Skip to content
LuxSci
Secure High Volume Email Secure Email Gateway Secure Marketing Secure Forms Secure Text Secure Email Hosting Secure Web Hosting
HIPAA Compliant Email HIPAA Compliant Marketing HIPAA Compliant Email Marketing HIPAA Compliant Forms HIPAA Compliant Hosting
API Access SMTP TLS Checker SecureLine Technology System Status Blog EOB Calculator
About Us Partners Support Contact Us
Login Contact Us
Secure High Volume Email Secure Email Gateway Secure Marketing Secure Forms Secure Text Secure Email Hosting Secure Web Hosting
HIPAA Compliant Email HIPAA Compliant Marketing HIPAA Compliant Email Marketing HIPAA Compliant Forms HIPAA Compliant Hosting
API Access SMTP TLS Checker SecureLine Technology System Status Blog EOB Calculator
About Us Partners Support Contact Us
Login Contact Us

Do I need to Buy an SSL Certificate to use Secure Email?

September 23, 2013 • By Erik Kangas • In LuxSci Library: Security and Privacy

Our sales staff have been asked this question countless times.  It is a natural assumption that because SSL and TLS encryption of email (and web sites) requires use of an “SSL certificate”, that one must buy an SSL certificate in order to use such a service.  Fortunately, the answer is always

You do not need to buy your own SSL certificate to use secure email.

We’ll explain why.

How do SSL and TLS work?

At its most basic level, SSL works as follows (TLS works similarly — what is the difference?):

  1. A user connects to a server that supports SSL
  2. The server sends its SSL Certificate back to the user’s computer
  3. The user verifies that the certificate is for the company/domain that it is trying to connect to (the certificate is signed by a trusted third party, like Verisign or Thawte).
  4. If the user trusts the certificate, the user’s computer sends the server a list of encryption methods that it supports
  5. The server picks one that it also supports
  6. The server and the user’s computer communicate henceforth over an encrypted channel using the chosen encryption method.

That is a little technical and terse; for a much more verbose and down to earth overview of how this works, see: How does Secure Socket Layer (SSL or TLS) Work? However, the main point is that the only certificate involved is the one that resides on the server owned by the service provider and which is sent to the user when s/he connects.  Since the user never needs to send his/her own certificate, there is no need to own it.

But without a certificate, how does the server know who I am?

In most cases, when your SSL session is completed, the next step in sending or receiving email is to send your username and password.  The server uses this information to determine your identity and verify your access.  This information is secure and protected by the established SSL security connection.

You do not need your own SSL certificate to establish your identity.

But is not using a client-side SSL certificate more secure than a username and password?

Ah ha! This is the crux of some people’s confusion.

It is indeed possible to have an SSL certificate on your computer and to use this to authenticate yourself with a server, providing that the server supports this kind of authentication.  It can be much more secure than a username and password, as it is tied to your computer and cannot be stolen without physical access to your machine and your account on it.

However, most email services do not support identity authentication via client-side SSL certificates.  This is much more common with secure web sites.  I.e. some OpenID providers, like “myopenid.com”, allow you to authenticate with them using a free client-side SSL certificate. This gives you better security with your OpenID than you get with usernames and passwords.  It also means that you do not have to remember another password … the client-side SSL certificate is your effective “password”.

LuxSci itself does not support use of SSL client-side certificates for any kind of login … though it does support OpenID for WebMail access, and thus supports any kind of excellent authentication accessible in that way.

Ok, when do I need to buy an SSL certificate of my own?

Here is the real question.  As far as LuxSci is concerned, you might need to buy your own SSL certificate in the following cases:

  • You have your own web site and you would like to have some or all of it secured by SSL.  You will then need to get an SSL certificate for your web site’s domain name.
  • You have Private Labeling with LuxSci and wish to use your own domain name in the browser address bar when users are logged in to your branded WebMail securely (i.e., instead of them seeing https://luxsci.com/…).  You would then need an SSL certificate for something like “webmail.yourdomain.com“.
  • You have Private Labeling with LuxSci and wish to use your own domain name in your users’ email clients for their secure IMAP, POP, or SMTP connections to your email server (i.e., instead of them using something like “secure-email.luxsci.com“).  You would then need an SSL certificate for something like “mail.yourdomain.com“.

LuxSci can purchase these SSL certificates for you through its partner, Thawte; or, you can buy them yourself and provide them to LuxSci (let us generate the CSRs  — certificate signing requests — for you to make things easier, however).  Its up to you which way to go; however, if we buy the certificate for you, a lot of leg work will be taken care of on your behalf and we will ensure that the certificate doesn’t expire without your permission. Read more as to why.

Erik Kangas

About Erik Kangas

With 30 years engaged in to both academic research and software architecture, Erik Kangas is the founder and Chief Technology Officer of LuxSci, playing a core role in building the company into the market leader for HIPAA compliant, secure healthcare communications solutions that it is today. An international lecturer on messaging security, Erik also advises and consults on email technology strategies and best practices, secure architectures, and HIPAA compliance. Erik holds undergraduate degrees in physics and mathematics from Case Western Reserve University, and a doctoral degree in computational biophysics from MIT.

Follow: LinkedIn

Get in touch

Find The Best Solution For Your Organization
Talk To An Expert & Get A Quote

I consent to be contacted by LuxSci for this inquiry and other relevant content, products, and services. You may unsubscribe from these communications at any time. We're committed to your privacy. For more information, check out our Privacy Policy.


A member of our staff will reach out to you

Category

  • AAA Featured Articles (8)
  • Affiliates & Resellers (3)
  • Business Solutions (72)
  • Case Studies (8)
  • Collaboration (1)
  • Company Announcements (8)
  • Dedicated & Cloud Servers (15)
  • Email Archival (4)
  • Email data breach (1)
  • Faxing (1)
  • HIPAA Compliant Email Marketing (10)
  • HIPAA Compliant Forms (28)
  • HIPAA Email Compliance (72)
  • HIPAA Marketing (98)
  • HITRUST CSF (6)
  • Industry News (11)
  • LuxSci Help (4)
  • LuxSci Insider (12)
  • LuxSci Library: Email Programs and Devices (13)
  • LuxSci Library: HIPAA (104)
  • LuxSci Library: Insider Insight (2)
  • LuxSci Library: Security and Privacy (95)
  • LuxSci Library: The Technical Side of Email (53)
  • LuxSci Library: Web Design and Programming (4)
  • Mobile (8)
  • New Feature Announcements (88)
  • Patient Engagement (14)
  • Popular Posts (21)
  • Secure Text (7)
  • Secure Video (1)
  • SMTP Connector (3)
  • Spam (1)
  • Telehealth (8)

Recent Posts

  • The Case For Email Security
  • What Makes A HIPAA Compliant Website?
  • Why You Should Separate Your Transactional and Your Marketing Email Sending
  • What exactly does HIPAA say about Email Security?
  • Patient Engagement: Why Email is an Essential Channel
  • 6 Email Marketing Best Practices for Healthcare

Get Your Free E-Book!

LuxSci High Email Deliverability Best Practices Paper

High Email Deliverability Best Practices

What you'll learn:

  • How to optimize email performance
  • Key strategies to increase email deliverability rates
  • How email deliverability impacts marketing ROI
Get Free Ebook
LuxSci

Personalized Healthcare Engagement

LinkedIn G2 YouTube Facebook X (Twitter)

Products

  • Secure High Volume Email
  • Secure Email Gateway
  • Secure Marketing
  • Secure Forms
  • Secure Text
  • Secure Email Hosting
  • Secure Web Hosting

Resources

  • SMTP TLS Checker
  • SecureLine Technology
  • System Status
  • Blog
  • Company
  • Support
  • Partners
  • Contact us
  • Report Security Concerns

Web Portal Links

  • LuxSci App: Phoenix
  • LuxSci App: Ashburn
  • LuxSci App: Staging
  • Premium Email Filtering
  • DNS Management
  • Secure Video
  • MobileSync Device Management
  • SecureSend
  • Affiliate Portal

Legal

  • Privacy Policy
  • GDPR Contract Addendum
  • HIPAA BAA
  • Legal

Copyright © 2004-2025 Lux Scientiae® Incorporated