 |
Nsasoft has been approved as an official
referrer of Thawte Secure Site Certificates. These certificates both ensures security for you and your users when any sensitive information passes between the parties over the web. To obtain your own SSL certificate
Click Here.
Over the years, Thawte has proven to be one of the most trusted sources for digital web server and code signing certificates. With professional, multi-platform support, relatively wide market share, and tremendous value, thawte is a true leader in web security services.
Why buy Thawte certificates?
- thawte is one of the most established
Certification Authorities worldwide, trusted since 1995.
Subsequently, thawte's
certificates have the highest browser ubiquity in the industry.
- thawte offers cost effect digital certificates
including domain validated certificates issued within minutes (SSL123
Certificates) to certificates which provide stringent Authentication and
Verification, namely SSL Web Server Certificates, SGC SuperCerts and Code
Signing Certificates.
- thawte's products who have the stringent
Authentication and Verification policies as mentioned above, help to minimize
the possibility of online fraud and in so doing address the major concerns of
consumers.
Click here
for more info.
- thawte is the first
and only Certification Authority (CA) to secure certificates with
Internationalized Domain Names(IDN's). thawte's
systems are able to recognize and issue certificates that contain local/foreign
language characters in all certificate fields.
- thawte's Trusted Site Seal is free to all SSL
customers and ensures that customers recognize the value of the digital
certificate that merchants use and its purpose to verify the certificate's
validity.
- FREE reissues during the entire validity of the certificates
- thawte is one of a very few CAs who offer SGC
Technology in its SGC SuperCert .
Click here
for more info
- Multi-platform Code Signing Certificates which are
EXCLUSIVE to thawte
- 24x5 FREE Technical support
- thawte has access to cutting edge technology
and industry leading standards to ensure customers have access to World class
products, services and support
SGC SuperCert - One step beyond:
By unleashing the full protection of your SSL-enabled server, a SuperCert from thawte will allow you to extend 128-bit encryption to all your customers, even if they use browsers with 40-bit or 56-bit encryption capabilities (except IE 5.01 or Netscape 4.7x).
SSL Server Certificate [40-, 56- or 128-bit] - A firm handshake of trust:
By utilising thawte's SSL Web Server Certificate you will send a clear signal to your customers that you are a verified, a real-world organization and that the information your customers submit will not be intercepted while in transit. The thawte SSL Web Server Certificate connects at 128-bit, 56-bit or 40-bit depending on your customers' browser capabilities.
Code Signing Certificates - secure your code:
If your clients are software developers they will know that the product they make available on the Internet can be tampered with (without detection) if it is not secured. Your clients will want their customers to know that the software really comes from the publisher who signed it and that it has not been altered or corrupted.
|
What Is An SSL Certificate? |
| SSL (Secure Socket Layer) is a
protocol developed by Netscape that enables a web browser and a web
server to communicate securely. Security is provided in two different
ways:
- Authenticating the web server to the client using a digital
certificate;
- Encrypting all information sent.
The SSL protocol requires that the web server should have a digital
certificate installed in order to make an SSL connection. This is where
thawte comes into the picture.Through an
SSL-enabled web server and a thawte SSL
certificate, a customer connecting to a secure website is assured of 3
things:
Verification and Authentication:
For thawte SSL Web Server and SGC
SuperCerts products, the certificate verifies that the company that
installed the certificate is the true owner of the website.
For thawte SSL123 product, the
certificate validates the domain name in the certificate.
Message privacy: Using a unique
session key, SSL encrypts all information exchanged between your web
server and your customers, such as credit card numbers and other
personal data. This ensures that personal information cannot be viewed
if intercepted by unauthorized persons.
Message integrity: The data cannot be
tampered with over the Internet.
SSL is the de facto standard for securing Internet transactions and is
implemented by all major software vendors. Your users do not need any
installation of additional software on their server or browser. When
implemented correctly the process is seamless to the user. |
|
How Does An SSL Certificate Work? |
| The browser asks to start
a secure session with the server. |
| The server returns the
site's certificate. |
| The browser checks the
certificate information for validity |
| The browser creates a
session key, which is encrypted with the server's public
key, which is then sent to the server |
| The server then decrypts
this information using its private key. |
| Both the browser and the
server now are using the same session key |
You can control which method and strength of encryption is required.
There are options that allow you for example, to see if 128-bit
encryption is supported by the browser. If you have a policy of
enforcing very strong encryption, then you can send a message back to
the user suggesting they download a 128 bit enabled browser.
Once both the browser and the server are using the same secret key
for encrypting and decrypting their information, they can then have a
certain amount of comfort in knowing their information cannot be
intercepted and decoded by a third party. Of course, this depends on
whether strong or weak encryption is used.
For the visitor to your site, the little lock icon will appear on
their browser. As long as you continue to use the https: protocol,
everything between the browser and your scripts are encrypted without
you having to worry about the details. |
|
What is SSL crypto strength? |
| SSL (Secure Sockets Layer) provides
encryption between web browsers and web servers. This encryption, based
on the RSA algorithm, can be done at different strengths, depending on
what the software supports at each end (i.e. the web browser and the web
server).
The strength of the encryption is typically specified by the size of
the session key (a unique value involved in the encryption that differs
for every customer every time he/she visits the site). The session key
can be either 40 bits, 56 bits or 128 bits in size.
Cryptographers consider 128-bit encryption impossible to crack, as it
would take millions of years with the fastest computers to try all the
combinations. On the other hand, 40- and 56-bit keys are not as strong
and it is feasible to try all the combinations.
Historically, the USA restricted the export of strong encryption
products. This meant that the browser versions developed for export from
the US were not automatically enabled to encrypt communications using
128-bit encryption. All secure communications using these international
browsers used 40-bit encryption. It is important to realize that a
substantial number of browsers used in the US today are international
browsers. So even if you only serve US customers, you may still require
an SGC SuperCert to provide them with the strongest possible encryption. |
|
What is SGC technology that is found in
thawte's SGC SuperCerts? |
| SGC technology stands for Server Gated
Cryptography and thawte has been issued a
license by the US Bureau of Export Administration (BXA), allowing the
issue of certificates that enable 128-bit SSL sessions in older browsers
that are usually restricted to 40/56-bit encryption. The difference
between SGC SuperCerts and normal SSL Web Server certificates is that
whenever one of these older browsers connects to a site that has a SGC
SuperCert installed, the SSL session will be automatically 'stepped-up'
to 128-bits, instead of being negotiated at an encryption level that the
browser has been defaulted to (40/56 bits).
IE 4.X or Netscape 4.06 and later)
thawte's SGC SuperCerts automatically
step up to 128-bit encryption for certain end-users with the Windows
operating system who, in the past, would not receive 128-bit
encryption irrespective of the version of Internet Explorer used.
The
systems affected are those that shipped prior to about March of 2001 and
did not subsequently have Microsoft's High Encryption pack or Service
Pack 2 installed. thawte's
SGC SuperCert ensures that all these site
visitors enjoy the protection of the strongest SSL encryption available.
An SGC SuperCert from thawte will allow
your clients to extend 128-bit encryption to their customers, even if
they use browsers (IE 4.X or Netscape 4.06 and later) limited to 40-bit
or 56-bit encryption capabilities. |
|
|