How SSL Certificates Work: From Validation to Encryption
What is an SSL Certificate and How Does it Work?
SSL (Secure Sockets Layer) is the transaction security protocol
used by websites to protect online communications. The most
common use of SSL is to provide protection for confidential
data, such as personal details or credit card information,
entered into a website.
The SSL Certificate provides two primary functions:
-
SSL Encryption allows data to be transmitted over computer
networks in a secure manner
-
Identity Assurance (validation) allows the business running
the site to 'prove' that they are who they claim to be
Once a secure transaction is initiated, (i.e. click the Submit
or Buy button to begin a transaction on a website), there are
four basic steps taken to establish a secure connection:
-
The browser checks the SSL Certificate to make sure that it is
valid and that the site you are connecting to is legitimate.
-
Data encryption levels are established based on what the
browser and website server can both use to understand each
other.
-
The browser and server send each other unique codes to use
when encrypting the information that will be sent.
-
The browser and server start talking using the encryption, the
Web browser shows the encrypting icon, and the Web pages and
information are processed securely.
In addition to data encryption and identity assurance, SSL
Certificates give important visual cues to the website user
that they are in a secure environment:
What is the SSL Validation Process?
Identity assurance is accomplished through the validation
process. Network Solutions offers two different validation
processes.
Organizationally Validated (OV) Certificates
OV Certificates are issued only after verifying the
legitimacy of the applicant's business. This is done by using
currently established and accepted vetting processes, like
manually checking credentials such as Dunn & Bradstreet
number, articles of incorporation, WHOIS, passport, driver's
license, etc. nsProtect™ Secure Basic, Advanced and
Wildcard certificates are organizationally validated.
Extended Validation (EV) Certificates
EV
Certificates provide a higher level of validation and are
available to all business and government entities, but are
not available to individuals. The EV process is more rigorous
and detailed than for any other Certificate and will require
additional steps, which may include obtaining signatures from
several people within the applying company, legal
verification of the business's existence, etc.
EV Certificates provide additional visual assurance by
turning your browser address bar green (when using modern
browsers like IE7).
When you buy a an nsProtect Secure SSL Certificate you are
asked to provide specific information which Network Solutions
will verify, or validate, to prove you are a legitimate
business. For example, you may be asked for articles of
incorporation, licensing, etc. You move through the various
stages of validation using Network Solutions Account Manager.
Email communications will also be sent to you to assist you in
the process.
Once all validation is complete, your SSL Certificate is issued
electronically and is ready for installation on your website.
If your site is hosted with Network Solutions, much of this
installation process is automated for you.
