Rule n° 198 - Security certificates are signed and currently valid

The encounter of a site whose certificate is invalid or out of date causes alerts on the Internet user's computer. In a certain number of cases, these alerts will lead the user to leave the site immediately.

#Basics #Development #Security

Goal

  • Allow users to check the certificate’s validity and to contribute to transactional security.

Solution technique

Strictly monitor the security certificates used on the website, and anticipate renewal dates.

Moyen de contrôle

Check the validity of the certificate using an online tool, or using the tools provided by browsers

Most browsers also display an alert when they encounter an invalid certificate.