Domain Validated & Wildcard SSL Setup Guide

The setup of domain validated and wildcard SSL certificates can be completed by following the steps outlined below. You can view details on the SSL certificates available with LCN and order an SSL certificate on the following page: Step 1 - Setting up your SSL Certificate To start the process to setup your SSL certificate, go to the 'SSL' section of your LCN account. Select the setup link alongside the unallocated SSL certificate. You will then need to enter a domain name to assign to the SSL certificate, the certificate will apply to both the 'www' and non 'www' version of the domain. If you enter a sub-domain (e.g. the certificate will be applied to the sub-domain only. For Wildcard SSL certificates - enter the bare domain for the certificate to apply for any sub-domain of the domain. The next step is to select an email address to validate the certificate. You will need to make sure that the selected email address exists before proceeding - if your domain is hosted with LCN you can go to the Email Addresses section of your account to add the address. To complete the setup process, select and confirm the contact for the SSL certificate - and select Register Certificate Step 2 - Validating and Enabling SSL certificate After completing the setup of the certificate within your account, you should receive an email to the selected address, to validate the SSL certificate application. Select the I Approve link within the email, to validate the certificate application. Step 3 - Enabling or Downloading SSL Certificate Once your SSL certificate has been validated - you can enable the SSL certificate if your site is hosted with LCN, or download the certificate by going to the 'SSL' section of your LCN account and selecting to manage the certificate. If your site is hosted with LCN - select enable to activate the SSL certificate on your hosting, otherwise if the certificate needs to be installed to a different server, select download to download a zip file containing the certificate components.

Extended Validation SSL Setup Guide

Extended Validation (EV) SSL Certificates require the most thorough authentication process in order to be sure that any company certified is a legitimate operation. The validation process is handled by our SSL supplier “GeoTrust”. Extended Validation Authentication in three simple steps: Once you have purchased your SSL EV, please keep an eye on your e-mails for further information and requests for documents. To continue to step 2, you’ll need your GeoTrust order number. To begin the validation process you’ll first need to download, complete, sign, and return the Acknowledgement of Agreement Form (PDF linked to below). EV Validation Requirements - Acknowledgement Agreement The signed Acknowledgement Agreement must be submitted to GeoTrust at: Email (sign and scan): Fax: 1-650-237-8871 GeoTrust cannot proceed with your SSL Certificate request until receipt of the signed Acknowledgement of Agreement form is received. Following receipt of the Acknowledgement of Agreement Form, the authentication process on your organisation can begin. The authentication of your organisation is broken down into four parts: Organisation requirements Domain requirements Certificate requester requirements Order verification requirements Below is an explanation of each. Organisation Authentication Requirements The following business entities can receive EV Certificates provided they are currently registered with and approved by an official registration agency in their jurisdiction. The resulting charter, certificate, license or equivalent must be verifiable through that registration agency. Government agencies Corporations General partnerships Unincorporated associations Sole Traders or Sole Proprietorships GeoTrust must be able to confirm all of the following organisational registration requirements: The registration number, date of registration/incorporation and registered address (or the address of the organisation’s registered agent) must be authenticated and approved. In the event that the place of business address is not shown within Government records, a Non-government data source (such as Dun & Bradstreet) must include your organisation’s place of business address. If the organisation has been registered for less than three years, GeoTrust will verify the operational existence of your organisation through one of the following means. Through a non-government data source (such as Dun & Bradstreet). By verifying the organisation has an active deposit account (such as a banking current account) with a regulated financial institution through a Lawyer’s Opinion Letter or directly with the financial institution. Domain Authentication Requirements To qualify for an Extended Validation SSL Certificate, the registration details for the domain you wish to secure must reflect the full name of the organisation as shown in the SSL Certificate request. Where domain registration does not reflect the organisation’s name as identified in the SSL Certificate request, positive confirmation of the organisation’s exclusive right to use the domain name is required from the registered domain administrator or with a professional opinion letter. Domain registration details must be updated to reflect the organisation / business name as included on the SSL Certificate request. This can be done via your account in most cases. Where domain privacy is in place, will temporarily halt the privacy feature to reveal the registered information directly from your domain name details. ** At no extra cost, can allow this to occur temporarily whilst your domain details are assessed by GeoTrust. The organisation’s "Certificate Requester” must confirm knowledge of the organisation’s domain ownership during the verification call. Organisation’s Certificate Requester Authentication Requirements The person identified in the in the certificate request (Certificate Requester) must be employed by the requesting organisation and have authority to obtain and delegate EV Certificate responsibilities. Note: Employment and authorisation cannot be verified through the organisation’s web site. If the Certificate Requester identified in the certificate request is listed in government records as a corporate officer (such as Secretary, President, CEO, CFO, COO, CIO, CSO, Director, or equivalent), then organisational contact employment and authorisation can be approved without verifying this information as described below. GeoTrust must be able to confirm the following Certificate Requesters information: Certificate Requester’s identity, title & employment via an independent source. That the Certificate Requester is authorised to obtain and approve EV Certificates on behalf of the organisation. This can be verified through one of the following: A Lawyer’s opinion letter. A Corporate Resolution. Directly contacting an executive of the organisation and confirming the authority of the organisational contact. Order Verification Requirements GeoTrust must verify the certificate request and all certificate details with the Certificate Requester identified in the certificate request. GeoTrust will contact the Certificate Requester using an independently-verified telephone number. This telephone number is obtained through one of the following methods: By researching qualified telephone databases to find a telephone number. Ensure your organisation’s primary telephone number is listed in a public telephone directory. As provided in a Lawyer's Opinion Letter. As confirmed during a site visit conducted by GeoTrust During the verification call, GeoTrust will verify the following with the Certificate Requester: The name of the Certificate Requestor identified in the certificate request and his or her authority to obtain the Extended Validation certificate on behalf of the organisation. Knowledge of the company's ownership and right to use the domain identified in the certificate request. Approval of the Extended Validation SSL Certificate request. Acknowledgement of signature of GeoTrust SSL Certificate Subscriber Agreement that includes all Extended Validation terms and conditions. If GeoTrust is unable to verify any of the required information on your certificate application, they may request you to provide a Professional opinion from a lawyer or accountant to verify the information GeoTrust's Validation Requirements: SSL Certificate Subscriber Agreement:

How to enable HTTPS for your website

If you have added and enabled an SSL certificate for your domain, you will need to configure your site, or pages within your site to use HTTPS URLs. HTTPS URLs begin with https:// - this prefix to the URL indicates that the connection to the web server is secured and encrypted with SSL. Once you have added and enabled an SSL certificate for your website - you will then need to configure your site or the required pages within your site to use HTTPS. Please note that these instructions will not apply for sites running Wordpress or other content management systems - contact the LCN support team if you need further assistance with enabling HTTPS for your site. Enabling HTTPS using .htaccess You can configure your site to use HTTPS by using a .htaccess file - see the following page for further information on .htaccess: What is a .htaccess file? Enabling HTTPS for all pages within your site To configure your site to use HTTPS for all pages, create a file using a text editor such as Notepad and save the file as: .htaccess (without any additional file extension). Enter the following lines of text within the file: RewriteEngine On RewriteCond %{HTTPS} !=on RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301] Save the file and then upload it to the 'web' folder for your site - see the following page for instructions on uploading the file to your website: How to upload files to your website with FTP Enabling HTTPS for a specific folder within your site If you want to enable HTTPS for a specific folder within your site, use the following text within the .htaccess file and change the URL within the 'RewriteRule' line to set your domain and folder name: RewriteEngine On RewriteCond %{SERVER_PORT} 80 RewriteCond %{REQUEST_URI} folder RewriteRule ^(.*)$$1 [R,L] Save the file, then upload it to the specified folder - rather than placing the file into the 'web' directory for your site.

How to set up SSL on your WordPress website

This guide will explain how to set up SSL on your WordPress website for customers using web hosting and WordPress hosting . Before you start, you'll need to have purchased and set up an SSL certificate. You can learn how to do this here . Let's get started… Login to your WordPress dashboard. You can do this by navigating to Hover over Plugins on the left hand side and click Add New Use the search bar in the top right hand side to find Really Simple SSL Click Install Now Once installed you'll need to turn the plugin on. Do this by clicking Activate Plugin To enable SSL click Go ahead, activate SSL! That's it! SSL should now be enabled for your WordPress website. You can test this by browsing to the green SSL padlock should be visible next to your URL bar. Your browser does not support the video tag.

