SSL - 如何以及何时使用它 [英] SSL - How and when to use it

查看:42
本文介绍了SSL - 如何以及何时使用它的处理方法,对大家解决问题具有一定的参考价值,需要的朋友们下面随着小编来一起学习吧!

问题描述

我有一个客户需要 SSL 来保护在线捐赠,但我对如何/何时使用 SSL 的经验有限.

I have a client that needs SSL to protect online donations, but I have limited experience with how/when to use SSL.

我知道在购买证书时,我将该证书分配给整个域(实际上是 IP 地址).有没有办法将加密隔离到网站的一个页面,或者我应该继续保护整个网站,即使只有一个页面需要它?

I understand that in purchasing a certificate that I am assigning that certificate to an entire domain (IP address really). Is there a way to isolate the encryption to only a single page of the website, or should I just go ahead and secure the entire site even though only one page needs it?

不确定此处的最佳做法.请指教.

Unsure of best practice here. Please advise.

推荐答案

SSL 会产生相当多的额外处理时间.对于低带宽站点,SSL 所需的额外处理并不是很明显.但对于 Facebook、Twitter 和 Flickr 等流量大的网站来说,SSL 带来的负载非常大,以至于他们不得不使用专用的 SSL 编码/解码硬件.

SSL incurs quite a bit of extra processing time. For low bandwidth sites, the extra processing required by SSL is not really noticeable. But for sites with heavy traffic like Facebook, Twitter and Flickr, the load caused by SSL is heavy enough that they would have to use dedicated SSL encoding/decoding hardware.

所以基本上是的,尽量减少使用 SSL 的页面数量是有意义的.这就是为什么您经常看到银行网站仅通过 https 保护实际帐户页面的原因.主页/登陆页面通常是普通的旧 http.

So basically yes, it makes sense to minimize the number of pages using SSL. That is why you often see banking sites only protect the actual account pages via https. The home/landing page is usually plain old http.

另一方面,除非你真的是像 Twitter、Facebook 或 Gmail 这样的网站,否则担心这有点过早优化.如果可以的话,先做简单的.请注意此问题,并在您的网站最终获得大量流量时注意升级策略.

On the other hand, unless you really are a site like Twitter or Facebook or Gmail, worrying about this is a bit of a premature optimization. First do it simple if you can. Be aware of this issue and be aware of upgrade strategies when your site finally get heavy traffic.

我的老板有句话:

这是一个快乐的问题.首先解决sad问题没有足够的用户,那么你会高兴遇到一个问题需要您重构您的架构.

This is a happy problem to have. First solve the sad problem of not having enough users then you'd be happy to have a problem that requires you to refactor your architecture.

这篇关于SSL - 如何以及何时使用它的文章就介绍到这了,希望我们推荐的答案对大家有所帮助,也希望大家多多支持IT屋!

查看全文
登录 关闭
扫码关注1秒登录
发送“验证码”获取 | 15天全站免登陆