To SSL or not to SSL that is the question?

We’ve been given conflicting information and wanted some other cs cart users/experts input. It’s the first e-shop I’ve done and we came to the part of online payments. The shop owner wants the payments to be handled online and not to deal with processing them himself in the shop and as such set up a paypal account.



At this point I was told by a fellow web designer that I needed an SSL, which we purchased upon consulting with the hosting company. They are now telling us the SSL isn’t working and to make it work by giving the site a dedicated IP they want a lot of money to make the changes, but asked why we would bother with an SSL if an external processor would do the payments? This was seconded by another web designer who suggested just using something directly with a bank and take SSL out of the picture.



So how are other cs cart users doing their online payments? and do I need to invest in the changes to make my SSL certificate work???

SSL certificate is also for encrypting users information and send their data to server. If you are using third party payment like Paypal, so this is the optional to use SSL Certificate but i recommend to use SSL. May be you can find a low price of Geotrust, Thawte ssl. Don’t buy Godaddy, it is useless, only the domain and name is important on their company.



I am using Verisign SSL for third party payment like Paypal & Credit Card transaction, however CC need to be rediret to gateway site, but it is required for my business, On my country people never purchase from me if they unable to see SSL Secure, Hacker Safe Secure or Trust Seal. May be everyone want to see those certificate but now you will only invest either in Trust Seal or SSL.



I am paying for $24/yr for one dedicated IP.

For SSL you will require a dedicated IP address OR a shared-ssl host. Either of these will have to be provided by your hosting company. Dedicated IP addresses should not cost more than $5~$10 per IP, wholesale costs for IP addresses are less than USD$1 - anything higher and your host is pulling tricks.



You MUST have an SSL certificate for online transactions where you capture customer information. Credit-card data and it’s collection differ depending on your geographical location pursuant to local, national and international requirements covering personal and financial data.



You must remember that you are the gatekeeper to personal information AND credit-card information - you require an SSL for both.

Hi, great info everyone. I wouldn't personally buy from a site if they didn't have one. Especially when I login to my account. Once you are loged in, it should show https.



I'm about to get the Comodo Elite SSL certificate at $300 a year. Does anyone have experience with it? I'm thinking of getting it because their seal looks really good and they will also offer hacker proof seal and HackerGuardian PCI Scanning free for 1 year.



Please let me know your thoughts. I'm looking for good seals to make the site look as legit and trustworthy as possibly.



Thanks.



D.

[quote name='Belzibot' timestamp='1308454703' post='115264']

Hi, great info everyone. I wouldn't personally buy from a site if they didn't have one. Especially when I login to my account. Once you are loged in, it should show https.



I'm about to get the Comodo Elite SSL certificate at $300 a year. Does anyone have experience with it? I'm thinking of getting it because their seal looks really good and they will also offer hacker proof seal and HackerGuardian PCI Scanning free for 1 year.



Please let me know your thoughts. I'm looking for good seals to make the site look as legit and trustworthy as possibly.



Thanks.



D.

[/quote]



On that price you can buy Verisign Secure SSL with Trusted Seal and Malware Scanning. I am using on my website.



If they giving Hacker proof seal with that one, than it is okay otherwise go for verisign.