a website for me and I tell them I want it SSL compatible for everything like user logins etc, do they need to know my SSL certificate details OR once they build the website do I just install my SSL certificate on my server and my website will automatically use SSL without me adding any code?

Reply With Quote
  #2  
Old October 25th, 2009, 10:32 AM
Alan8 Alan8 is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Aug 2009
Posts: 21 Alan8 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 8 h 59 m 15 sec
Reputation Power: 0
They don't need to know any details of your SSL certificate. They will build a website for you and you can just deploy it on SSL enabled web server without any changes to the code.

Reply With Quote
  #3  
Old October 26th, 2009, 08:26 AM
sebastiannielse sebastiannielse is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Mar 2004
Posts: 69 sebastiannielse User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 Day 1 h 27 m 26 sec
Reputation Power: 6
No, they don't need to know your certificate details.
Most webservers will put a enviroment variable, when the server is running secure.

So if the company that develops the homepage wants a page only accessible in SSL, they will make the code check for this enviroment variable, and if not, the page will error out.

But if you want your user logins and such accessible both from HTTP and HTTPS, your website company does not need to care about this, all this are handled by the webserver.

The website company only needs to build the page like any other HTTP page.

Reply With Quote
  #4  
Old October 26th, 2009, 01:36 PM
fishtoprecords's Avatar
fishtoprecords fishtoprecords is offline
Contributing User
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: Sep 2007
Location: outside Washington DC
Posts: 2,211 fishtoprecords User rank is General 22nd Grade (Above 100000 Reputation Level)fishtoprecords User rank is General 22nd Grade (Above 100000 Reputation Level)fishtoprecords User rank is General 22nd Grade (Above 100000 Reputation Level)fishtoprecords User rank is General 22nd Grade (Above 100000 Reputation Level)fishtoprecords User rank is General 22nd Grade (Above 100000 Reputation Level)fishtoprecords User rank is General 22nd Grade (Above 100000 Reputation Level)fishtoprecords User rank is General 22nd Grade (Above 100000 Reputation Level)fishtoprecords User rank is General 22nd Grade (Above 100000 Reputation Level)fishtoprecords User rank is General 22nd Grade (Above 100000 Reputation Level)fishtoprecords User rank is General 22nd Grade (Above 100000 Reputation Level)fishtoprecords User rank is General 22nd Grade (Above 100000 Reputation Level)fishtoprecords User rank is General 22nd Grade (Above 100000 Reputation Level)fishtoprecords User rank is General 22nd Grade (Above 100000 Reputation Level)fishtoprecords User rank is General 22nd Grade (Above 100000 Reputation Level)fishtoprecords User rank is General 22nd Grade (Above 100000 Reputation Level)fishtoprecords User rank is General 22nd Grade (Above 100000 Reputation Level)  Folding Points: 757975 Folding Title: Super Ultimate Folder - Level 2Folding Points: 757975 Folding Title: Super Ultimate Folder - Level 2Folding Points: 757975 Folding Title: Super Ultimate Folder - Level 2Folding Points: 757975 Folding Title: Super Ultimate Folder - Level 2Folding Points: 757975 Folding Title: Super Ultimate Folder - Level 2Folding Points: 757975 Folding Title: Super Ultimate Folder - Level 2Folding Points: 757975 Folding Title: Super Ultimate Folder - Level 2
Time spent in forums: 3 Weeks 2 Days 7 h 52 m 30 sec
Reputation Power: 2468
Quote:
Originally Posted by sebastiannielse
But if you want your user logins and such accessible both from HTTP and HTTPS, your website company does not need to care about this, all this are handled by the webserver.


Just to expand a bit, a user should be able to get to your login page from anypage, SSL or not.

If you have the user enter a username and password, or anything similar, they to have any claim of security, you have to do the POST using SSL.

If you pass the username and password in the clear, you are open to all sorts of attacks. Don't do this.

Reply With Quote
  #5  
Old November 4th, 2009, 04:40 PM
romario romario is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: May 2003
Posts: 275 romario User rank is Sergeant Major (2000 - 5000 Reputation Level)romario User rank is Sergeant Major (2000 - 5000 Reputation Level)romario User rank is Sergeant Major (2000 - 5000 Reputation Level)romario User rank is Sergeant Major (2000 - 5000 Reputation Level)romario User rank is Sergeant Major (2000 - 5000 Reputation Level)romario User rank is Sergeant Major (2000 - 5000 Reputation Level) 
Time spent in forums: 2 Days 4 h 26 m 38 sec
Reputation Power: 42
Quote:
Originally Posted by fishtoprecords
If you have the user enter a username and password, or anything similar, they to have any claim of security, you have to do the POST using SSL.


How is this done?

Reply With Quote
  #6  
Old November 5th, 2009, 12:15 AM
fishtoprecords's Avatar
fishtoprecords fishtoprecords is offline
Contributing User
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: Sep 2007
Location: outside Washington DC
Posts: 2,211 fishtoprecords User rank is General 22nd Grade (Above 100000 Reputation Level)fishtoprecords User rank is General 22nd Grade (Above 100000 Reputation Level)fishtoprecords User rank is General 22nd Grade (Above 100000 Reputation Level)fishtoprecords User rank is General 22nd Grade (Above 100000 Reputation Level)fishtoprecords User rank is General 22nd Grade (Above 100000 Reputation Level)fishtoprecords User rank is General 22nd Grade (Above 100000 Reputation Level)fishtoprecords User rank is General 22nd Grade (Above 100000 Reputation Level)fishtoprecords User rank is General 22nd Grade (Above 100000 Reputation Level)fishtoprecords User rank is General 22nd Grade (Above 100000 Reputation Level)fishtoprecords User rank is General 22nd Grade (Above 100000 Reputation Level)fishtoprecords User rank is General 22nd Grade (Above 100000 Reputation Level)fishtoprecords User rank is General 22nd Grade (Above 100000 Reputation Level)fishtoprecords User rank is General 22nd Grade (Above 100000 Reputation Level)fishtoprecords User rank is General 22nd Grade (Above 100000 Reputation Level)fishtoprecords User rank is General 22nd Grade (Above 100000 Reputation Level)fishtoprecords User rank is General 22nd Grade (Above 100000 Reputation Level)  Folding Points: 757975 Folding Title: Super Ultimate Folder - Level 2Folding Points: 757975 Folding Title: Super Ultimate Folder - Level 2Folding Points: 757975 Folding Title: Super Ultimate Folder - Level 2Folding Points: 757975 Folding Title: Super Ultimate Folder - Level 2Folding Points: 757975 Folding Title: Super Ultimate Folder - Level 2Folding Points: 757975 Folding Title: Super Ultimate Folder - Level 2Folding Points: 757975 Folding Title: Super Ultimate Folder - Level 2
Time spent in forums: 3 Weeks 2 Days 7 h 52 m 30 sec
Reputation Power: 2468
Quote:
Originally Posted by romario
How is this done?


In your form's ACTION line, use HTTPS://mydomain.com
rather than http://mydomain.com

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationSecurity and Cryptography > SSL - Building SSL website


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump




 Free IT White Papers!
 
How to Present Effectively Online
This white paper offers practical and actionable advice on the key steps that any presenter should consider as they plan and execute a Webinar or online meeting.

 
Open Source Security Myths
Open Source Software (OSS) is computer software whose source code is available to the general public with relaxed or non-existent intellectual property restrictions (or arrangement such as the public domain), and is usually developed with the input of many contributors.

 
Power and Cooling Capacity Management for Data Centers
This paper describes the principles for achieving power and cooling capacity management.

 
Scalable, Fault-Tolerant NAS for Oracle - The Next Generation
For several years NAS has been evolving as a storage alternative for Oracle databases, and for good reason: NAS is quite often the simplest, most cost-effective storage approach for Oracle. Learn about the benefits that HP's approach to scalable NAS brings to Oracle environments in this comprehensive white paper.

 
Understanding Web Application Security Challenges
This white paper discusses many common threats and preventive measures for Web application security, and explains what you can do to help protect your organization.

 

Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 




© 2003-2009 by Developer Shed. All rights reserved. DS Cluster 1 Hosted by Hostway
For more Enterprise Application Development news, visit eWeek