Robert Richart wrote:
> I'm a librarian in charge of a Solaris server. The library wants to
> offer some services requiring ssl (e.g. forms requiring social security
> numbers). I have installed an Apache web server with mod-ssl and created
> my own certificate, but we will need an official certificate to make
> this work properly. The University IS Dept. tells me that SSL
> Certificates are a big hassle and it would be a mistake for the library
> to try to maintain one. They have had major problems with certificates.
> They are a totally NT shop. The library has the only UNIX server on
> campus. So my question is, are there problems with maintaining an SSL
> Certificate on a Solaris box? Or are these problems only related to
> Microsoft incompatibilities? Does anyone have recommendation about
> signing authorities? Verisign or Thawte? Thanks.
>From a technical point of view, certificates require zero maintenance,
and their generation is pretty straitforward if you follow the
instructions.
In our experience the difficult part about certificates is the
administration issue - you need to prove to the cert authority that a)
you are who you say you are, b) that you own the domain name that you
want a cert for, and c) you are authorised by the company to get the
cert. This generally involves a whole lot of bureaucracy and red tape
and is rather frustrating, but fortunately it only needs to be done
once.
When we bought certs from Thawte, we followed the step by step process
they offer on their website that isn't that complicated. Your IT
department seems to be making a bigger issue out of it than necessary.
Regards,
Graham
--
-----------------------------------------
[EMAIL PROTECTED] "There's a moon
over Bourbon Street
tonight...
______________________________________________________________________
Apache Interface to OpenSSL (mod_ssl) www.modssl.org
User Support Mailing List [EMAIL PROTECTED]
Automated List Manager [EMAIL PROTECTED]