ServerTastic Blog - Stuff that happens at ServerTastic and other product related things
Filed under

QuickSSL Premium

 

Important SSL Changes


There have been some significant changes to the SSL certificates supplied via ServerTastic. The most important point to make is that these changes do not affect any certificates already issued and installed.

SSL invite URLs
All invite URLs issued from today now have a validity of 365 days from purchase. This means you must use the invite URL to generate your SSL certificate within 365 days of placing your order. This also applies to bulk purchases. Failure to use the invite URL within 365 days will result in the invite expiring and becoming invalid. No refunds or replacements will be issued for expired invite URLs.

Geotrust certificates now use intermediate
Geotrust certificates such as the QuickSSL Premium used to be issued from a root CA certificate. This meant that when installing your certificate there was no additional "CA Bundle" to install. However Geotrust certificates issued from today will require an intermediate certificate. This intermediate certificate will be supplied with your certificate during purchase.

The installation process may have changed slightly depending on the certificate and server OS. Please make sure you read the fulfilment email completely before commencing installation.

2048Bit minimum key size
From 2013 all SSL certificates must have a minimum 2048bit key size. Therefore if you order a certificate that extends beyond this then the CSR must be generated with a key size of at least 2048bit. You can order certificates using a smaller key size that expire before this date however you will receive a warning during the order process.

Root migration
Many SSL certificates are being migrated to alternative root certificates with a minimum 2048bit key size. This does not affect any existing SSL certificates. However re-issues and new certificates will be issued from the new root. There is no action required by customers during the root migration.

PKCS7 downloads
Certificates can now be downloaded as PKCS7 (which will include the intermediate CA) from the SSL control panel

Plesk/Apache bundle downloads
Certificates can now be downloaded as Plesk/Apache bundles from the SSL control panel

RapidSSL Certificates
RapidSSL and RapidSSL wildcard certificates will continue to be issued from a root certificate until 23 September 2010. 

Questions
If you have any questions/concerns about these changes please let us know in the comments or contact us

Filed under  //   Geotrust   QuickSSL Premium   rapidssl   SSL   thawte  
Posted by Andy Gambles 

Comments [0]

SSL email approver options


Last month the approver email address options for domain validated SSL certificates were restricted. This was due to a number of security problems which arose. (Someone was able to register the ssladmin@ account at a number of webmail accounts).

This prompted a review of the email addresses available to select for domain approval. This affects RapidSSL, QuickSSL Premium and SSL123 products.

The following email addresses can be used for domain approval:

  • admin@
  • administrator@
  • hostmaster@
  • root@
  • webmaster@
  • postmaster@
  • The current whois admin contact
  • The current whois technical contact

You must have access to one of these email accounts on the SSL domain to be able to receive the SSL certificate.

Filed under  //   QuickSSL Premium   rapidssl   SSL   SSL123  
Posted by Andy Gambles 

Comments [0]

RapidSSL and Geotrust now secure WWW and non-WWW domain


OK So I said this before back in March and then the feature got withdrawn suddenly due to some technical problems! Well it is back now and has been active for the last few days.

The latest update to the SSL order system means that RapidSSL and Geotrust certificates now automatically secure the WWW and non-WWW domain in a single certificate.

For instance if you order a RapidSSL certificate for www.servertastic.com it will also secure servertastic.com for no extra charge and within the same certificate. You do not need to do anything extra in the order process this is automatic.
 
The following certificates now have this feature at no extra cost

All these are available for amazing discounts on ServerTastic.

If you are not already signed up to our newsletter visit the blog and do so now.

 

Filed under  //   EV   Geotrust   QuickSSL Premium   rapidssl   SSL   True BusinessID  
Posted by Andy Gambles 

Comments [2]

Resend missing approver email


When you purchase an SSL Certificate such as RapidSSL, QuickSSL Premium or SSL123 you have to complete an approver email process. 

This means that during your order you choose from a pre-determined list of email addresses. An email is then sent to this email address with a link you must click to complete the order.

This process is an automated way of validating you have access to an email address associated with the domain and therefore have the authority to request a certificate.

The order will not be completed until this approver email process is completed. Recently we have had a number of customers raise tickets saying they have not received this email, that they forgot to set-up the mailbox this was sent to or they just want it resending.

If you do not complete the approver email it is automatically resent every 12 hours until you do. However you can also resend it yourself at anytime via the Self Service SSL Portal.

I posted more information about how to Manage Your SSL Certificate Orders last year.

If you have any questions about this process please let me know.

Filed under  //   Geotrust   QuickSSL Premium   rapidssl   SSL   SSL123  
Posted by Andy Gambles 

Comments [0]

RapidSSL and Geotrust now secure WWW and non-WWW domain


The latest update to the SSL order system means that RapidSSL and Geotrust certificates now automatically secure the WWW and non-WWW domain in a single certificate.

For instance if you order a RapidSSL certificate for servertastic.com it will also secure www.servertastic.com for no extra charge and within the same certificate. You do not need to do anything extra in the order process this is automatic.
The following certificates now have this feature at no extra cost

All these are available for amazing discounts on ServerTastic.

If you are not already signed up to our newsletter visit the blog and do so now. More exciting features and promotions will be announced soon.

Filed under  //   EV   Geotrust   QuickSSL Premium   rapidssl   SSL   True BusinessID  
Posted by Andy Gambles 

Comments [4]

SSL Certificate Flagged For Quality Review


The RapidSSL and QuickSSL Premium SSL certificates sold by ServerTastic are usually issued in less than 10 minutes from your order. They simply require you to click a link in an email to complete domain validation.

However we are receiving an increase in the number of tickets asking about delays in the certificate being issued and "quality reviews". It is possible that your SSL order may be flagged for a quality review by RapidSSL/Geotrust. This means that the order must be completed by a member of the RapidSSL/Geotrust staff.

You will know if your certificate has been flagged for review because on the confirmation page after you click the email authorisation link you will see the following wording

Your order is pending a final quality review prior to issuance. This review is normally completed within one business day. For more information on why your order was selected for final quality review visit our FAQs at [link]

There are many reasons your order may be flagged for review. These include:

  • Domain whois details appear invalid
  • Website does not load or resolve
  • The domain contains a flagged phrase. For example BANK is a defined term therefore a certificate for riverbanktours.com may be flagged for quality review
  • Your order was randomly selected for review (unlucky!)

Here are some of the things you can do (before requesting your certificate) to try and reduce the likely hood of your order being flagged for a quality review:

  • Remove any whois privacy settings on your domain
  • Make sure the domain whois contains valid details
  • Make sure the domain resolves to a live website

If your certificate does get flagged for a quality review there is very little ServerTastic can do to speed up the review process. They are all checked on a first come first served basis during working hours Monday to Friday. The review is performed by RapidSSL/Geotrust NOT ServerTastic. You can try and speed up the review by contacting Geotrust on the LiveChat link from their support page. In most cases they can do the required steps with you while on line.

It is also likely that the certificate would have been flagged if you had ordered through any other reseller or direct.

You can always contact ServerTastic if you have a problem with your order but please be aware there is little we can do if the order is under quality review.

Remember you can also check the status of your order at any time via the Self Service System.

Filed under  //   Geotrust   QuickSSL Premium   rapidssl   SSL  
Posted by Andy Gambles 

Comments [0]

QuickSSL Premium Secures WWW and non-WWW


The QuickSSL Premium SSL certificate from Geotrust can now be used to secure both the www and the non-www part of a domain with just a single certificate.

NOTE: This has now changed. The QuickSSL Premium now automatically secures the www and non-www portion of the SSL domain. You do not need to follow the instructions any further.

In fact the certificate can secure the main domain and up to 3 sub-domains. Those of you with an understanding of SSL certificates will see that this is done by providing 3 SANs within the SSL certificate.

If that wasn't good news on it's own the even better news is that this does not cost any extra with ServerTastic.

But there is some bad news. To enable this on the certificate is a little bit fiddley. I will do my best to describe how to do it (we hope to make this much easier in the future).

Just one other point before we continue this can not be applied to certificates already issued but you can use this with any QuickSSL Premium invites you have not yet used.

When you order a QuickSSL Premium certificate from ServerTastic you will get an enrolment URL sent to you via email like the one below

 

 

Do not click on the URL. Instead copy and paste this into your browsers address bar. Then you must add &SAN=True onto the end of the URL as per the example below.

 

 

Hit enter and you will then be taken to the QuickSSL Premium enrolment screen. The second page of this process is where you would paste your CSR. But you should also see some additional options at the bottom of the page were you can enter up to 3 domains

 

 

Firstly you should completely ignore the Microsoft Small Business Server 2003 text. This is now redundant and we are trying to get this changed.

In the 3 boxes Domain 1, Domain 2 and Domain 3 you can enter the domains you want to secure with this certificate. They must however be part of the main domain.

Here are some examples

CSR: www. servertastic.com
Domain 1: servertastic.com
Domain 2: checkout.servertastic.com
Domain 3: support.servertastic.com

 

CSR: servertastic.com
Domain 1: www. servertastic.com
Domain 2: checkout.servertastic.com
Domain 3: support.servertastic.com

 

As you can see you can either include the www element of your domain in the CSR or as one of the extra domains.

The QuickSSL Premium certificate is available at ServerTastic from just $55.00 a year.

Be sure to leave your questions or comments below if you have any!

 

Filed under  //   Geotrust   QuickSSL Premium   SSL  
Posted by Andy Gambles 

Comments [4]

QuickSSL Premium with Mail Servers


One of our most popular certificates is the QuickSSL Premium.


The increase in popularity would seem to be due to the fact it is mobile ubiquitous and fairly inexpensive. Unlike the RapidSSL certificate the QuickSSL Premium is present in the vast majority of todays mobile devices. This means it can be used on mail servers such as SmarterMail and users can connect from a mobile device without receiving any warnings or the need to install any root certificates.

Filed under  //   Geotrust   Mail Servers   QuickSSL Premium   SSL  
Posted by Andy Gambles 

Comments [0]