SSL - Single Root Vs Chained Root



SSL certificates are basically two types.
  1. Single Root Level SSL Certificate
  2. Chain Root SSL Certificate

When connecting to a web server over SSL, the visitor's browser decides whether or not to trust the website's SSL certificate based on which SSL Certification Authority has issued the SSL certificate. To determine this, the browser looks at its list of trusted issuing authorities - represented by a collection of Trusted Root CA certificates added into the browser by the browser vendor (such as Microsoft, Linux, UNIX, Sun and Netscape, Mozilla, Safari).

Where is this list of CA in your computer?

When browsers and operating systems are developed / installed, most CA Root certificates will be installed. As all Root CA are required to authenticate SSL certificate on any website. When you browse any website on HTTPS://, browser will automatically identify Root Certificate as defined earlier. If browser fails to identify CS then there would be an error message.

Most SSL certificates are issued by CAs who own and use their own Trusted Root CA certificates, such as those issued by VeriSign, RapidSSL, Thawte, and GeoTrust. As all of these are known to browser vendors as a trusted issuing authority, its Trusted Root CA certificate has already been added to all popular browsers like Internet Explore (IE 4.0, 5.0, 6.0, 7.0, 8.0), Mozilla Firefox, Safari, Netscape and hence is already trusted. These SSL certificates are known as "single root" SSL certificates. RapidSSL and GeoTrust own the Equifax root used to issue its certificates. As well VeriSign and Thawte have own Root to issue SSL certificates.

What is Chained Root SSL Certificate?

Some Certification Authorities do not have a Trusted Root CA certificate present in browsers, or do not use the root they do own. In place they use a "chained root" in order for their SSL certificates to be trusted - essentially a CA with a Trusted Root CA certificate issues a "chained" certificate which "inherits" the browser recognition of the Trusted Root CA. These SSL certificates are known as "chained root" SSL certificates. However chained root certificates installation is more complex and some web servers and applications are not compatible with chained root certificates. Chained root certificates require additional effort to install as the web server must also have the chained root installed. This is not necessary for single root certificates.

For a Certification Authority to have and use its own Trusted Root CA certificate already present in browsers is a clear sign that they are long-time, stable and credible organizations who have long term relationships with the browser for the inclusion of their Trusted Root CA certificates. For this reason, such CAs are seen as being considerably more credible and stable than chained root certificate providers who do not have a direct relationship with the browser vendors, or do not use their own root certificates to issue SSL certificates.

ClickSSL.com provides only Single Root SSL Certificates.
[Read More...]


More about RapidSSL Certificate



As you know RapidSSL is largest SSL Certificate seller in the world. As a CA (Certificate Authority) RapidSSL strongly follow industry standard in SSL issuance and validation process.

What validation processes does RapidSSL use?

Trust hierarchy demands that entities "vouch" for each other. Companies that issue SSL certificates are in the business of establishing that entities on the web are, in fact, who they claim to be. The potential for criminal activity on the web (in relevance to SSL anyway), is in online ‘hijacking’ of sites or connections to siphon encrypted data. Persons so inclined can easily "copy" web site interfaces and pose as well known vendors, simply to collect these data.


SSL certificates work to prevent this through ensuring that www.abc.com is, in fact, ABC Co. In the “real world”, RapidSSL use identification procedures like photo ids, telephone calls and papers of incorporation to know with whom we’re dealing. If products or services are defective, buyers can seek recourse. In the “online world”, companies wishing to use SSL certificates must prove to the certificate authority that they have the right to present themselves online as ABC Co.
This is done through a variety of means in different SSL products. For simplicity’s sake, consider the method started and championed by Verisign, as the ‘traditional’ model. The process involves certificate petitioners faxing in their articles of incorporation, and then waiting several days to be granted a certificate to do business online under that name. There is a fair amount of overhead related to this task, as these credentials are examined and reviewed, and full-service products in this arena can cost hundreds of dollars.

There are newer, lower-cost alternatives in which certificates are issued more quickly. These SSL certificates verify that the certificate holder is the owner of that domain, ensuring customers that URL “owners” are who they claim to be.
[Read More...]


Are you shopping online using credit card?




Hey, are you shopping online using credit card? Wait first read this before you provide your credit card detail on any website.

Hi, I am Jay from CLICKSSL. I would like to share some security facts about your website, email risks.

How any one can hack information from website?

Hackers are always there on internet to steal your credit card numbers, email passwords and credential information. When you start paying on website you enter your credit card number and secret code on website. This information will go on internet. Now if the information does not pass on secure way then hacker will hijack your credit card. To know more visit: ClickSSL.com

How can I know that website is secured or not?

Well, it is so simple to identify secure website. Website should work on HTTPS:// protocol. For example: https://www.clickssl.com. SSL Certificate is only a security solution that can provide secure way to transfer data over internet.

How SSL Secures data?

SSL Certificate use Data encryption and decryption technology for data transmission. SSL use 256 bit encryption level to encrypt data. So no one can hack your information.

When you open site with HTTPS:// site should work fine without any error or warning message. Now you can see SSL Lock Icon on browser window.


What type of SSL Certificate website should have?

Below is list for SSL Providers CA (Certificate Authority).


VeriSign | GeoTrust | Thawte | RapidSSL


All of these CA are well known and trusted. VeriSign offers high value SSL Certificate as well GeoTrust EV SSL Certificates are built on high level encryption including Green Address Bar. When visitor will browse website address bar color will be changed to Green. EV SSL Certificates are high value SSL Certificates It will look like this.


However, there so many SSL types you can use for your website. Following are few recommendations:
First you have to identify that what type of website you hold.

My website is
Recommended SSL Certificate Type
E-Commerce Website : Low Volume Business
Thawte SSL123
E-Commerce Website : High Volume Business
GeoTrust True BusinessID
Intranet Website
RapidSSL
Unlimited Sub domain website(*.domainname.com)
RapidSSL Wildcard
Mail Server - Webmail
GeoTrust Quick SSL Premium
Banking and Finance Website
VeriSign EV SSL Certificate
Exchange & SharePoint Server
Thawte SSL Web Server
Website know by business brand
Green Address Bar SSL Certificate

About CLICKSSL

ClickSSL is a leading SSL Provider and reseller for VeriSign, GeoTrust, Thawte and RapidSSL. ClickSSL is a Platinum Partner of VeriSign. We offers instant issued SSL Certificates at high discount prices. You can save up to 80% of SSL Spending with us. ClickSSL offers clock around support and quick reference guide. We offer FREE Site Seal and Root CA certificates.
[Read More...]


 
Return to top of page ClickSSL - Start your E-Business with SSL Certificates