|
AlphaSSL Certificates are trusted by all browsers and mobile devices. AlphaSSL also adopts a high security model which means that you need to install a single Intermediate Root Certificate on your web server. Your customers do not need to install anything as AlphaSSL is issued from a highly trusted and widely distributed trusted Root CA certificate. Please select your Webserver from the list below and follow the instructions.
Download the Root Certificates here (Right Click Save-as):
crt DER Format | .pem Format | .txt Format - this root CA certificate does not need need to be installed on your webserver
Copy and Paste ALL characters within the below box (including the
-----BEGIN CERTIFICATE----- and
-----END CERTIFICATE-----) into a text editor and Save to your server as per your Server installation instructions.
What are Intermediate Root CA certificates?
All customers installing an AlphaSSL Certificate will need to install the Alpha CA Intermediate root CA onto their web servers. The installation needs to only be conducted once. Once installed, all browsers, applications and mobiles will trust AlphaSSL Certificates transparently. The Intermediate root CA certificate needs only be installed on the web server and does NOT need to be installed by visitors to your web site.
Why does AlphaSSL use an Intermediate root CA certificate?
AlphaSSL has always adopted a high security model when issuing digital certificates. We use a trust chain that ensures that the primary root CA used to create the Alpha CA Intermediate Root CA (i.e. the GlobalSign Root CA certificate that is pre-installed with all browsers, applications and mobiles) is “offline” and kept in a highly secure environment with stringently limited access. This means the root CA is not used to directly sign end entity SSL Certificates, as such AlphaSSL employs a best practices approach for it Public Key Infrastructure therefore protecting against the major effects of a “key compromise”. For example, a key compromise of the primary Root CA would render the root and all certificates issued by the root untrustworthy, and because we keep our root offline this (somewhat unlikely event) is significantly less likely to happen.
The use of Intermediate root CAs is utilized by all major Certification Authorities because of the extra security level they provide.
|