{"id":225,"date":"2019-02-17T10:25:49","date_gmt":"2019-02-17T10:25:49","guid":{"rendered":"https:\/\/www.icdsoft.com\/blog\/?p=225"},"modified":"2026-03-19T08:15:08","modified_gmt":"2026-03-19T08:15:08","slug":"should-you-get-an-ssl-certificate","status":"publish","type":"post","link":"https:\/\/www.icdsoft.com\/blog\/should-you-get-an-ssl-certificate\/","title":{"rendered":"What is an SSL Certificate, and Do You Need It?"},"content":{"rendered":"\n<p><strong>The short answer<\/strong> - <strong>Yes<\/strong>, you definitely need an SSL certificate, and there are no reasons to avoid using one.<\/p>\n\n\n\n<p>For the long answer (and it is long), read below.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"advgb-toc-d17d29b8-fb87-4ade-a825-b7f14cc2af8f\">Is SSL Really Required for All Websites Now?<\/h2>\n\n\n\n<p>SSL Certificates were once needed only by big commercial and shopping sites. Nowadays, however, this is a <u>requirement<\/u> for any website, even simple <em>blogs<\/em>, <em>portfolio<\/em> sites, or <em>galleries<\/em>. Web browsers have begun a transition to a more secure web, and their UIs (user interfaces) have started reflecting on that by showing warnings on sites not protected with an SSL certificate.<\/p>\n\n\n\n<p>When you open a website over a plain HTTP connection (see explainer below) you may get a \u201cNot secure\u201d sticker on the left in some browsers:<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><a href=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2018\/12\/doc1-1.png\"><img decoding=\"async\" width=\"416\" height=\"74\" data-src=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2018\/12\/doc1-1.png\" alt=\"Web browser showing Not secure warning for not-secure-domain.com in address bar.\" class=\"wp-image-232 lazyload\" data-srcset=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2018\/12\/doc1-1.png 416w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2018\/12\/doc1-1-300x53.png 300w\" data-sizes=\"(max-width: 416px) 100vw, 416px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 416px; --smush-placeholder-aspect-ratio: 416\/74;\" \/><\/a><figcaption class=\"wp-element-caption\"><br><em>Google Chrome showing a \u201cNot Secure\u201d site.&nbsp;Google plan on making the \u2018Not Secure\u201d text red in the future. See <a href=\"https:\/\/security.googleblog.com\/2016\/09\/moving-towards-more-secure-web.html\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">here<\/a>.<\/em><\/figcaption><\/figure>\n<\/div>\n\n\n<p>To fix this, you need an SSL certificate. SSL stands for <a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/en.wikipedia.org\/wiki\/Transport_Layer_Security\" target=\"_blank\">Secure Sockets Layer<\/a>. In layman's terms, it\u2019s what helps create an encrypted connection between the device of the visitor and your website. <\/p>\n\n\n\n<p>When you go to a site with an SSL certificate, like <a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/www.google.com\" target=\"_blank\">https:\/\/www.google.com<\/a> , you get a reassuring padlock: <\/p>\n\n\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image\"><img decoding=\"async\" width=\"416\" height=\"74\" data-id=\"227\" data-src=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2018\/12\/doc2.png\" alt=\"Browser displaying Google homepage with secure lock icon in URL bar.\" class=\"wp-image-227 lazyload\" data-srcset=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2018\/12\/doc2.png 416w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2018\/12\/doc2-300x53.png 300w\" data-sizes=\"(max-width: 416px) 100vw, 416px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 416px; --smush-placeholder-aspect-ratio: 416\/74;\" \/><figcaption class=\"wp-element-caption\">Google Chrome Showing a Padlock Icon<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" width=\"416\" height=\"74\" data-id=\"230\" data-src=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2018\/12\/doc3.png\" alt=\"Web browser address bar displaying Google homepage URL with secure connection indicator.\" class=\"wp-image-230 lazyload\" data-srcset=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2018\/12\/doc3.png 416w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2018\/12\/doc3-300x53.png 300w\" data-sizes=\"(max-width: 416px) 100vw, 416px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 416px; --smush-placeholder-aspect-ratio: 416\/74;\" \/><figcaption class=\"wp-element-caption\">Firefox Shows a Green Padlock<\/figcaption><\/figure>\n<\/figure>\n\n\n\n<div class=\"wp-block-columns has-2-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<h3 class=\"wp-block-heading\" id=\"mce_8\">SSL Certificates for SEO?<\/h3>\n\n\n\n<p>An additional benefit (more like a drawback to not having one) is that having an SSL certificate helps you rank better in Google search results. Back in 2014, Google announced that sites using HTTPS will be ranked higher than ones that don\u2019t utilize it (click <a rel=\"noreferrer noopener\" href=\"https:\/\/webmasters.googleblog.com\/2014\/08\/https-as-ranking-signal.html\" target=\"_blank\">here<\/a> for their blog post). <\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<hr class=\"wp-block-separator has-css-opacity\"\/>\n<\/div>\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"advgb-toc-b01eb2ed-84a4-46ee-80f3-264fd5af1ace\">Some Common Terms<\/h2>\n\n\n\n<p>You see these abbreviations a lot, but what do they mean? Aren't HTTPS and SSL one and the same thing? What is TLS then? And how about HSTS? Here are the answers in human words. <\/p>\n\n\n\n<div class=\"wp-block-genesis-blocks-gb-accordion gb-font-size-18 gb-block-accordion\"><details><summary class=\"gb-accordion-title\"><strong> HTTP, HTTPS, HTTP\/2, SSL, TLS, CA, CSR, HSTS?!? <\/strong><\/summary><div class=\"gb-accordion-text\">\n<ul class=\"wp-block-list\">\n<li><strong>HTTP\u00a0(Hyper\u00a0Text\u00a0Transfer\u00a0Protocol)\u00a0-\u00a0<\/strong>This is the original protocol used on the web. It works, but it has several drawbacks - mainly, it transmits all data in plain text over the internet. This means that any intermediary can sniff the connection and check all the data. Check the <a href=\"https:\/\/www.icdsoft.com\/blog\/should-you-get-an-ssl-certificate\/#advgb-toc-a5bc6d5c-64ce-44da-9c16-c3b2d36b412a\">video<\/a> below for a demonstration of this type of attack.<\/li>\n\n\n\n<li><strong> HTTPS (Hypertext Transfer Protocol Secure) -<\/strong> That's the secure version of HTTP, providing encryption via SSL\/TLS certificates.<\/li>\n\n\n\n<li><strong>HTTP\/2\u00a0<\/strong>- This is a major revision of the protocol designed to resolve another problem with it - HTTP opens a separate connection for each resource. This works for small sites, but nowadays websites load a lot of resources - JavaScript libraries, CSS files, fonts, images. HTTP\/2 combines all of them in the same connection, speeding things up. And since HTTP\/2 was new, browser developers decided to make it work over encrypted connections only, meaning that if you wish to take advantage of the speed boost HTTP\/2 provides, you need an SSL certificate. HTTP\/2 is fully supported on all our servers.<\/li>\n\n\n\n<li><strong>SSL\/TLS<\/strong> - Did you know that SSL is actually an outdated protocol and no longer used? The latest version of the SSL protocol was published in 1996. Confusing, right? How could it be outdated, when this whole article is about its importance at present? Well, TLS is the updated version, but for legacy reasons, the old name has stayed with us. However, what you actually need is not an SSL certificate, but a TLS one.<\/li>\n\n\n\n<li><strong>CA <\/strong>- Certificate Authority - CAs are trusted third-party entities that issue SSL\/TLS certificates and verify the owner of the certificate. Some common Certificate Authorities are Digicert, Sectico \/Comodo\/, and Let's Encrypt.<\/li>\n\n\n\n<li><strong>CSR\u00a0-\u00a0<\/strong>Certificate Singing Request. The name may sound complicated, but this is actually something quite simple - for the actual generation of the SSL certificate, the authority needs your data in a specific format. Our support team can help you with the CSR generation, or you can easily generate one yourself from the online Control Panel included with all our hosting accounts.<\/li>\n\n\n\n<li><strong>HSTS<\/strong> - HTTP Strict Transport Security - this is actually a policy mechanism that indicates to browsers that this site is available over secure connections only. This is useful, as an attacker with control over a network you may be using may be trying to downgrade the SSL connection in order to inspect the packets. By setting the HSTS policy for your website, you can prevent this.<\/li>\n<\/ul>\n\n\n\n<p><\/p>\n<\/div><\/details><\/div>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"advgb-toc-3955ce91-d560-4dd4-8c4f-e60f253acdbe\">Keys, Root &amp; Intermediate Certificates, PKI, SHA1<\/h3>\n\n\n\n<div class=\"wp-block-columns alignfull has-2-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<p>\n\nThere is a slew of other abbreviations you will encounter during your conquest to obtain an SSL certificate - <strong>Private Key<\/strong>, <strong>Public Key<\/strong> (this is the certificate itself), <strong>Common Name<\/strong> (an obscure name for your site's address), <strong>Root Certificate<\/strong> (the certificate used by the CA), <strong>Intermediate Certificate<\/strong> (some CAs don't have root certificates, but they have an intermediate one, signed with the root certificate of another CA), <strong>Certificate Chain<\/strong> (the chain of intermediate certificates leading back to the root certificate), <strong>PKI<\/strong> (Public Key Infrastructure), <strong>SHA-1<\/strong>, <strong>SHA-2<\/strong>, <strong>SHA-256<\/strong> (cryptographic functions).\n\n<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<h4 class=\"wp-block-heading\" id=\"mce_51\">The SHA-1 to SHA-256 upgrade<\/h4>\n\n\n\n<p class=\"has-small-font-size\">Up until 2017 SHA-1 was the most widely used hashing algorithm. In 2017 however, security researches proved the concept of some attacks that were thought possible previously, but never produced in real life. The SHA-1 design was finalized in 1995, and computing power and security requirements have increased tenfold since then. After a Proof of Concept (PoC) was available for the vulnerability in SHA-1, browser vendors quickly deprecated this algorithm and forced everybody to the more secure versions. This change wasn't backwards compatible, and many website owners needed to update their certificates to be compliant.<\/p>\n<\/div>\n<\/div>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"advgb-toc-a5bc6d5c-64ce-44da-9c16-c3b2d36b412a\">How Can Anyone Sniff Your Plain HTTP Connection?<\/h2>\n\n\n\n<p>It's rather easy and you only need free tools to perform this attack yourself:<\/p>\n\n\n\n<figure class=\"wp-block-video\"><video height=\"802\" style=\"aspect-ratio: 1428 \/ 802;\" width=\"1428\" controls src=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/02\/iF0EGm24JM.mp4\"><\/video><\/figure>\n\n\n\n<p>The tool above is <a href=\"https:\/\/www.wireshark.org\/\" target=\"_blank\" rel=\"noopener\">Wireshark<\/a>, a&nbsp;packet&nbsp;analyzer&nbsp;that&nbsp;has many different uses. For example, some users may use it to check if their computer is making some unauthorized connections, which would be an indication that malware is running on the computer.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"advgb-toc-8a8e501d-b831-4241-b3f3-85a4239366e0\"> How Do You Obtain an SSL Certificate?<\/h2>\n\n\n\n<div class=\"wp-block-columns has-2-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<p>You get it from a Certificate Authority. There are many authorities, and even more  resellers. Resellers may sound expensive, but due to the bulk pricing they get, they can usually offer SSLs cheaper than the authorities themselves. Additionally, if you get an SSL from your hosting provider (usually a reseller), you don't need to deal with CSR generations, certificate files, installations, etc. This is all handled for you. Or at least with <a href=\"https:\/\/www.icdsoft.com\/en\/ssl\/\">ICDSoft<\/a> it is.  <\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<h6 class=\"wp-block-heading has-text-align-left\" id=\"mce_73\">S<strong>ymantec's SSL Business Sale<\/strong><\/h6>\n\n\n\n<p class=\"has-small-font-size\">Symantec were the owners of several SSL brands: Thawte, VeriSign, Equifax,&nbsp;GeoTrust, and RapidSSL. In late 2017 it was revealed that Symantec was issuing certificates without adhering to the policies agreed by the major browsers. This forced Symantec to sell their SSL business, and the SSL Certificates we offer (GeoTrust and RapidSSL) landed in DigiCert's hands.<\/p>\n<\/div>\n<\/div>\n\n\n\n<p><\/p>\n\n\n\n<div class=\"wp-block-media-text alignwide has-media-on-the-right\"><div class=\"wp-block-media-text__content\">\n<h3 class=\"wp-block-heading\" id=\"mce_0\">Commercial Certificates<\/h3>\n<\/div><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"400\" height=\"203\" data-src=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/02\/2-logotypes.png\" alt=\"Sectigo Digicert logos\" class=\"wp-image-3497 size-full lazyload\" data-srcset=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/02\/2-logotypes.png 400w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/02\/2-logotypes-300x152.png 300w\" data-sizes=\"(max-width: 400px) 100vw, 400px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 400px; --smush-placeholder-aspect-ratio: 400\/203;\" \/><\/figure><\/div>\n\n\n\n<div class=\"wp-block-columns has-2-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<p><strong>Sectigo<\/strong> \/previously <strong>Comodo<\/strong>\/ and <strong>DigiCert<\/strong> \/previously <strong>GeoTrust<\/strong>\/ are the commercial SSL providers we work with. Until the appearance of <strong>Let's Encrypt<\/strong>, this was the only way to get an SSL certificate - you had to pay for it (actually, there was another CA offering free SSLs - <a title=\"StartCom were pioneers - they were the first and only SSL authority for a long time that offered Free SSL certificates. That's right, Let's Encrypt aren't the first to offer that.\" style=\"cursor: help;\">StartCom<\/a>, but it had to close down). Paid SSL certificates are still used and there are reasons for that.  <\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<h6 class=\"wp-block-heading\" id=\"mce_62\">StartCom - The original Free SSL Provider<\/h6>\n\n\n\n<p class=\"has-small-font-size\">StartCom were pioneers - they were the first and only SSL authority for a long time that offered free SSL certificates.  <br>Their demise started after they were sold in secrecy to <a href=\"https:\/\/en.wikipedia.org\/wiki\/WoSign\" target=\"_blank\" rel=\"noopener\">WoSign<\/a>&nbsp;Limited (based in Beijing, China). It was later found that they were issuing certificates in order to circumvent browser restrictions. Browser vendors quickly reacted and removed the root certificates of StartCom, effectively crippling their business.  <\/p>\n\n\n\n<p class=\"has-small-font-size\"><\/p>\n<\/div>\n<\/div>\n\n\n\n<p>There are different types of certificates in different price categories, but they ultimately serve the same purpose - they encrypt the connection between your  visitors and your website. We offer several types of commercial certificates which you can check here:  <strong><a href=\"https:\/\/www.icdsoft.com\/en\/ssl\"><em>https:\/\/www.icdsoft.com\/en\/ssl <\/em><\/a><\/strong> <\/p>\n\n\n\n<hr class=\"wp-block-separator has-css-opacity\"\/>\n\n\n\n<div class=\"wp-block-media-text alignwide has-media-on-the-right\"><div class=\"wp-block-media-text__content\">\n<h3 class=\"wp-block-heading\" id=\"lets-encrypt\">Free Let's Encrypt Certificates<\/h3>\n\n\n\n<p><\/p>\n<\/div><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"301\" data-src=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/02\/le-logo-wide-1024x301.png\" alt=\"Let's Encrypt logo\" class=\"wp-image-3475 size-full lazyload\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1024px; --smush-placeholder-aspect-ratio: 1024\/301;\" \/><\/figure><\/div>\n\n\n\n<p>Around the time Google was already starting their push to HTTPS, high-ranking personnel from different tech companies such as the Mozilla Foundation and Cisco started a project that provides free and legitimate certificates. It\u2019s called <a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/letsencrypt.org\/\" target=\"_blank\">Let\u2019s Encrypt<\/a>. These certificates offer the same level of protection as commercial certificates, but they are free.  <\/p>\n\n\n\n<div class=\"wp-block-columns has-2-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<p><\/p>\n\n\n\n<p>So what's the catch? Well, Let's Encrypt have decided that they will issue SSL certificates for a limited time period only - a maximum of 3 months. This means that the certificates need to be renewed on a regular basis, which isn't suitable for all systems. You need an SSL management infrastructure in order to automate this process and keep your SSL certificates updated. Of course, there is no need to worry about these implementation details when you have an account with us - everything is handled by our Let's Encrypt Infrastructure - issuing, verification, installation and renewal.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<h4 class=\"wp-block-heading\" id=\"mce_38\">Comodo vs Let's Encrypt Trademark Dispute<\/h4>\n\n\n\n<p class=\"has-small-font-size\">In 2016, an interesting story captured the attention of techheads - Comodo, a large Certificate Authority had decided to trademark \"Let's Encrypt\". You can read more about their decision to do so here - <a rel=\"noreferrer noopener\" href=\"https:\/\/letsencrypt.org\/2016\/06\/23\/defending-our-brand.html\" target=\"_blank\">Let's Encrypt - Defending our Brand<\/a>, and you can also&nbsp;check&nbsp;the&nbsp;comments Comodo's CEO made on <a rel=\"noreferrer noopener\" href=\"https:\/\/forums.comodo.com\/general-discussion-off-topic-anything-and-everything\/shame-on-you-comodo-t115958.0.html;msg837411#msg837411\" target=\"_blank\">their own product forum<\/a><\/p>\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-columns has-2-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<h2 class=\"wp-block-heading\" id=\"mce_20\">What is a DV Certificate?<\/h2>\n\n\n\n<p>A <strong>DV<\/strong>, or <strong>Domain Validated<\/strong> certificate, is the standard SSL certificate which you can get from us, from Let's Encrypt, and from most other authorities. It means that the certificate authority validates only that you have control over the domain name. This validation usually occurs by creating a special DNS record, placing a special file on the domain, or by sending an email to one of the following predefined email addresses:<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<hr class=\"wp-block-separator has-css-opacity\"\/>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"mce_28\">The DigiNotar bankruptcy<\/h4>\n\n\n\n<p class=\"has-small-font-size\">This is an interesting case because of one of the features often cited in commercial SSL offers (yes, we have it on our page as well) - SSL Warranties. The SSL Warranty is usually several thousand dollars, but so far we haven't heard of anyone getting it. The closest certificate users got to getting their warranties was in the DigiNotar case, but this SSL authority declared bankruptcy only a month after it was revealed that their systems were hacked. You can read more about this on Wikipedia: <a rel=\"noreferrer noopener\" href=\"https:\/\/en.wikipedia.org\/wiki\/DigiNotar\" target=\"_blank\">https:\/\/en.wikipedia.org\/wiki\/DigiNotar<\/a><\/p>\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-columns has-2-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<ul class=\"wp-block-list\">\n<li>admin@example.com<\/li>\n\n\n\n<li>administrator@example.com<\/li>\n\n\n\n<li>postmaster@example.com <\/li>\n\n\n\n<li>hostmaster@example.com<\/li>\n\n\n\n<li>webmaster@example.com<\/li>\n<\/ul>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<hr class=\"wp-block-separator has-css-opacity\"\/>\n\n\n\n<p class=\"has-small-font-size\">We often get asked if another email address can be used instead. The answer is <u>No<\/u>. It has to be one of the predefined email addresses. The postmaster account is required by <a rel=\"noreferrer noopener\" href=\"https:\/\/tools.ietf.org\/html\/rfc822#section-6.3\" target=\"_blank\">RFC 822<\/a> , so every domain owner should have it. At ICDSoft.com all hosting accounts have it by default.<\/p>\n<\/div>\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"advgb-toc-30b20b9d-e9b9-4992-a4a0-2826e6130c02\">What is an EV Certificate?<\/h2>\n\n\n\n<p><strong>EV Certificates<\/strong>, or <strong>Extended Validation<\/strong> certificates provide the same level of encryption, but during the issuing process, the authority performs additional checks. The benefits of having such an SSL certificate are dubious, and the fact that popular websites, such as <a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/facebook.com\" target=\"_blank\">https:\/\/facebook.com<\/a> or <a rel=\"noreferrer noopener\" aria-label=\"https:\/\/google.com (opens in a new tab)\" href=\"https:\/\/google.com\" target=\"_blank\">https:\/\/google.com<\/a> do not use them adds to the controversy. You may have noticed that some sites have a green bar next to the padlock. Here are screenshots from Mozilla Firefox and Google Chrome which show the way most browsers used to distinguish EV certificates, and the way most browsers are headed now (no visual distinction):<\/p>\n\n\n\n<figure class=\"wp-block-gallery aligncenter has-nested-images columns-1 wp-block-gallery-2 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image\"><img decoding=\"async\" width=\"500\" height=\"32\" data-id=\"3564\" data-src=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/02\/firefox_D6UOIrdCiL.png\" alt=\"Firefox EV Certificate UI\" class=\"wp-image-3564 lazyload\" data-srcset=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/02\/firefox_D6UOIrdCiL.png 500w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/02\/firefox_D6UOIrdCiL-300x19.png 300w\" data-sizes=\"(max-width: 500px) 100vw, 500px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 500px; --smush-placeholder-aspect-ratio: 500\/32;\" \/><figcaption class=\"wp-element-caption\">Firefox still shows clear visual indication for EV certificates<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" width=\"500\" height=\"32\" data-id=\"3570\" data-src=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/02\/chrome_YtuBKwkIGS.png\" alt=\"Chrome EV\" class=\"wp-image-3570 lazyload\" data-srcset=\"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/02\/chrome_YtuBKwkIGS.png 500w, https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/02\/chrome_YtuBKwkIGS-300x19.png 300w\" data-sizes=\"(max-width: 500px) 100vw, 500px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 500px; --smush-placeholder-aspect-ratio: 500\/32;\" \/><figcaption class=\"wp-element-caption\">Chrome Showing No Clear Indication for EV<\/figcaption><\/figure>\n<\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"advgb-toc-71a8ea2c-a63c-4adc-95bb-df2abd55b96f\">Email Certificates<\/h2>\n\n\n\n<p>Email certificates are largely the same as HTTP certificates. Our mail servers, for example, use the same Let's Encrypt TLS certificates as our web servers. They secure other protocols there, however, and are respectively called <strong>SMTP over TLS<\/strong>, <strong>IMAP over TLS<\/strong>, and <strong>POP3 over TLS.<\/strong><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"advgb-toc-95f2d0f3-3352-40dc-abf0-59daeea2f673\">OK I Have the SSL, is My Site Secure Now?<\/h2>\n\n\n\n<p>A common issue we encounter is that website owners buy a certificate, install it (or have it installed on their server) but their site continues to load over <strong>HTTP<\/strong>. The <strong>SSL<\/strong> certificate is there, but no one has forced the users to use it - users may have a bookmark pointing to the <strong>HTTP<\/strong> version, or their habits may be pointing them there. For this reason, you should implement an <strong>HSTS<\/strong> policy, or enable a redirect to <strong>HTTPS<\/strong> on your website. This is easily done via our online Control Panel - just go to the <strong>SSL\/HTTPS<\/strong> section and click <strong>Enable <\/strong>on the <strong>Force SSL<\/strong> option. <\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"advgb-toc-2d369afe-581b-4239-a8b3-f35a33700ebd\">WordPress and SSL Certificates<\/h4>\n\n\n\n<p>There is a caveat however, <u>WordPress<\/u>, the most popular website platform, isn't fully compatible with these redirects. See, WordPress stores the full URLs (another one of these abbreviations, meaning your full website address, including the protocol) in its database, sometimes in encoded form. That's why with WordPress additional configuration steps may be required. <a rel=\"noreferrer noopener\" aria-label=\"This article (opens in a new tab)\" href=\"https:\/\/tickets.suresupport.com\/faq\/article-1864\/en\/switch_a_wordpress_site_to_https\" target=\"_blank\">This article<\/a> at our FAQ covers the topic, but if you are our customer, it would be easier to just <a href=\"https:\/\/www.icdsoft.com\/en\/support\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">ask our support team<\/a> to do this for you.<\/p>\n\n\n\n<div style=\"background-color:#3373dc;text-align:center\" class=\"wp-block-genesis-blocks-gb-cta gb-block-cta\"><div class=\"gb-cta-content\"><h2 class=\"gb-cta-title gb-font-size-32\" style=\"color:#eeeeee\">Trying To Switch Your Site to HTTPS?<\/h2><div class=\"gb-cta-text gb-font-size-32\" style=\"color:#eeeeee\"><p>Did you know that ICDSoft's Support Team Does It For Free?<\/p><\/div><\/div><div class=\"gb-cta-button\"><a href=\"https:\/\/www.icdsoft.com\/en\/hosting\/usa#\/sharedplans\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"gb-button gb-button-shape-rounded gb-button-size-medium\" style=\"color:#ffffff;background-color:#F7812B\">Get ICDSoft Hosting<\/a><\/div><\/div>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"advgb-toc-35ed6219-7d7e-46f6-9f5f-079fccf147d4\">Can I Safely Accept Credit Card Payments with an SSL Certificate?<\/h3>\n\n\n\n<p>Having an SSL certificate is the absolute minimum required for you to process payments, but we recommend outsourcing credit card processing to companies like <a rel=\"noreferrer noopener\" aria-label=\"PayPal (opens in a new tab)\" href=\"https:\/\/paypal.com\/\" target=\"_blank\">PayPal<\/a>, <a rel=\"noreferrer noopener\" aria-label=\"2CheckOut (opens in a new tab)\" href=\"https:\/\/www.2checkout.com\/\" target=\"_blank\">2CheckOut<\/a>, or <a rel=\"noreferrer noopener\" aria-label=\"Stripe (opens in a new tab)\" href=\"https:\/\/stripe.com\/\" target=\"_blank\">Stripe<\/a>. For the small increase in fees you pay for each transaction, you get the comfort of having an entire company looking over the security of the payment process and the user's payment details. Our company uses this model as well, and we are pretty satisfied with it. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"advgb-toc-d310b6b2-d4a7-498f-8116-daf01593400a\">Security is a Process, Not an End State<\/h2>\n\n\n\n<p>Anyone with knowledge of connected systems will tell you that security is a process. There is no final stage where you are 100% secure. <\/p>\n\n\n\n<p>With the SSL certificate you have covered only one side of this process and that is the connection encryption. This protects against eavesdropping, and malicious actors sniffing your networks, but does nothing to the security of your data at rest or to the security of your scripts. If you collect any data from users, you must take proper security precautions, SSL being one of them, but certainly not the last one. <\/p>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">So are You Ready to Go Full HTTPS?<\/h2>\n\n\n\n<p>You could go and buy one directly from: <a rel=\"noreferrer noopener\" aria-label=\"https:\/\/www.icdsoft.com\/en\/ssl (opens in a new tab)\" href=\"https:\/\/www.icdsoft.com\/en\/ssl\" target=\"_blank\">https:\/\/www.icdsoft.com\/en\/ssl<\/a> , but it will be easier, and cheaper in the long run to have a hosting account with a <strong>Free SSL Certificate<\/strong> which is automatically renewed. And we will also move your site and switch it to <strong>HTTPS:\/\/<\/strong> for you. Get your <strong>Hosting with SSL Included<\/strong> at: <\/p>\n\n\n\n<p><a href=\"https:\/\/www.icdsoft.com\/en\/hosting\/usa#\/sharedplans\">https:\/\/www.icdsoft.com\/en\/hosting\/usa#\/sharedplans<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Do you really need an SSL certificate? Short answer &#8211; yes! Read our post for the long answer&#8230;<\/p>\n","protected":false},"author":1,"featured_media":3580,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"advgb_blocks_editor_width":"","advgb_blocks_columns_visual_guide":"","footnotes":""},"categories":[6],"tags":[],"class_list":{"0":"post-225","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-security"},"author_meta":{"display_name":"ICDSoft","author_link":"https:\/\/www.icdsoft.com\/blog\/author\/icdsoft\/"},"featured_img":"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/02\/firefox_IDvChXfMhd-300x157.png","featured_image_src":"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/02\/firefox_IDvChXfMhd.png","featured_image_src_square":"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/02\/firefox_IDvChXfMhd.png","author_info":{"display_name":"ICDSoft","author_link":"https:\/\/www.icdsoft.com\/blog\/author\/icdsoft\/"},"coauthors":[],"tax_additional":{"categories":{"linked":["<a href=\"https:\/\/www.icdsoft.com\/blog\/category\/security\/\" class=\"advgb-post-tax-term\">Security<\/a>"],"unlinked":["<span class=\"advgb-post-tax-term\">Security<\/span>"]}},"comment_count":"0","relative_dates":{"created":"Posted 7 years ago","modified":"Updated 4 months ago"},"absolute_dates":{"created":"Posted on February 17, 2019","modified":"Updated on March 19, 2026"},"absolute_dates_time":{"created":"Posted on February 17, 2019 10:25 am","modified":"Updated on March 19, 2026 8:15 am"},"featured_img_caption":"","series_order":"","_links":{"self":[{"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/posts\/225","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/comments?post=225"}],"version-history":[{"count":232,"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/posts\/225\/revisions"}],"predecessor-version":[{"id":14923,"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/posts\/225\/revisions\/14923"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/media\/3580"}],"wp:attachment":[{"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/media?parent=225"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/categories?post=225"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/tags?post=225"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}