andyt57 Posted July 6, 2018 Posted July 6, 2018 One of my primary schools has their website hosted by eSchools. They have just received a letter from eSchools stating that an upcoming Google browser update will change the way that they will display information relating to website security and since the school has a DfE allocated domain (i.e. http://www.school.area.sch.uk) the school will need to buy a certificate from eSchools (by 13th July!) at a cost of £95+VAT per annum. Is there a cheaper way of adding a certificate to an externally hosted web site? Andy
Sibrows Posted July 6, 2018 Posted July 6, 2018 Can you ask them if they support letsencrypt? https://letsencrypt.org
pete Posted July 6, 2018 Posted July 6, 2018 I'd ask eSchools why they haven't integrated Let's Encrypt (like nearly every other hosting provider) Can you post the text of the letter (the bit describing the certificate and the issue) so we can see what they're trying to sell?
Sibrows Posted July 6, 2018 Posted July 6, 2018 This has been covered in the press over the past 6 months: https://www.theregister.co.uk/2018/02/08/google_chrome_http_shame/ but as both of us have pointed out there are no cost alternatives.
pete Posted July 6, 2018 Posted July 6, 2018 Ah, so blatant milking of customers rather than selling you an EV wildcard cert or anything fancy? A single-domain cert is ~£7/yr from Namecheap. I suspect eSchools may charge you £88 for installing it though.
andyt57 Posted July 6, 2018 Author Posted July 6, 2018 Can you post the text of the letter (the bit describing the certificate and the issue) so we can see what they're trying to sell? Letter attached. AndySSL Certificate Letter.pdf
pete Posted July 6, 2018 Posted July 6, 2018 So reading that letter.. Does the primary currently use https://primaryschoolname.eschools.co.uk to access eSchools? If you do (and HTTPS works) you don't need to do anything. However, if the primary uses http://primaryschoolname.region.sch.uk to access eschools insecurely (no current cert) they're very likely breaking data protection legislation (judging by how eschools can be used) and yes, you need to get a certificate on there.
andyt57 Posted July 6, 2018 Author Posted July 6, 2018 So reading that letter.. Does the primary currently use https://primaryschoolname.eschools.co.uk to access eSchools? If you do (and HTTPS works) you don't need to do anything. However, if the primary uses http://primaryschoolname.region.sch.uk to access eschools insecurely (no current cert) they're very likely breaking data protection legislation (judging by how eschools can be used) and yes, you need to get a certificate on there. Yes, the school is a .dorset.sch.uk so it looks like we need an SSL certificate. But I'm a bit annoyed at getting a letter like that which gives me less than 2 weeks to investigate the alternatives, especially as I only work at the school for 15 hours a week and, since the school is part of an academy, this is the end of the financial year and there's not much money left. Andy
Blue_Cookeh Posted July 6, 2018 Posted July 6, 2018 1. Move your DNS over to Cloudflare 2. point it at eSchools 3. turn on Cloudflare's auto SSL functionality 4. ???? 5. PROFIT! (... or 0 cost, anyway)
gsk Posted July 10, 2018 Posted July 10, 2018 However, if the primary uses http://primaryschoolname.region.sch.uk to access eschools insecurely (no current cert) they're very likely breaking data protection legislation (judging by how eschools can be used) and yes, you need to get a certificate on there. Why would not having SSL break Data Protection legislation? Genuine question. 1
pete Posted July 10, 2018 Posted July 10, 2018 (edited) Why would not having SSL break Data Protection legislation? Genuine question. eSchools isn't necessarily just a school website. Depending on which package you buy it can be parental communications and/or VLE as well. If a school has bought the parental comms or VLE (homework/attainment) options then it's holding personal data. If you're using HTTP-based auth for that over the Internet you're not adequately securing personal data (certs cost very little - there's no good excuse not to use one). This doesn't mean the OP's school is doing that, just that a 30-second poke around a random selection of primary websites using eSchools reveals a fair amount using the add-on bits. Edited July 10, 2018 by pete
Edutech98 Posted July 10, 2018 Posted July 10, 2018 If the school had some kind of embedded "contact us" which allowed you to send the school messages via the school website that's the only thing I can think off? i.e a person sends what they think is a confidential email via the website. Or maybe if the school had links to other applications on their site i.e schoolemail login page - you'd want a secure connection to ensure you are not being sent to a spoofed site. In fairness though I can't remember actually seeing a contact us on a school website, it normally just gives the postal address and email so this might be an irrelevant point!
Oaktech Posted July 10, 2018 Posted July 10, 2018 If the school had some kind of embedded "contact us" which allowed you to send the school messages via the school website that's the only thing I can think off? i.e a person sends what they think is a confidential email via the website. Or maybe if the school had links to other applications on their site i.e schoolemail login page - you'd want a secure connection to ensure you are not being sent to a spoofed site. In fairness though I can't remember actually seeing a contact us on a school website, it normally just gives the postal address and email so this might be an irrelevant point! It's an interesting point that I'm going to bring up with my webdeveloper as we're getting a new website right now. We have a contact page, so that may be an issue. We have both staff and parent links pages, but all the links off are to thirdparty sites with their own SSL.
pete Posted July 10, 2018 Posted July 10, 2018 Given it's trivial* to set up, I can't see a good reason not to use HTTPS. Especially since Google has been using it as a lightweight ranking tool since ~2014. *for values of "having picked a sensible hosting provider"
andyt57 Posted July 10, 2018 Author Posted July 10, 2018 eSchools isn't necessarily just a school website. Depending on which package you buy it can be parental communications and/or VLE as well. If a school has bought the parental comms or VLE (homework/attainment) options then it's holding personal data. If you're using HTTP-based auth for that over the Internet you're not adequately securing personal data (certs cost very little - there's no good excuse not to use one). This doesn't mean the OP's school is doing that, just that a 30-second poke around a random selection of primary websites using eSchools reveals a fair amount using the add-on bits. The school just uses eSchools as a web site, not as a VLE. But they do use a form on their Contact Us page as they found that it vastly reduced the amount of spam they were getting into their office@ email account. Andy
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now