In order to use SSL-protected communications, such as exchanging Web traffic using the HTTPS protocol, an enterprise must first purchase and then install a digital certificate on its server. This involves selecting a certificate authority (such as Verisign or Thawte), proving your identity to that CA, paying a certificate fee and installing the certificate on the server. The exact technical steps will depend upon the type of server...
you're running, but each CA has detailed instructions on their websites for obtaining a certificate.
It's important that you obtain a digital certificate if you wish to provide users with the ability to securely connect to your website. Without a certificate, they will be unable to use SSL encryption to connect to your site and will not have a guarantee of your server's identity or the peace of mind that their information is encrypted while in transit over the Internet.
Dig deeper on PKI and Digital Certificates
Related Q&A from Mike Chapple, Enterprise Compliance
The HHS security risk assessment tool is designed to help healthcare providers meet the HIPAA security requirement. Expert Mike Chapple explains how ...continue reading
PCI DSS requirement 6.6 demands application security compliance through one of two options: an application firewall or a code review. Expert Mike ...continue reading
Are HIPAA-compliant hosting services a better option for compliance than a secure storage API? Expert Mike Chapple analyzes.continue reading
Have a question for an expert?
Please add a title for your question
Get answers from a TechTarget expert on whatever's puzzling you.