Convio SSL and greenbar?

Options

I notice that some convio sites get the greenbar SSL on their donation forms, but ours is blue. (Greenbar is encrypted AND extended validation. Meaning that our cert says that it is 'run by (unknown)'.)

Tagged:

Comments

  • Have you paid extra for extended validation?  It generally costs a good bit more.  If you DID pay for it and your certificate was issued, then it's an issue with the certificate issuer and the first place you should start is with them.  Part of the process of getting that certificate is they validate you and your environment to ensure you're up to standards and your server is too...  if the certificate can't work, then they shouldn't have issued it (and taken your money).  Most reputable issuers will work with you, and if you're having errors with your SSL certificate, so will Convio -- file a high priority ticket and/or contact your account rep.

    On the other hand, if you didn't pay for extended validation, then... well.. there's your answer.  Personally, I don't think it's worth the extra expense unless you feel like your organization either A) has a poor reputation for some reason and needs to build confidence or B) doesn't have enough of a reputation for donors to know one way or the other that you're not fraudulent simply by looking at your domain name.  I'd advise you not to worry about the extended validation unless you have the extra money in your budget or your executives are whining about it (I hate when my budget is blown because of some board member's crazy, and unfunded, vision of interactive holograms online or whatever).

  • Michael :

    Have you paid extra for extended validation?  It generally costs a good bit more.  If you DID pay for it and your certificate was issued, then it's an issue with the certificate issuer and the first place you should start is with them.  Part of the process of getting that certificate is they validate you and your environment to ensure you're up to standards and your server is too...  if the certificate can't work, then they shouldn't have issued it (and taken your money).  Most reputable issuers will work with you, and if you're having errors with your SSL certificate, so will Convio -- file a high priority ticket and/or contact your account rep.

    On the other hand, if you didn't pay for extended validation, then... well.. there's your answer.  Personally, I don't think it's worth the extra expense unless you feel like your organization either A) has a poor reputation for some reason and needs to build confidence or B) doesn't have enough of a reputation for donors to know one way or the other that you're not fraudulent simply by looking at your domain name.  I'd advise you not to worry about the extended validation unless you have the extra money in your budget or your executives are whining about it (I hate when my budget is blown because of some board member's crazy, and unfunded, vision of interactive holograms online or whatever).

    Note that an organization only needs to pay for their own SSL certificate if they use a custom secure hostname (as opposed to https://secure2.convio.net/ or https://secure3.convio.net/). It looks like the certificate for secure2 includes Extended Validation, but secure3 does not, and Brian's organization's site is on the secure3 domain. I'm checking with Convio's IT department to see if there's a reason for the difference between the two certificates.

  • Noah Cooper:

    Note that an organization only needs to pay for their own SSL certificate if they use a custom secure hostname (as opposed to https://secure2.convio.net/ or https://secure3.convio.net/). It looks like the certificate for secure2 includes Extended Validation, but secure3 does not, and Brian's organization's site is on the secure3 domain. I'm checking with Convio's IT department to see if there's a reason for the difference between the two certificates.

    Ah, makes sense.  Though for the life of me I can't figure out why anyone wouldn't use their own domain name on their donation forms... I mean, if there is anywhere you want to make sure people don't get confused about what site they're on it's the donation page and, at least in my experience with both GetActive and Convio, using our own hostname was easy enough....

  • Noah Cooper:

    Note that an organization only needs to pay for their own SSL certificate if they use a custom secure hostname (as opposed to https://secure2.convio.net/ or https://secure3.convio.net/). It looks like the certificate for secure2 includes Extended Validation, but secure3 does not, and Brian's organization's site is on the secure3 domain. I'm checking with Convio's IT department to see if there's a reason for the difference between the two certificates.

    Thanks, I thought it was something like that.

  • Michael :

    Ah, makes sense.  Though for the life of me I can't figure out why anyone wouldn't use their own domain name on their donation forms... I mean, if there is anywhere you want to make sure people don't get confused about what site they're on it's the donation page and, at least in my experience with both GetActive and Convio, using our own hostname was easy enough....

    "Though for the life of me I can't figure out why anyone wouldn't use their own domain name on their donation forms..."

    I'm with you there. I'm working on that issue soon! Crack open those wallets, cheapskates!

Categories