Secure Socket Layer encryption (SSL) provides additional security for
businesses that deal with sensitive or confidential information, or offer
secure transactions online. SSL support is included with all web hosting
plans.
SSL on your own domain (https://www.yourdomain.com) requires
that you purchase your own SSL certificate. This confirms that you are
who you say you are and is necessary for SSL to to function correctly.
This process requires us to generate a Certificate Signing Request and
that you have this signed by a Certification Authority. The signed certificate
is then installed to your domain. FastVirtual supports VeriSign, Thawte
and GeoTrust certificates, as well as others.
Shared Secure Server
FastVirtual provides a shared secure server as standard with all web
hosting plans. This is immediately available for use and requires no special
configuration or uploads. Simply point your browser to https://www.yourdomain.com/
and all content uploaded to your domain will be available securely.
Although the shared secure server is fully functional, visitors using modern browsers will receive
a warning as our shared key will not match your domain name. For eCommerce purposes we therefore strongly
recommend that you purchase your own SSL certificate (https://www.yourdomain.com).
File Locations
All documents on your site can be accessed normally, through your own
secure server and through the shared secure server. The following URLs
display identical content:
http://www.yourdomain.com/
https://www.yourdomain.com/
Similarly, the "cgi-bin" directory is mirrored:
http://www.yourdomain.com/cgi-bin/
https://www.yourdomain.com/cgi-bin/
Many of our free web tools and scripts are also mirrored:
http://www.yourdomain.com/cgi-t/
https://www.yourdomain.com/cgi-t/
CGI Issues
CGI scripts are executed identically on the normal web server and the secure
server. You can determine the server type within your CGI
script by examining the HTTPS environment variable. If HTTPS=ON, the
script is being accessed through the secure server. Otherwise it is being
accessed through the normal web server.
Please see our tips for writing
portable CGI for guidelines on developing scripts that function
correctly on both secure and normal web servers.
Costs Involved in Using SSL
There are no costs involved in using the shared secure server.
SSL on your own domain (https://www.yourdomain.com) requires that
you purchase your own SSL certificate. This confirms that you are who
you say you are and is necessary for SSL to to function correctly.
This process requires us to generate a Certificate Signing Request (CSR)
and that you have this signed by a Certification Authority (CA), such as VeriSign,
Thawte or GeoTrust. The signed certificate is then installed on your domain.
A CSR can be automatically requested from the "Hosting" area of your control panel.
The process involves a $25.00 setup fee, which includes the installation and configuration
of your issued certificate.
FastVirtual supports VeriSign, Thawte and GeoTrust certificates, as well as
others. Please visit your control panel for current pricing.
Obtaining Your SSL Certificate
To obtain your SSL certificate and establish your own https://www.yourdomain.com/
secure URL, please visit the 'Hosting' section of your account control
panel and select Commerce. Under SSL, select Add/Manage
SSL keys and click Create a new SSL Request for a New Domain.
If you require a VeriSign or Thawte certificate, you can choose for
FastVirtual to complete the application on your behalf, or to complete
the process yourself. For other certificate types, you will need to complete
the process yourself.
- Enter your information as it should appear in your SSL certificate.
The information you provide will be used to generate your CSR (Certificate
Signing Request), so double-check for errors. Once issued, a CSR cannot
be altered, so if you discover an error when you reach step 3, you will
have to start the whole process again.
- Once you have submitted your details, if you selected for FastVirtual
to complete the application, you have nothing further to do. If you
selected to complete the process yourself, you will receive your completed
CSR by email (please allow at least 48 hours), together with a link
to your stipulated CA's (Certification Authority's) application URL.
- Follow the link provided and paste the CSR into the designated form.
Then follow the step-by-step application process.
During this process you will be prompted to verify the accuracy of the
information provided in your CSR. You should double-check this, as it
cannot be modified once you complete the application process.
You will be asked to provide organizational information about your company,
which needs to be verifiable. This can include your D&B DUNS number,
or a copy of your Certificate of Incorporation. At this stage, you will
also be prompted for payment information.
- Once your certificate has been issued, usually within 3-5 days,
you will be notified by email and given a link to the applicable CA's
web site, where you certificate can be downloaded.
- Simply send the signed certificate (in plain-text) to
support@fastvirtual.com,
making sure you include your account name in the subject line of your
email.
We will notify you once the installation has been completed (please
allow at least 48 hours). Once your certificate has been installed,
your secure URL, https://www.yourdomain.com/, will be active.
Choosing VeriSign, Thawte or GeoTrust
FastVirtual supports VeriSign, Thawte and GeoTrust certificates, as
well as others. It's up to you to decide which better serves your needs,
based on price and browser compatibility.
Please visit your control panel for current pricing.
Moving Your Secure Key to FastVirtual from Another Provider
If you wish to move an existing SSL certificate to FastVirtual from
another hosting provider, you should send us both the
certificate and the key. If you are unable to provide both items, you will
have
to apply to your certification authority for a new key.
Secure Server Specification
FastVirtual uses Stronghold-powered secure servers, a derivative of
Apache (our normal web servers). Security is assured with Stronghold,
which utilizes the most robust authentication protocols and standards
available today. Stronghold is stable, reliable, and features 128-bit
encryption; the current maximum.
Every effort has been made to ensure secure servers behave identically
to the normal web servers. SSL is fully compatible with the storefront
systems included with our Gold, Platinum and Platinum Plus hosting plans,
as well as many other ecommerce applications.
Find Out More
To find out more about secure server IDs, please see the
Symantec/VeriSign FAQ, or the
Symantec/Thawte SSL Overview.
|