all things wordpress - the how, what and why of ssls

40
The how, what and why of SSLs #ATWP

Upload: mickey-mellen

Post on 12-Apr-2017

125 views

Category:

Technology


1 download

TRANSCRIPT

The how, what and why of SSLs

#ATWP

AllThingsWordPress.com

Facebook Group LinkedIn Group Google+ Community

Join us on Slack

AllThingsWordPress.com/slackto request to join

Thursday, February 23Between two WordCamps

All Things WordPress

Thursday, March 2Grow Your Business, Pick Up Work

All Things WordPress

Tuesday, March 14TBD

All Things WordPress

March 18-192017.atlanta.wordcamp.org

WordCamp Atlanta 2017

Thank You to Our Sponsor

ClickHOST now offers Managed WordPress hosting on AWS:

- Super fast and reliable, Backups & Monitoring

- Built on Amazon Web Services

- Unlimited data transfer, 10GB SSD disk space

- Starting at $49/month

20% off monthly or annual plans with code:

CH-ATWP20

www.clickhost.com

facebook.com/TomAndCheeKennesaw

1200 Barrett Parkway

The how, what andwhy of SSLs

WHY DO I NEED SSL AND HTTPS

FOR MY WEBSITE?

Carel Bekker: President/Owner

Copyright & trademark ClickHOST.com 18

What is SSL & HTTPS?•SSL: Secure Sockets Layer

•HTTPS: HTTP (Hypertext Transfer Protocol) Secure

•Secure way to communicate between your computer and a

website.

• For example: https://amazon.com — all communication between

your PC and Amazon is encrypted. Happy Shopping!

Copyright & trademark ClickHOST.com

Why SSL?• Security, Peace of mind, Trust

• Giving your customers confidence in your website

• Especially for e-commerce sites

• SEO

• Google is now highlighting it!

Is SSL active?• How do I know SSL is active for a website?

• Check in the browser search bar.

• Green padlock, “Secure” in Chrome

• Green Padlock in Firefox

• Grey Padlock in Safari

• Click on the Padlock to view the SSL

How does it work?• SSL Certificates from ClickHOST, Comodo, Digicert.com, etc.

• Verify your identify at the CA (Cert Authority), w DV, OV & EV.

• DV - Domain Validation, OV - Organization Validation, EV -

Extended Validation

• Install the SSL

• This encrypts the traffic & authenticates the website

Validation● Domain Validation (DV):

○ Typically using a text file, or email sent to admin.

○ Inexpensive & Easy installation

● Organization Validation (OV):

○ Validation using DUNS, Government DB.

○ More secure & expensive

● Extended Validation:

○ Same as OV, but includes green organization name bar.

What is the deal with FREE SSLs?• Let’s Encrypt, Cloudflare, Comodo

• Provided by Hosting Provider, e.g., ClickHOST

• SSL is free and encrypts traffic, however

• Website owner is not verified — “securely downloading

malware” �

Miscellaneous

• Wildcard SSL

• www. and/or non-www.

• Mixed content: https://www.whynopadlock.com/

• Test SSL: digicert.com/help, OR ssllabs.com/ssltest

ClickHOST Services• Free SSL via Let’s Encrypt & Cloudflare

• Paid SSLs includes Authentication & Installation

• Standard SSL: $119/year

• Wildcard SSL: $199/year (*.example.com)

• Fix Mixed content service: $85

26

Adding SSL to your WordPress site

http://yoursite.comhttps://yoursite.com

Should both work (to some degree).

Get it activated through your host

[Settings] → [General]

Change your WordPress Settings URL

siteurl in phpMyAdmin

wordpress.org/plugins/really-simple-ssl

Install the “Really Simple SSL” plugin

Update your Google Analytics URL

Update your Google Search Console URL

If necessary...

Update URLs in functions.php and style.css

Update Genesis Simple Hooks (or similar)

Run the “Velvet Blues Update URLs” plugin

Update ManageWP (or similar) URLs

Update other embedded scripts, such as Wufoo

Questions?

Thank You to Our Sponsor