SSL error messages?

Yesterday, someone told me: “…do you realize that you have an SSL certificate problem at your site?”. Well, it still is a problem, or rather a minor annoyance, but the problem is with browsers, not with our site. Here are the explanations:

We use a free certificate from cacert.org, and I just included a small image in our sidebar to show we do. Some browsers on some operating systems still have problems with these, because they don’t integrate cacert.org as a trusted certification authority. Others, like Debian or even the Nokia 770 do. So what do you do if your browser shows that strange “security” message when trying to connect to our site? There are two possible solutions:

  • accept the certificate permanently (the easy way)
  • insert the cacert.org root certificate (the trusted way)

The browser inclusion status and lots of other tips and howtos can be found at cacert’s Wiki pages, as well as tutorials how to integrate SSL security into your own site. Note that you do need a dedicated IP address to do that - so your site needs to be running on at least some virtual server with its own IP. If you have that, you can add security cost-free.

Leave a Reply