Security Basics mailing list archives

Re: Extended Validation SSL Certificates


From: krymson () gmail com
Date: Tue, 3 Mar 2009 08:02:41 -0700

1. Sadly, even if people don't know what a green bar means, the major browser players will make sure you care. Instead 
of a quickly dismissed pop-up dialog box, recent browser versions render a full error page. In IE7, you then have to 
unintuitively click the *red* link to proceed in an "unsafe" fashion.

2. Some info on the process can be found here: http://www.terminal23.net/2009/01/ev_ssl_fail_or_how_to_rebrand.html


<- snip ->
W W wrote:
I guess this begs the question on whether extended validation certs
are really worth their merit. You are correct in the information you
provide to cert companies is not much more then what you would provide
for a standard cert. Technically they are no more secure than your
standard cert so what is the point? How many users out there really
know what the "green bar" bar really means or even care?

I don't know, but based on the general awareness of such things by
ordinary users I would guess not that many. What type of clients you
target is certainly a factor consider before purchasing one.

Odd


On Thu, Feb 26, 2009 at 7:13 PM, Odd wrote:
s0h0us wrote:
Can anyone share their experiences with the purchase of these certs?
I've heard the amount of information that needs to be supplied and
the due diligence required is a difficult and long process.
Some months ago I purchased one from Verisign for a
multinational company. It took a while to get it, but there
was no more job than for regular certs.

Odd


Current thread: