HoloWWW - Secure Transactions - NEW

HoloWWW can provide secure transactions utlizing SSL. SSL is the industry standard protocol for secure transactions. These transaction are secure in the sense that it is is difficult for someone other than the receiver and sender to read your encrypted transactions.

HoloNet does not guarantee security, but provides service utilizing the industry standard tools for security.


Security Info


Rates

There is an annual setup fee of $50 per site. Regular HoloWWW rates apply for access. Additionally, sites will need a Digital ID from VeriSign. ? VeriSign rates are available on their Digital ID Pricing page in the section titled "Secure Web Server Digital ID Pricing".

HoloNet generates 512-bit keys. HoloNet retains the private key and will destroy it, but not surrender it, upon request.


Obtaining A Digital ID

The procedure for obtaining a Digital ID for our C2Net (Apache-SSL-US) Servers is as follows:


Secure Pages

Secure pages are served significantly slower than unsecure pags. For this reason, we recommend only critical pages, such as credit card capture pages be secure.

If the customer has a browser which supports Secure Socket Layer (SSL) transactions, such as Netscape, they can transfer pages securely between their browser and the HoloWWW server.

If the page contains any inline images, these images will need to also be transfered securely or the Netscape client will display them as a broken image.

To allow HoloWWW to tell which pages are to use SSL, all secure pages are placed in different directory from the normal "http". The new directory for secure pages is created called "https".

Because you may have many elements that you may want to share between your secure "https" site and your regular "http" site, a shared directory is also created. The shared directory is installed in the "http directory. It is available via the URLs "https://www.sitename.holowww.com/shared" and "http://www.sitename.holowww.com/shared".

Secure URLs

Secure pages are accessed via a URL similar to "https://www.sitename.holowww.com".

The root of securely served pages is the "https" directory.

Summary of Directories

http
This directory is for all unsecure pages and graphics.

For unsecure access, use the URL "http://www.yoursite.holowww.com/file".

https
This directory is for all secure pages and graphics.

For secured access, use the URL "https://www.yoursite.holowww.com/file".

http/shared
This directory is for pages that can be accessed either securely or unsecurely.

For unsecure access, use the URL "http://www.yoursite.holowww.com/shared/file".

For secured access, use the URL "https://www.yoursite.holowww.com/shared/file".

In a page, to access another files, the same way as the page was accessed, just use a URL of "/shared/file".

Caveats

HoloWWW Access Control (passwords) is not available. Passwords must be implmented Apache style. Please use DBM style passwords if you have more than a few passwords. HoloWWW expects ".htaccess" files to be named "www_htaccess".

Only the transfer of information between the browser and the server is secure.


Secure E-Mail

PGP (Pretty Good Privacy) can be used to encrypt e-mail sent from HoloWWW Web sites. PGP is installed and available for use with CGI Anywhere.

PGP is available from for non-commercial use from the MIT distribution site for PGP and commercially from ViaCrypt.


Why Security?

Most Webmasters will want secure service to implement an online store or to deliver and receive sensitive data between the HoloWWW Server and their Web users.

The components in an online store are:

Customers who shop online may feel more comfortable if it is difficult for unauthorized people to view their transactions. This is especially true if their credit card number is at risk. However, most, if not all, credit card providers will not force a card holder to pay for things they did not order.


Legal Notices