Changes

Jump to navigation Jump to search
Line 5: Line 5:  
While there are many technical details within the report that are not captured in this brief summary, the most important recommendations are:
 
While there are many technical details within the report that are not captured in this brief summary, the most important recommendations are:
 
* Domain Validated (DV) server certificates are recommended for use by GC public facing websites. While the use of Organization Validated (OV) and Extended Validation (EV) certificates is not precluded, DV certificates are preferred due to their lower cost, the ability to support automated certificate issuance, and the fact that DV certificates provide the same level of security between the web browser and web server as OV and EV certificates.   
 
* Domain Validated (DV) server certificates are recommended for use by GC public facing websites. While the use of Organization Validated (OV) and Extended Validation (EV) certificates is not precluded, DV certificates are preferred due to their lower cost, the ability to support automated certificate issuance, and the fact that DV certificates provide the same level of security between the web browser and web server as OV and EV certificates.   
* The '''use of the free service provided by Let’s Encrypt is recommended''' for obtaining DV certificates combined with the use of [[https://letsencrypt.org/docs/client-options/ compatible certificate management agents]] (e.g.: https://digital.canada.ca/).  If used, OV and '''EV certificates should be obtained from SSC''' (contact [mailto:ssc.ssltls.spc@canada.ca ssc.ssltls.spc@canada.ca]) in order to take advantage of the reduced pricing from an approved CA vendor.
+
* The '''use of the free service provided by Let’s Encrypt is recommended''' for obtaining DV certificates combined with the use of [https://letsencrypt.org/docs/client-options/ compatible certificate management agents] (e.g.: https://digital.canada.ca/).  If used, OV and '''EV certificates should be obtained from SSC''' (contact [mailto:ssc.ssltls.spc@canada.ca ssc.ssltls.spc@canada.ca]) in order to take advantage of the reduced pricing from an approved CA vendor.
    
[[File:Le-logo-twitter.png|250px|link=https://letsencrypt.org/]] [[file:entrust_site_seal_ssl.png|200px|link=mailto:ssc.ssltls.spc@canada.ca]]
 
[[File:Le-logo-twitter.png|250px|link=https://letsencrypt.org/]] [[file:entrust_site_seal_ssl.png|200px|link=mailto:ssc.ssltls.spc@canada.ca]]
263

edits

Navigation menu

GCwiki