ServerTastic Blog - Stuff that happens at ServerTastic and other product related things
Filed under

rapidssl

 

Important SSL Changes


There have been some significant changes to the SSL certificates supplied via ServerTastic. The most important point to make is that these changes do not affect any certificates already issued and installed.

SSL invite URLs
All invite URLs issued from today now have a validity of 365 days from purchase. This means you must use the invite URL to generate your SSL certificate within 365 days of placing your order. This also applies to bulk purchases. Failure to use the invite URL within 365 days will result in the invite expiring and becoming invalid. No refunds or replacements will be issued for expired invite URLs.

Geotrust certificates now use intermediate
Geotrust certificates such as the QuickSSL Premium used to be issued from a root CA certificate. This meant that when installing your certificate there was no additional "CA Bundle" to install. However Geotrust certificates issued from today will require an intermediate certificate. This intermediate certificate will be supplied with your certificate during purchase.

The installation process may have changed slightly depending on the certificate and server OS. Please make sure you read the fulfilment email completely before commencing installation.

2048Bit minimum key size
From 2013 all SSL certificates must have a minimum 2048bit key size. Therefore if you order a certificate that extends beyond this then the CSR must be generated with a key size of at least 2048bit. You can order certificates using a smaller key size that expire before this date however you will receive a warning during the order process.

Root migration
Many SSL certificates are being migrated to alternative root certificates with a minimum 2048bit key size. This does not affect any existing SSL certificates. However re-issues and new certificates will be issued from the new root. There is no action required by customers during the root migration.

PKCS7 downloads
Certificates can now be downloaded as PKCS7 (which will include the intermediate CA) from the SSL control panel

Plesk/Apache bundle downloads
Certificates can now be downloaded as Plesk/Apache bundles from the SSL control panel

RapidSSL Certificates
RapidSSL and RapidSSL wildcard certificates will continue to be issued from a root certificate until 23 September 2010. 

Questions
If you have any questions/concerns about these changes please let us know in the comments or contact us

Filed under  //   Geotrust   QuickSSL Premium   rapidssl   SSL   thawte  
Posted by Andy Gambles 

Comments [0]

New SSL Wizard Launched


The new SSL Wizard has just been enabled on ServerTastic. The wizard is designed to help you with a number of SSL related tasks including, renewing your SSL, requesting a re-issue, resending your approver email and of course helping you find the best SSL for your requirements.

Please give it a try and let us know your comments. (You can also provide feedback via FaceBook, Twitter and LinkedIn).

Filed under  //   Geotrust   rapidssl   ServerTastic   SSL   thawte   VeriSign  
Posted by Andy Gambles 

Comments [0]

SSL email approver options


Last month the approver email address options for domain validated SSL certificates were restricted. This was due to a number of security problems which arose. (Someone was able to register the ssladmin@ account at a number of webmail accounts).

This prompted a review of the email addresses available to select for domain approval. This affects RapidSSL, QuickSSL Premium and SSL123 products.

The following email addresses can be used for domain approval:

  • admin@
  • administrator@
  • hostmaster@
  • root@
  • webmaster@
  • postmaster@
  • The current whois admin contact
  • The current whois technical contact

You must have access to one of these email accounts on the SSL domain to be able to receive the SSL certificate.

Filed under  //   QuickSSL Premium   rapidssl   SSL   SSL123  
Posted by Andy Gambles 

Comments [0]

RapidSSL and Geotrust now secure WWW and non-WWW domain


OK So I said this before back in March and then the feature got withdrawn suddenly due to some technical problems! Well it is back now and has been active for the last few days.

The latest update to the SSL order system means that RapidSSL and Geotrust certificates now automatically secure the WWW and non-WWW domain in a single certificate.

For instance if you order a RapidSSL certificate for www.servertastic.com it will also secure servertastic.com for no extra charge and within the same certificate. You do not need to do anything extra in the order process this is automatic.
 
The following certificates now have this feature at no extra cost

All these are available for amazing discounts on ServerTastic.

If you are not already signed up to our newsletter visit the blog and do so now.

 

Filed under  //   EV   Geotrust   QuickSSL Premium   rapidssl   SSL   True BusinessID  
Posted by Andy Gambles 

Comments [2]

Resend missing approver email


When you purchase an SSL Certificate such as RapidSSL, QuickSSL Premium or SSL123 you have to complete an approver email process. 

This means that during your order you choose from a pre-determined list of email addresses. An email is then sent to this email address with a link you must click to complete the order.

This process is an automated way of validating you have access to an email address associated with the domain and therefore have the authority to request a certificate.

The order will not be completed until this approver email process is completed. Recently we have had a number of customers raise tickets saying they have not received this email, that they forgot to set-up the mailbox this was sent to or they just want it resending.

If you do not complete the approver email it is automatically resent every 12 hours until you do. However you can also resend it yourself at anytime via the Self Service SSL Portal.

I posted more information about how to Manage Your SSL Certificate Orders last year.

If you have any questions about this process please let me know.

Filed under  //   Geotrust   QuickSSL Premium   rapidssl   SSL   SSL123  
Posted by Andy Gambles 

Comments [0]

CA Root Upgrade for SSL Certificates


During the second half of 2010 VeriSign, Thawte, Geotrust and RapidSSL certificates will transition to use a 2048-bit root.

This will have no impact on existing certificates. These will continue to work as expected. However once the root has been updated (we will provide details when this happens) you must ensure you install any intermediary certificates as instructed in your fulfilment emails.

An important change to note is that once the new roots are in place RapidSSL will be issued with an intermediary certificate. This has become common practice within the industry.

Prior to the change you may want to ensure that your applications support the use of 2048-bit certificates.

For more information and FAQ's please see the links below

Filed under  //   Geotrust   rapidssl   SSL   VeriSign  
Posted by Andy Gambles 

Comments [0]

RapidSSL and Geotrust now secure WWW and non-WWW domain


The latest update to the SSL order system means that RapidSSL and Geotrust certificates now automatically secure the WWW and non-WWW domain in a single certificate.

For instance if you order a RapidSSL certificate for servertastic.com it will also secure www.servertastic.com for no extra charge and within the same certificate. You do not need to do anything extra in the order process this is automatic.
The following certificates now have this feature at no extra cost

All these are available for amazing discounts on ServerTastic.

If you are not already signed up to our newsletter visit the blog and do so now. More exciting features and promotions will be announced soon.

Filed under  //   EV   Geotrust   QuickSSL Premium   rapidssl   SSL   True BusinessID  
Posted by Andy Gambles 

Comments [4]

SSL Certificate Flagged For Quality Review


The RapidSSL and QuickSSL Premium SSL certificates sold by ServerTastic are usually issued in less than 10 minutes from your order. They simply require you to click a link in an email to complete domain validation.

However we are receiving an increase in the number of tickets asking about delays in the certificate being issued and "quality reviews". It is possible that your SSL order may be flagged for a quality review by RapidSSL/Geotrust. This means that the order must be completed by a member of the RapidSSL/Geotrust staff.

You will know if your certificate has been flagged for review because on the confirmation page after you click the email authorisation link you will see the following wording

Your order is pending a final quality review prior to issuance. This review is normally completed within one business day. For more information on why your order was selected for final quality review visit our FAQs at [link]

There are many reasons your order may be flagged for review. These include:

  • Domain whois details appear invalid
  • Website does not load or resolve
  • The domain contains a flagged phrase. For example BANK is a defined term therefore a certificate for riverbanktours.com may be flagged for quality review
  • Your order was randomly selected for review (unlucky!)

Here are some of the things you can do (before requesting your certificate) to try and reduce the likely hood of your order being flagged for a quality review:

  • Remove any whois privacy settings on your domain
  • Make sure the domain whois contains valid details
  • Make sure the domain resolves to a live website

If your certificate does get flagged for a quality review there is very little ServerTastic can do to speed up the review process. They are all checked on a first come first served basis during working hours Monday to Friday. The review is performed by RapidSSL/Geotrust NOT ServerTastic. You can try and speed up the review by contacting Geotrust on the LiveChat link from their support page. In most cases they can do the required steps with you while on line.

It is also likely that the certificate would have been flagged if you had ordered through any other reseller or direct.

You can always contact ServerTastic if you have a problem with your order but please be aware there is little we can do if the order is under quality review.

Remember you can also check the status of your order at any time via the Self Service System.

Filed under  //   Geotrust   QuickSSL Premium   rapidssl   SSL  
Posted by Andy Gambles 

Comments [0]

RapidSSL Re-issuance Insurance


Over the last few months there has been a steady increase in support requests about re-issuing RapidSSL certificates and insurance.

RapidSSL certificates without insurance can be re-issued an unlimited number of times for the first 7 days after the certificate has been issued. This is not the day it was purchased from ServerTastic but the issuance date stated within the certificate.

This 7 day period is provided in case you have problems with installation and need to re-issue the certificate.

After these 7 days have passed it is not possible to re-issue the certificate unless you have insurance. If it is day 8 and you need to re-issue the certificate then sorry but you can't!

It is therefore important that if you are having installation problems during the first week that you seek assistance. If it is coming to the end of the first 7 days and you have not yet got the installation completed contact us and we can cancel the order and you can then start again. We are only able to cancel orders without charge within the first 7 days.

If you purchased your certificate without insurance it is possible to purchase re-issuance insurance directly from RapidSSL at a later date but this will cost more than purchasing a new RapidSSL from ServerTastic.

If you purchase your certificate with insurance then you can re-issue the certificate as many times as you want for the life of the certificate. You do not have to worry about server crashes, corruption or having to move server.

So it is important to note the following points when purchasing your certificate without insurance:

  • You can only re-issue your certificate during the first 7 days
  • You are responsible for maintaining a backup of your certificate
  • If you suffer a server failure and do not have a back-up you will have to purchase the certificate again
  • If you need to move servers/host and can not export your existing certificate you will have to purchase it again
Final Comment:
We are not trying to be awkward or unfriendly. However ServerTastic is a low cost provider. The margins on RapidSSL certificates are very small. As such we are unable to pay for re-issues to customers who do not have insurance. Please if you are unsure we highly recommend spending a little extra and getting the insurance.

Filed under  //   RapidSSL   SSL  
Posted by Andy Gambles 

Comments [0]

Manage Your SSL Certificate Orders


Customers purchasing their RapidSSL, Geotrust, thawte or Verisign SSL certificate from ServerTastic are now able to manage their SSL certificate orders and perform the following actions:

  • Resend approver emails
  • Resend fulfilment emails
  • Re-issue certificates (where purchase allows)
  • Revoke certificates
  • Check status and view comments for org validated and EV certificate orders in process
How cool is that! You no longer need to raise a support ticket to perform any of these actions - you can do them yourself.

"I have heard enough how do I do this?" I hear you all cry. Simply visit the relevant URL below (you can bookmark it) and complete the form. You will require to know the SSL domain, the admin email contact (which you will also require access to) and the captcha.

You will then be shown your order for verification. Click "Select" next to the correct order and then submit to confirm your email address. An email will be sent to the admin contact email address which will contain a unique URL allowing instant access to your order. It sounds a lot more complicated than it actually is. I simply suggest you give it a try!

End User Order Management
RapidSSL and Geotrust branded order management: Click Here
thawte branded order management: Click Here
VeriSign branded order management: Click Here

SSL Certificate Resellers
You can also provide these links to your customer. They are not branded by ServerTastic in anyway so the customer will never know (if that is what you want).

Filed under  //   Geotrust   rapidssl   ServerTastic   SSL   thawte   VeriSign  
Posted by Andy Gambles 

Comments [2]