Picture of 🚀 SSL Problem Solvers 🚀

🚀 SSL Problem Solvers 🚀

How do I Renew my SSL Certificate?

 

Important Please note:

  • You can purchase SSL certificates for more than one year, but you must renew your certificate every year and raise a support ticket with the renewed certificate. This is an industry standard rule changed on 1st September 2020.

The below CSR information are the required fields needed on the SSL renewal ticket form:

  • Country Name (full name)
  • State or Province Name (full name)
  • Locality Name (e.g. city)
  • Organization Name (e.g. company)
  • Organizational Unit Name (e.g. section / department)
  • Common Name (e.g. your name or your server's hostname, should be exact to the website name)
  • Email Address

***

We ask that you send us the renewed certificate 2-4 weeks before it is due to expire (This allows for plenty of time for the SSL to be renewed before it expires). SSL renewals without a rush fee* are charged at £75 + VAT / USD $100 / €90 / AUD $145 / CAD $129. If you forget to renew your certificate then we may be able to rush* through the renewal, however the costs for this vary. 

  1. Please log into your providers site (for example, 123 Reg, Go Daddy, DigiCert, etc). If you're unsure of how to do this with your given provider, then please go to their help pages for instructions. 
  2. Go to your account
  3. Find the SSL in question and there should be a renewal option.
  4. Renew the certificate & download a copy
  5. Please submit a SSL Renewal Ticket,attach the certificate / zip file and confirm the storefront URL. If you have a wildcard SSL, please please also give us the primary domain.
  6. SSL Certificate Renewals are applied to your site and the Support Team will let you know when these are done.

If your certificate is close to expiry or has expired and you would like us to rush* it through then we may be able to do so. To renew an SSL certificate in less than:

  • 5 working days we charge £150 + VAT / USD $200 / €180 / AUD $290 / CAD $258
  • 2 working days we charge £375+VAT/ USD $500 / €450 / AUD $730 / CAD $644

*Rush fees explained: If you need us to apply the renewed certificate on your storefront(s) after the SSL has expored then there will be a rush fee. This is because this task will be put in front of all other tasks to get your renwel completed sooner. We cannot guarantee a rush fee, but we will do our best to accommodate you. 

Bindings and SSL Certificates FAQs

In this article we will cover some the questions that we often get asked when adding a new binding to a storefront, securing a storefront with an SSL certificate and renewing your existing SSL certificate. 

Question: What is a binding? 

Answer: A binding is the URL that is 'assigned' to your storefront. Essentially the address an end user will go to when they want to visit your site. When we create a new platform we give it a default URL and then any storefronts you create will have the same URL with a /storefrontname at the end. 

Question: Do I have to change the storefront binding? 

Answer: No, you don't have to add a new binding. 

Question: How do I add a new binding? 

Answer: We have an article which explains everything, so please have a read of that and then submit a ticket with the storefront name (as it is) and the new binding (URL) that you'd like for that storefront. 

Question: What do I need to add a binding? 

Answer: Before you get in touch with us, you need to buy the domain. There are lots of websites where you can purchase domains. 

Question: What is an SSL Certificate and why do I need one? 

Answer: SSL stands for Secure Sockets Layer, a security protocol that creates an encrypted link between a web server and a web browser. Companies and organisations need to add SSL certificates to their websites to secure online transactions and keep customer information private and secure.

Question: What happens if I don't secure my storefront with an SSL? 

Answer: When people visit your storefront they will be shown a security warning and advised not to proceed to the site. 

Question: How long is an SSL certificate valid for? 

Answer: Different providers will sell SSL certificates for different lengths of time, however all SSLs need to be updated yearly. You will need to create a ticket every year (we ask you to do so 2-4 weeks before it is due to expire) so we can update your SSL. 

Question: What happens when my SSL certificate expires? 

Answer: When people visit your storefront they will be shown a security warning and advised not to proceed to the site. 

Question: How do I renew my SSL certificate? 

Answer: Please see our help centre article.

Question: I have more than one binding that I'd like to secure. Do I need more than one certificate? 

Answer: This depends on the bindings that you'd like to use. We have an article that explains the different types of SSL certificates; please give it a read and let us know if you have any questions. 

Question: The binding I would like to use is already in use on another website which I plan to move to Infigo. What do I need to do in this instance? 

Answer: We have lots of customers that move sites onto Infigo storefronts, so this is something we do a lot. You can setup the binding on Infigo as normal, you will also need to secure the storefront with an SSL certificate. To avoid any disruption to the existing site we would recommend purchasing a new SSL certificate for the Infigo site. 

If the existing site (the non-Infigo storefront) is not live, and it can be left unsecured, then you can obtain a new CSR from the Infigo Support Team and download a new copy of the same SSL for us to apply to your Infigo Storefront. 

Question: Are there costs involved in settings up new bindings and securing them with SSL certificates? 

Answer: Yes, all costs are outlined here:

New Binding 

SSL Implementation 

SSL renewal 

Question: How long does it take to setup a new binding and secure the storefront with an SSL certificate? 

Answer: Bindings and SSLs are applied with our twice monthly deployment (every 2 weeks). So please give us at least 2 weeks notice. 

Question: I missed my SSL expiry reminders from my provider, and my certificate is going to expire within a few days. What can I do? 

Answer: Sometimes we're able to rush SSL renewals (costs outlined here). Please submit a ticket and make a note that it is due to expire and you'd like to proceed with a -5 day, or -2 day rush. Please note: this is only during normal business hours (Monday - Friday, 0900 - 1800 GMT) and is subject to capacity in the team. It is not always possible. 

Question: I don't own the domain, but I need to buy the SSL certificate. How does this work? 

Answer: Each provider will handle this differently, however it is normally handled with a verification email. Wherever you're purchasing your SSL from, you will be asked for the site you wish to secure and the CSR. Once that information has been provided you will be given a list of email address that can verify your request. Once the email address holder has verified this, you will be provided with the certificate / a zip file containing the certificate. 

Please note: each provider will have a slightly different process. Please refer to their own help pages for instructions.  

Question: What is a CSR? 

Answer: A CSR (Certificate Signing Request) is a specific code and an essential part for the SSL activation. It contains information about website name and the company contact details. We need to create for this you because we are hosting your site.

Question: I already have a certificate from another site. Can I use that? 

Answer: Yes, you can. However, we will need to create a CSR for you to download a new copy of that certificate. You will need to compete our CSR Form and submit a ticket. The CSR Form is attached to this article. 

Question: I've just changed my binding, but my header and footer links are still showing the old infigo URL.

Answer: Now that the new binding is in place, the header and footer links will need to be updated manually.

Here’s a handy guide that walks you through how to do that:

👉 Changing Header/Footer Links After Adding a New Binding

SSL certificate security: why you should not share private keys

When a public/private key pair is generated, the key must be generated from a good source of randomness and should normally be generated by the end entity that will use it.

Where a private key has to be generated away from the end entity, then it must be encrypted in transit and at rest. Access to the key must be monitored, authenticated and authorised, see principle 3, develop a robust certificate registration procedure.

Once a private key has been generated, it must be protected so that it can only be used by the identity it represents. The private portion should always be kept secure, while the public portion can be distributed to other users in the system. If the private key came into the hands of an attacker, they could use it impersonate a user and gain access to a system.

Why shared private keys are vulnerable:

Shared private keys open up the possibility for stolen keys, and stolen keys can mean signed software with vulnerabilities or malware being distributed with your company’s name on it. It’s like the key to your front door: you want to make sure it is protected and only with people you trust at all times. Shared private keys can get lost or stolen in transit or abused. Plus, there is no way to track who signed what and when if everyone has a local copy of the same signing key.

If you would like to share your private key with Infigo, or you would like us to send you the private key we generate, then we must have written consent on the support ticket accepting you're invalidating the SSLs security and accept all risks. 

The SSL Implementation Process: Securing Your Storefront

This article will explain the step-by-step process of starting, obtaining, and implementing an SSL certificate. Implementing an SSL is a chargeable request as it takes some time for our development team to complete this task.

The following pricing charges are separate from the price it will cost for you to purchase your SSL. Infigo is not responsible for obtaining certificates: 

UK: £100 + VAT  /  USD $120  /  € 115 / AUD $195 / CAD $172

Note: Before the SSL Process can begin, the new domain you will be protecting will need to be configured. The process on configuring a new URL binding can be found here

If you would like to know more about SSLs and why they are important, click here. Also, if you are not sure what kind of SSL to purchase, this article can help you determine which one best suits your needs. 

The Process

1. If you decide to purchase an SSL, you will first need to open a Support Ticket. Here is what the Infigo Support Team will need when you open a ticket:

  • The storefront URL you would like the SSL to cover.
  • A completed CSR form

2. Please download the CSR form at the bottom of this article. Support will provide a Change Request Form to be signed to authorize the implementation of the SSL. Here is some more information on each field required in the CSR Form:

mceclip0.png

3. You (the customer) should then return the completed CSR Form via the Support Ticket and the signed Change Request Form

4. The Support Team will then provide the completed CSR form to the Development team

5. The Development team will then provide the CSR code to the Support team. The Support Team will then attach the CSR code back to the Support Ticket and return it to you.

6. Using that CSR code, you can then purchase the SSL Certificate via a third party provider. Most of our customers use GoDaddy or 123Reg, but feel free to purchase your SSL from any issuer.

7. If prompted, select a IIS supported SSL, download the certificate, and attach it back to the Support Ticket and return the ticket to Support.

8. Infigo Support will then install the SSL certificate on the server on the next scheduled deployment. Note: Currently, Infigo is doing a biweekly release schedule. 

9. Infigo Support will then provide a CNAME for you to configure your DNS. Once you have configured it properly, and the SSL has been deployed, your site should then be secure.

Note: Please keep in mind that your SSL will expire after a certain date, based on what length of certificate you purchased. To ensure that your site remains secure, please see this article explaining our SSL renewal process.

If for any reason you need to expedite this process then we can do so, but there is an additional 'rush charge'. 

CSR form download: 

Types of SSL Certificates

There are three different types of SSLs you can purchase for your domains: Single Use SSL, Wildcard SSL, and a SAN SSL.  Each one of these has pros and cons and this article will help make your decision easier.

Single Use SSL

This SSL only covers one of your domains at a time. It is typically the cheapest one to purchase, but if you have multiple domains to cover, we will need to install a different SSL for each domain you wish to secure.

Wildcard SSL

This SSL will cover a single domain, but with unlimited subdomains, as long as the subdomains follow the Wildcard SSL format. Here's an example of the the format needed to cover multiple domains:

*.yourdomain.com where the * is a subdomain.

As you can see with the storefront we provide you during your Infigo platform handover, we have it following the Wildcard format in order to protect that domain by using the infigosoftware.com Wildcard SSL:

YourPlatform.Infigosoftware.com

So, if we wanted to add a new domain and have it covered under our wildcard SSL, it would have to follow that structure. Here is an example of a new sub domain we could add and have it immediately covered without installing a new SSL:

YourPlatform2.Infigosoftware.com

This SSL is typically a bit more expensive than a Single Use certificate, but cheaper than a SAN SSL, and is best used when you want to separate your storefronts with subdomains instead of regular domains i.e. "storefront1.yourcompany.com," "storefront2.yourcompany.com," instead of "storefront1.com," "storefront2.com."

SAN SSL

The SAN SSL has the ability to cover multiple domains and does not require them to follow a format. For example, you can have the following domains and cover all of them with a single SSL:

storefront1.platform.com

platform.com

storefront1.com

storefront2.com

platform2.com

This certificate is typically quite expensive and also requires you to re-install it each time you add a new domain.

Note: Each re-installation will incur the standard SSL installation fee (see this article for more).

What is an SSL?

An SSL Certificate (Secure Sockets Layer), also called a Digital Certificate, creates a secure link between a website and a visitor's browser.

Why is an SSL Important?

By ensuring that all data passed between the two remains private and secure, SSL encryption prevents hackers from stealing private information such as credit card numbers, names and addresses.

An organisation needs to install the SSL Certificate onto its web server to initiate a secure session with browsers. Once a secure connection is established, all web traffic between the web server and the web browser will be encrypted.

How Do I Secure My Site?

You can visit this article to learn about how we implement an SSL on your storefront. 

How Do I Know if My Storefront is Secure?

When a certificate is successfully installed on your server, the application protocol (also known as HTTP) will change to HTTPS, where the ‘S’ stands for ‘secure’. Depending on the type of certificate you purchase and what browser you are surfing the internet on, a browser will show a padlock or green bar in the browser when you visit a website that has an SSL Certificate installed.

mceclip1.png

Additional Information about SSLs

We would always recommend installing an SSL certificate on your site for your customers' piece of mind, but, also, Google now ranks websites based on their security ratings (Sites which are served through a standard http connection as opposed to https are instantly ranked lower in Google's new algorithm).

Incomplete

Can’t find what you need?

Ask our Infigo Support Team for help..

🔎
Loading…
    Select a Problem Solver