Skip to content

Commit a50c652

Browse files
Commit to using "organization" (US) instead of "organisation" (GB)
1 parent 8bc4a43 commit a50c652

File tree

7 files changed

+11
-11
lines changed

7 files changed

+11
-11
lines changed

docs/dns/providers/certifydns.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -74,7 +74,7 @@ Advantages:
7474

7575
Disadvantages:
7676

77-
- Delegating DNS validation to an external service theoretically allows the service to complete validation for certificates on your domain. **This is a security risk and you must trust the service provider.** An alternative is to host your own internet facing acme-dns server. You should review the requirements for doing that and assess whether it's the best choice for your organisation. Your CA can implement https://datatracker.ietf.org/doc/html/rfc8657 issuance features for the DNS CAA record standard adds a way to limit updates to only be performed by specific CA accounts. Let's Encrypt now support this CAA extension.
77+
- Delegating DNS validation to an external service theoretically allows the service to complete validation for certificates on your domain. **This is a security risk and you must trust the service provider.** An alternative is to host your own internet facing acme-dns server. You should review the requirements for doing that and assess whether it's the best choice for your organization. Your CA can implement https://datatracker.ietf.org/doc/html/rfc8657 issuance features for the DNS CAA record standard adds a way to limit updates to only be performed by specific CA accounts. Let's Encrypt now support this CAA extension.
7878

7979
## Pricing
8080

docs/faq.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@ Our aim is to ensure that the app is easy to use and that you get setup with you
1313
Web hosting configurations vary and sometimes securing your site can be harder than expected, but the good news is that thousands of other users have succeeded before you. There are a few things that are good to know should you run into any problems. If you encounter a problem you can't resolve, check out our [support options](support.md).
1414

1515
### Is this application commercially supported?
16-
Yes, full time [email support](support.md) is available for registered users who have purchased a license key (or those who are evaluating the software) via https://certifytheweb.com/upgrade/. This makes the application ideal for organisations or professionals who need a dependable support option. Support operates office-hours, weekdays (Australian Western Standard Time) with some coverage on weekends. Telephone support and general consultancy is not currently available but we will try to help where we can for all questions. Users of the free Community Edition are also supported via our community forum and other [support options](support.md).
16+
Yes, full time [email support](support.md) is available for registered users who have purchased a license key (or those who are evaluating the software) via https://certifytheweb.com/upgrade/. This makes the application ideal for organizations or professionals who need a dependable support option. Support operates office-hours, weekdays (Australian Western Standard Time) with some coverage on weekends. Telephone support and general consultancy is not currently available but we will try to help where we can for all questions. Users of the free Community Edition are also supported via our community forum and other [support options](support.md).
1717

1818
*You are encouraged to test out the software yourself as an evaluation before purchasing, as not all usage scenarios will be supported.*
1919

@@ -23,7 +23,7 @@ Yes, full time [email support](support.md) is available for registered users who
2323

2424
To activate your license key open the app and navigate to the *About* tab, then click *Enter Key* to apply your license. To transfer to a new license key use *About > Deactivate Install*, then *About > Enter Key* to apply the new key. You can also deactivate the usage of a key within the app or from the https://certifytheweb.com License Keys tab.
2525

26-
**If you are using this application within a business or funded organisation (beyond a temporary evaluation) you are required to purchase a license key.**
26+
**If you are using this application within a business or funded organization (beyond a temporary evaluation) you are required to purchase a license key.**
2727

2828
For more information about licensing see our [licensing guide](./guides/licensing.md).
2929

docs/guides/best-practices.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ Once you have setup your certificate and your website is accessible over https y
88

99
However, if you scan your website with a tool such as https://www.ssllabs.com/ssltest/ it will likely point out a number of areas you could improve upon, many of which are quite cryptic. These include areas such as *HTTP Strict Transport Security* (HSTS), *Protocols* and *Cipher Suites*.
1010

11-
Even if you have a great automated score for security, your choice of operating system can be a security or operational risk and the way you manage your application lifecycle could be a risk to your organisation.
11+
Even if you have a great automated score for security, your choice of operating system can be a security or operational risk and the way you manage your application lifecycle could be a risk to your organization.
1212

1313
## Redirecting all visitors to HTTPS
1414
A user could try to access your site by just typing the domain or perhaps they will even type the full domain with `https://` - whether the site loads as `http://` or `https://` will depend on the web browser or the link the user followed, so in some cases users will see a site as "insecure". To avoid this, you can automatically direct the users browser to the HTTPS version of your site.
@@ -113,7 +113,7 @@ If you are running **Windows Server 2012**, mainstream support from Microsoft en
113113
Mainstream Microsoft support for **Windows Server 2016** ended in January 2022.
114114

115115
## Disaster Recovery Planning
116-
It's very common for organisations to consider their apps as being "too difficult" to move to newer operating systems. This is a critical risk for your system and if your service is *business critical* (i.e. your business cannot effectively operate without it) then it's also a high priority risk to your business. If you *cannot* move an app (because you don't really know how), consider whether you can even restore it if the server fails and the impact to your organisation if that happens.
116+
It's very common for organizations to consider their apps as being "too difficult" to move to newer operating systems. This is a critical risk for your system and if your service is *business critical* (i.e. your business cannot effectively operate without it) then it's also a high priority risk to your business. If you *cannot* move an app (because you don't really know how), consider whether you can even restore it if the server fails and the impact to your organization if that happens.
117117

118118
Write a simply worded document that you can hand to a competent IT administrator (they should not have to know the system or how it works beforehand) that lets them recover your system to a new server. The document should summarize what the system does, how it's put together and most importantly how to set it all up again to the point where users can start using it. **Exercise the plan by getting someone else to setup a test system using your document.**
119119

docs/guides/certificate-authorities.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -7,13 +7,13 @@ title: Certificate Authorities
77

88
## Introduction
99

10-
For a certificate to be trusted by other computers it needs to be issued using another certificate controlled by a **Certificate Authority (CA)**. This is an organisation or service which controls the issuing of certificates. Your computer operating system update process will usually take care of maintaining a 'Trust Store' of root certificates and when your computer sees a certificate from that issuer it knows that's one of the certificates it should trust.
10+
For a certificate to be trusted by other computers it needs to be issued using another certificate controlled by a **Certificate Authority (CA)**. This is an organization or service which controls the issuing of certificates. Your computer operating system update process will usually take care of maintaining a 'Trust Store' of root certificates and when your computer sees a certificate from that issuer it knows that's one of the certificates it should trust.
1111

12-
There are hundreds of publicly trusted Certificate Authorities and a subset of those implement a specification for certificate request/renewal called **ACME** (Automatic Certificate Management Environment) https://datatracker.ietf.org/doc/html/rfc8555 (ACME v2). Anyone can create (and use) a new certificate authority but only recognised CAs which can prove they follow strict issuance guidelines become generally trusted. You can, for instance, create your own ACME certificate authority and trust it within your organisation, but it won't be trusted by computers outside your organisation.
12+
There are hundreds of publicly trusted Certificate Authorities and a subset of those implement a specification for certificate request/renewal called **ACME** (Automatic Certificate Management Environment) https://datatracker.ietf.org/doc/html/rfc8555 (ACME v2). Anyone can create (and use) a new certificate authority but only recognised CAs which can prove they follow strict issuance guidelines become generally trusted. You can, for instance, create your own ACME certificate authority and trust it within your organization, but it won't be trusted by computers outside your organization.
1313

1414
The app supports a number of built-in CAs but you can also configure your own custom ACME CA (either public or self-hosted). Different managed certificates can be configured to use different CAs or they can all default to the same CA.
1515

16-
The certificate issuance service remains the responsibility of the Certificate Authority and we (Certify The Web operated by Webprofusion Pty Ltd) have no affiliation to their organisation or any control over their service. **Our software makes the process easier and automates how you acquire and use the certificates. We are not a Certificate Authority.** Using Certify to request a certificate from a CA also means you accept the CAs current service privacy policy, and their terms and conditions.
16+
The certificate issuance service remains the responsibility of the Certificate Authority and we (Certify The Web operated by Webprofusion Pty Ltd) have no affiliation to their organization or any control over their service. **Our software makes the process easier and automates how you acquire and use the certificates. We are not a Certificate Authority.** Using Certify to request a certificate from a CA also means you accept the CAs current service privacy policy, and their terms and conditions.
1717

1818
From v6.x onwards the app supports smart CA failover/fallback so if your preferred CA is unavailable for any reason (e.g. maintenance) it will automatically try to use another configured CA account. To use this feature ensure you have configured multiple CA accounts under Settings > Certificate Authorities, for instance you might already have a Let's Encrypt account configured as your default, but you could add a Google Trust account as a fallback (or vice-versa).
1919

docs/guides/certificates.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ title: Certificates
55

66
# Certificates
77

8-
Certificates are part of a Public Key Infrastructure (PKI) trust mechanism which state that a [Certificate Authority (CA)](certificate-authorities.md) has validated the identity of something. In our case, certificates are Domain Validated (DV) certificates, meaning they are (automatically) validated to ensure they have been issued to the organisation controlling the given domain.
8+
Certificates are part of a Public Key Infrastructure (PKI) trust mechanism which state that a [Certificate Authority (CA)](certificate-authorities.md) has validated the identity of something. In our case, certificates are Domain Validated (DV) certificates, meaning they are (automatically) validated to ensure they have been issued to the organization controlling the given domain.
99

1010
A digital certificate consists of a set of public information which has been signed by a Certificate Authority and issued to the holder of a secret *Private Key*. It asserts that the CA believes the holder (represented by their own public key, derived from their own private key) controls a particular domain (or set of domains). The public certificate itself is useless to anyone else except to verify the identity of the service presenting it. They can encrypt something with the public key and only the holder of the private key can decrypt it. This proves that the service you are communicating with also holds the private key that was used when the certificate was created.
1111

docs/guides/csr.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ title: Certificate Signing & Security
77

88
When requesting a certificate from a [Certificate Authority (CA)](certificate-authorities.md) a special file called a Certificate Signing Request (CSR) is submitted. See also https://en.wikipedia.org/wiki/Certificate_signing_request
99

10-
In the case of ACME domain validated certificates this CSR mainly just includes the list of domains you want to include on the certificate (other fields such as Organisation etc are discarded because ACME doesn't validate these). The CSR is signed using your Private Key, verifiable using the public key included in the CSR. This ensures that the same entity who completed certificate validation is also the same entity submitting the certificate signing request.
10+
In the case of ACME domain validated certificates this CSR mainly just includes the list of domains you want to include on the certificate (other fields such as Organization etc are discarded because ACME doesn't validate these). The CSR is signed using your Private Key, verifiable using the public key included in the CSR. This ensures that the same entity who completed certificate validation is also the same entity submitting the certificate signing request.
1111

1212
## OCSP Must-Staple
1313
To enable OCSP-Must staple check *Require OCSP Must-Staple* under Certificate > Advanced > Signing & Security. This will add the OCSP Must Staple extension to the CSR and the resulting certificate.

docs/support.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ Check out our [FAQ](faq.md) if you are just getting started and having trouble w
1515

1616
## Support for Licensed Customers
1717

18-
Our products are ideal for organisations or professionals who need tools with dependable support. _You are encouraged to test out the software yourself as an evaluation before purchasing as not all usage scenarios will be supported._
18+
Our products are ideal for organizations or professionals who need tools with dependable support. _You are encouraged to test out the software yourself as an evaluation before purchasing as not all usage scenarios will be supported._
1919

2020
**Full time support is available via email support tickets for registered users (or those who are evaluating the software).** You can register for the Professional or Enterprise editions via https://certifytheweb.com/upgrade/. To create a new support request for help or for general questions, email **support at certifytheweb.com**, including details of your licensed email address, describing the problem/question in detail with any supporting information you can provide.
2121

0 commit comments

Comments
 (0)