Sign your own certificate.
Users would have to go through a certificate acceptance process, so
that they would not get a bunch of security screens coming up when
they enter the secure area.
Just add a help page to step users on how to add the certificate to
their browsers. Internet explorer (ie) is more difficult to do this
than netscape, and the MAC version of ie is even more difficult (if
not impossible) to add certificates (so suggest that mac users use
Netscape [hello? microsoft? did you hear that? hint hint.]).
You may want to create a separate secret key for the signing of the
main certificate, and keep it in a safer place than on your website.
Optional.
Hope this is what you are looking for.
Blair.
>I'm a librarian in charge of a Solaris server. The library wants to
>offer some services requiring ssl (e.g. forms requiring social security
>numbers). I have installed an Apache web server with mod-ssl and created
>my own certificate, but we will need an official certificate to make
>this work properly. The University IS Dept. tells me that SSL
>Certificates are a big hassle and it would be a mistake for the library
>to try to maintain one. They have had major problems with certificates.
>They are a totally NT shop. The library has the only UNIX server on
>campus. So my question is, are there problems with maintaining an SSL
>Certificate on a Solaris box? Or are these problems only related to
>Microsoft incompatibilities? Does anyone have recommendation about
>signing authorities? Verisign or Thawte? Thanks.
>
>Bob Richart, Systems Librarian
>City University
>919 SW Grady Way
>Renton, WA 98055
>(425) 204-3756
>[EMAIL PROTECTED]
>
>______________________________________________________________________
>Apache Interface to OpenSSL (mod_ssl) www.modssl.org
>User Support Mailing List [EMAIL PROTECTED]
>Automated List Manager [EMAIL PROTECTED]
Computer Engineering Inc.
http://www.compeng.net
Phone: 780 499 5687 (9 - 5 MST)
Fax: 780 435 0693 (24 Hours)
______________________________________________________________________
Apache Interface to OpenSSL (mod_ssl) www.modssl.org
User Support Mailing List [EMAIL PROTECTED]
Automated List Manager [EMAIL PROTECTED]