# How much is your SSL costing you?

**URL:** <https://forums.realmacsoftware.com/t/how-much-is-your-ssl-costing-you/20346>\
**Category:** RapidWeaver Classic\
**Created:** [May 24, 2018, 12:16pm UTC](https://forums.realmacsoftware.com/t/how-much-is-your-ssl-costing-you/20346 "2018-05-24T12:16:50Z")\
**Posts on this page:** 20\
**Page:** 2

<div class="post-metadata">

**Author:** ![Gabrielle](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/gabrielle/32/183_2.png) [@Gabrielle](https://forums.realmacsoftware.com/u/Gabrielle)\
**Post date:** [May 30, 2018, 11:35am UTC](https://forums.realmacsoftware.com/t/how-much-is-your-ssl-costing-you/20346/21 "2018-05-30T11:35:10Z")

</div>

I’m still not sure that I understand SSL in the right way. People THINK that an https site is secure so that they can trust it right? But that’s not entirely true. Scammers are simply making new sites and adding a free SSL to it which makes it look more authentic, but it’s still a scammers site. So people are MORE likely to click through to a scamming site then they might have been before. I attach a screen grab to show you what I mean.

So yes adding SSL to your site means that people can more safely add their sensitive information. But it’s also now a great new way for scammers to hook more people into their own dodgy sites, that’s right isn’t it?! SCREEN GRAB BELOW

 ![SCAM](https://europe1.discourse-cdn.com/flex005/uploads/realmacsoftware1/original/2X/a/a5170eea887d2e14c9b361251d5577984cda42e5.jpg)

---

<div class="post-metadata">

**Author:** ![NeilUK](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/neiluk/32/23434_2.png) [@NeilUK](https://forums.realmacsoftware.com/u/NeilUK)\
**Post date:** [May 30, 2018, 11:50am UTC](https://forums.realmacsoftware.com/t/how-much-is-your-ssl-costing-you/20346/22 "2018-05-30T11:50:18Z")

</div>

You can tell by the link it’s not genuine. It’s a common trick to use the name of the company in a longer url.

Barclays would use their root domain, [That page can't be found](http://barclays.co.uk/downloads), or something similar.

Barclays have an EV Cert (Extended Validation), which means the company has gone through extensive checks to make sure it’s legit. All banks should have this.

Also, Barclays URL is .co.uk.

![34](https://europe1.discourse-cdn.com/flex005/uploads/realmacsoftware1/original/2X/2/2d7782f35fe0ad865fc57cf97c6d6a9dfa12bec5.png)

---

<div class="post-metadata">

**Author:** ![yabdab](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/yabdab/32/26154_2.png) [@yabdab](https://forums.realmacsoftware.com/u/yabdab)\
**Post date:** [May 30, 2018, 12:29pm UTC](https://forums.realmacsoftware.com/t/how-much-is-your-ssl-costing-you/20346/23 "2018-05-30T12:29:31Z")

</div>

Macdock offers it for free via Plesk ONYX and Lets Encrypt.

Cartloom will offer it as well very soon. Use Storefront with your own domain and free ssl 😉

---

<div class="post-metadata">

**Author:** ![teefers](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/teefers/32/8173_2.png) [@teefers](https://forums.realmacsoftware.com/u/teefers)\
**Post date:** [May 30, 2018, 1:18pm UTC](https://forums.realmacsoftware.com/t/how-much-is-your-ssl-costing-you/20346/24 "2018-05-30T13:18:25Z")

</div>

> [@Gabrielle](#):
>
> Scammers are simply making new sites and adding a free SSL

Scammers have been using paid certificates for years, a few bucks isn’t going to get in the way. The HTTPS only ensures that the data being transmitted is encrypted, not that the company is legitimate. This is to ensure that no one is intercepting the data between the users and the server.

So even a paid certificate wouldn’t help ensure you’re not getting scammed.  
There’s no easy way for an end user to determine the certificate type issued.

---

<div class="post-metadata">

**Author:** ![willwood](https://avatars.discourse-cdn.com/v4/letter/w/bc8723/32.png) [@willwood](https://forums.realmacsoftware.com/u/willwood)\
**Post date:** [May 30, 2018, 2:11pm UTC](https://forums.realmacsoftware.com/t/how-much-is-your-ssl-costing-you/20346/25 "2018-05-30T14:11:33Z")

</div>

Following on from what @NeilUK and @teefers have correctly said, better banks NEVER put web links, email addresses or phone numbers in emails. If a bank needs a user to action something, they normally tell them to manually go to the website and login. Quite a lot of other businesses do the same.

I’m sorry, but I lack sympathy for people who are gullible enough to fall for these simple scams. Not really any excuse for it and you certainly cannot levy the blame on SSL. It sounds like this individual needs to enroll onto a safe computing course or be under tighter supervision when they use their computer!

SSL is still vitally important for maintaining a safer transfer of personal data between the client and web server. For this reason, SSL becomes mandatory in Chrome next month: [https://www.geocerts.com/blog/google-chrome-to-mark-all-non-ssl-sites-as-not-secure-in-june-2018](https://www.geocerts.com/blog/google-chrome-to-mark-all-non-ssl-sites-as-not-secure-in-june-2018)

Firefox has just introduced something similar in the nightly builds too. So expect this to become mainstream soon. Safari and others are probably not far behind.

In answer to the original question, most of my public-facing sites are with @barchard Chillidog hosting, so are covered by the free SSL certificates Greg has been providing for a few years now.

For the reason stated above (with SSL becoming mandatory), I am of the opinion that any hosting company trying to charge users for SSL are not playing fair and blatantly out to just profiteer. Such companies should be boycotted - if we haven’t boycotted them already for their [elephant killing antics](http://gawker.com/5787676/meet-godaddys-ridiculous-elephant-killing-ceo)! 😠

The only reason to pay for an SSL certificate is if you need a special type of certificate or extra warranty / guarantee. Most average websites don’t. Even if you are selling stuff, often the final transaction is processed through a payment vendor (e.g. PayPal or Stripe) who have these more complex certificates and obviously have to maintain PCI compliance and suchlike.

---

<div class="post-metadata">

**Author:** ![peterdanckwerts](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/peterdanckwerts/32/22443_2.png) [@peterdanckwerts](https://forums.realmacsoftware.com/u/peterdanckwerts)\
**Post date:** [May 30, 2018, 5:52pm UTC](https://forums.realmacsoftware.com/t/how-much-is-your-ssl-costing-you/20346/26 "2018-05-30T17:52:44Z")

</div>

![Inbox%20(16%2C599%20messages%2C%201%20unread%20-%20Connection%20Logging%20Enabled)%202018-05-30%2011-38-14](https://europe1.discourse-cdn.com/flex005/uploads/realmacsoftware1/original/2X/b/b546fa80f8578aa3e13ecc115211517d3ec70094.jpg)

This is superficially plausible but Companies House and HMRC would tell you to log in on line to see documents, never attach a file. And, of course, they’d never tell you to click a link.

---

<div class="post-metadata">

**Author:** ![Bentley](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/bentley/32/7402_2.png) [@Bentley](https://forums.realmacsoftware.com/u/Bentley)\
**Post date:** [May 30, 2018, 6:55pm UTC](https://forums.realmacsoftware.com/t/how-much-is-your-ssl-costing-you/20346/27 "2018-05-30T18:55:19Z")

</div>

Two things are making me procrastinate as I change a website for the new EU requirements.  
One is changing all my pages to php to get Gateway etc to work and the other not strictly related but something I want to do when I am making changes and that is SSL.  
I want publishing to be a simple as possible and I can’t afford to change hosting as it has all just been paid for, for another year and I don’t really want to use Transmit to publish, though I might have to. In other words I would prefer to just publish straight from Rapidweaver.  
My host is LittleOak and I have been lazy about that but they have just been paid for the next year.  
I understand if I change my pages to php although they will upload they will not remove the html files, will sit there and the only thing that will be provided are the html pages.  
What is the easiest and least hassle way of removing the html files and republish the php files?  
As for SSL, the information on Littleoak is that you select your Certificate provider, tell Littleoak who the provider is, then give the information to the provider and then give Littleoak the certificate.  
Can you recommend a provider of the certificate and has anyone done this process with Littleoak who could clarify the process with Littleoak?  
Best wishes,  
Bentley

---

<div class="post-metadata">

**Author:** ![swilliam](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/swilliam/32/14799_2.png) [@swilliam](https://forums.realmacsoftware.com/u/swilliam)\
**Post date:** [May 30, 2018, 7:25pm UTC](https://forums.realmacsoftware.com/t/how-much-is-your-ssl-costing-you/20346/28 "2018-05-30T19:25:35Z")

</div>

You can remove all the html pages with either an ftp program like transmit or with the file manager in your Cpanel.

To change pages to php, just change the filename in the RW page UI

---

<div class="post-metadata">

**Author:** ![Gabrielle](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/gabrielle/32/183_2.png) [@Gabrielle](https://forums.realmacsoftware.com/u/Gabrielle)\
**Post date:** [May 31, 2018, 10:25am UTC](https://forums.realmacsoftware.com/t/how-much-is-your-ssl-costing-you/20346/29 "2018-05-31T10:25:15Z")

</div>

Thanks everyone, your comments are appreciated :-).

---

<div class="post-metadata">

**Author:** ![bradf1405](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/bradf1405/32/9037_2.png) [@bradf1405](https://forums.realmacsoftware.com/u/bradf1405)\
**Post date:** [June 15, 2018, 8:56am UTC](https://forums.realmacsoftware.com/t/how-much-is-your-ssl-costing-you/20346/30 "2018-06-15T08:56:40Z")

</div>

**Simple Secure Socket Layer (SSL)/TLS Encryption | Cloudflare**  
Our SSL certificates encrypts communication for secure communications. Our Basic Universal SSL/TLS is **free** , this will increase your sites security, trust. goto [https://www.cloudflare.com/ssl/](https://www.cloudflare.com/ssl/)

---

<div class="post-metadata">

**Author:** ![Gabrielle](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/gabrielle/32/183_2.png) [@Gabrielle](https://forums.realmacsoftware.com/u/Gabrielle)\
**Post date:** [June 15, 2018, 9:42am UTC](https://forums.realmacsoftware.com/t/how-much-is-your-ssl-costing-you/20346/31 "2018-06-15T09:42:50Z")

</div>

I started the process with Cloudflare but then got a bit scared. we need to go back to the domain hosting panel and change the DNS records right? It’s as simple as that? I haven’t taken that next step yet.

---

<div class="post-metadata">

**Author:** ![bradf1405](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/bradf1405/32/9037_2.png) [@bradf1405](https://forums.realmacsoftware.com/u/bradf1405)\
**Post date:** [June 16, 2018, 1:51am UTC](https://forums.realmacsoftware.com/t/how-much-is-your-ssl-costing-you/20346/32 "2018-06-16T01:51:49Z")

</div>

Yes, that’s right. It’s not very complicated. Just follow their instructions.  
As well as FREE SSL, you get a free SPEED boost, protection against a DOS attack etc… I have used Cloudflare on over 50+ of my domains and I never had any problems!

---

<div class="post-metadata">

**Author:** ![Gabrielle](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/gabrielle/32/183_2.png) [@Gabrielle](https://forums.realmacsoftware.com/u/Gabrielle)\
**Post date:** [June 16, 2018, 4:31pm UTC](https://forums.realmacsoftware.com/t/how-much-is-your-ssl-costing-you/20346/33 "2018-06-16T16:31:37Z")

</div>

Ah brilliant I can now see the padlock if I type in https… thanks so much 🙂  
However on my old bookmarks the old site still shows up ie www…

Can you remind me how I get old bookmarks to show the https automatically, or does it not work that way?

---

<div class="post-metadata">

**Author:** ![teefers](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/teefers/32/8173_2.png) [@teefers](https://forums.realmacsoftware.com/u/teefers)\
**Post date:** [June 16, 2018, 4:53pm UTC](https://forums.realmacsoftware.com/t/how-much-is-your-ssl-costing-you/20346/34 "2018-06-16T16:53:15Z")

</div>

if You’re using CloudFlare there are page rules that you use to redirect http to https.

[https://support.cloudflare.com/hc/en-us/articles/200170536-How-do-I-redirect-all-visitors-to-HTTPS-SSL-](https://support.cloudflare.com/hc/en-us/articles/200170536-How-do-I-redirect-all-visitors-to-HTTPS-SSL-)

---

<div class="post-metadata">

**Author:** ![Gabrielle](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/gabrielle/32/183_2.png) [@Gabrielle](https://forums.realmacsoftware.com/u/Gabrielle)\
**Post date:** [June 16, 2018, 7:46pm UTC](https://forums.realmacsoftware.com/t/how-much-is-your-ssl-costing-you/20346/35 "2018-06-16T19:46:24Z")

</div>

Ah ok I’ll check it out thank you. Also I notice that when I do a check on the site using www.whynopadlock, I can see a whole list of domains (see attached). Is that because it’s a free service and is therefore being shared alongside lots of other peoples domains?

 ![cloudflare](https://europe1.discourse-cdn.com/flex005/uploads/realmacsoftware1/original/2X/3/3aca99666e7191348020764b85a806a543253a3e.jpg)

---

<div class="post-metadata">

**Author:** ![NeilUK](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/neiluk/32/23434_2.png) [@NeilUK](https://forums.realmacsoftware.com/u/NeilUK)\
**Post date:** [June 16, 2018, 7:57pm UTC](https://forums.realmacsoftware.com/t/how-much-is-your-ssl-costing-you/20346/36 "2018-06-16T19:57:45Z")

</div>

Shared SSL certs are like shared hosting. Crap!

---

<div class="post-metadata">

**Author:** ![Gabrielle](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/gabrielle/32/183_2.png) [@Gabrielle](https://forums.realmacsoftware.com/u/Gabrielle)\
**Post date:** [June 16, 2018, 8:39pm UTC](https://forums.realmacsoftware.com/t/how-much-is-your-ssl-costing-you/20346/37 "2018-06-16T20:39:35Z")

</div>

Why do you think it’s crap NeilUK?

---

<div class="post-metadata">

**Author:** ![NeilUK](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/neiluk/32/23434_2.png) [@NeilUK](https://forums.realmacsoftware.com/u/NeilUK)\
**Post date:** [June 16, 2018, 8:48pm UTC](https://forums.realmacsoftware.com/t/how-much-is-your-ssl-costing-you/20346/38 "2018-06-16T20:48:31Z")

</div>

Just because you can be sharing space with some dodgy websites. Although, I think the consequences are minimal these days.

Shared hosting is usually very limited, and I’d never trust my own or client sites on a shared hosting account. I’d rather pay a little more for peace of mind.

Also, many people swear by Cloudflare, but I’ve never rated their free service. I tried it once; it added 2 seconds to the site’s loading time.

However, people’s experiences are different, and if Cloudflare’s working for you, no reason not to use it.

---

<div class="post-metadata">

**Author:** ![Gabrielle](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/gabrielle/32/183_2.png) [@Gabrielle](https://forums.realmacsoftware.com/u/Gabrielle)\
**Post date:** [June 17, 2018, 10:08am UTC](https://forums.realmacsoftware.com/t/how-much-is-your-ssl-costing-you/20346/39 "2018-06-17T10:08:58Z")

</div>

Sorry I should have been a bit clearer with my question. I understand about shared hosting, but sharing the SSL feature isn’t the same as sharing your hosting is it? I know that @joeworkman has recommended Cloudflare on his podcast so that’s why I’ve gone that route. Also it means I’m saving my client £80+ annually by bypassing their hosters SSL service. Does anyone else have less than positive views about Cloudflare?

---

<div class="post-metadata">

**Author:** ![NeilUK](https://dub1.discourse-cdn.com/flex005/user_avatar/forums.realmacsoftware.com/neiluk/32/23434_2.png) [@NeilUK](https://forums.realmacsoftware.com/u/NeilUK)\
**Post date:** [June 17, 2018, 10:45am UTC](https://forums.realmacsoftware.com/t/how-much-is-your-ssl-costing-you/20346/40 "2018-06-17T10:45:58Z")

</div>

As long as your domain name is on the SSL cert, it’s fine. Issues arise when using a shared SSL that doesn’t specify your domain name.

Personally, I just prefer to have a unique SSL per domain. Good hosting companies offer free Let’s Encrypt SSL certs so there’s no need to be paying £80+.

[Previous page](https://forums.realmacsoftware.com/t/how-much-is-your-ssl-costing-you/20346.md?page=1)

[Next page](https://forums.realmacsoftware.com/t/how-much-is-your-ssl-costing-you/20346.md?page=3)
