SSL Information Centre - About SSL Certificate Licensing - VeriSign UK Ltd.
VeriSign, Inc.® United Kingdom Home | Worldwide Sites | Site Map
You Are Here: United Kingdom Home > SSL Certificates > SSL Information Centre > About SSL Certificate Licensing

SSL Information Centre

About SSL Certificate Licensing

As enterprises and service providers enhance their Web sites and extranets with new technology to reach larger audiences, server configurations have become increasingly complex. To ensure a common, high-level standard of security across all types of configurations, VeriSign recommends that you do not share or copy certificates among servers.

Tuesday-Wednesday Problem
ProblemWhen Deploying different certificate types across a site creates the Tuesday-Wednesday problem. A site visitor may receive one kind of SSL assurance on Tuesday when shopping and a different level of SSL assurance when they return on Wednesday to purchase, eroding confidence.
SolutionDeploy the same type of SSL Certificate across multiple servers. If you have staggered validity periods and need to upgrade all of your SSL Certificates to the new Extended Validation Standard, contact VeriSign for assistance.
Certificate Sharing
ProblemWhen private keys are moved among servers - by disk or by network - accountability and control decrease and auditing becomes more complex. By sharing certificates on multiple servers, enterprises increase the risk of exposure and complicate tracing access to a private key in the event of a compromise.
SolutionDeploy a unique certificate for each server or license a single certificate across multiple servers in appropriate configurations.

The VeriSign subscriber agreement prohibits customers from using a certificate on more than one physical server or device at a time, unless the customer has purchased the Licensed Certificate Option. VeriSign's licensing policy allows licensed certificates to be shared in the following configurations:

- Redundant server backups
- Server load balancing
- SSL accelerators
Business Identity Authentication
ProblemWhen a user connects to a Web site secured by an SSL Certificate, the client browser and the site perform an SSL handshake. At that time, the client browser confirms that the Web site URL and the common name of the certificate are the same. If they are not, the client browser will display a warning.
SolutionUse appropriate Common Name and organisational information to prevent warnings or error messages.

To ensure that users receive correct information and that their information is protected, VeriSign recommends that certificates are not shared in a configuration with multiple physical servers with different hostnames.
NetSure Protection Plan
ProblemIf customers violate the terms of the certificate licence, they forfeit the NetSure protection provided with their certificate.
SolutionFollow the terms of the certificate licence.

Due to the increased risk of private key compromise associated with copying certificates and private keys from server to server, licensing a certificate for multiple servers is less secure than deploying unique certificates. For this reason, VeriSign offers only $10,000 in NetSure warranty protection for each additional licence purchased.


Need Help Deciding? Why VeriSign?
Call 0800 032 2101  Request Information online

Contact Us
Contact VeriSign

Sales
Tel: 0800 032 2101

Submit an inquiry >>
 
ABOUT SSL CERTIFICATES
Contact VeriSign Legal Notices Privacy Repository © 2003 - 2008 VeriSign UK Limited. All rights reserved.
5/8/08 9:55 PM