Ask HN: SSL certificates
There has, over the last year or so, been quite a number of interesting crypto-related news coverage related to not inconsequential vulnerabilities and issues. In briefest terms, I'd like to get an idea of what the current best practices/recommendations are regarding deploying applications/services that will operate over HTTPS. For starters--though I'd love to hear beyond where applicable--if someone is launching a new product wanting to be as up-to-date on best security practices in this regard, a few questions:
1. What is the current recommendation for SSL certificates regarding strength, cipher types, etc.? Do wildcard certs have special needs worth being mindful of that non-wildcard certs do not?
2. Any recommendations on reputable, reliable, and trustworthy vendors for securing a new SSL certificate that meets current best-practice expectations?
3. Aside from ensuring a server is up-to-date with all security-related releases/patches, what else should one be mindful of in setting up and deploying a product/service that needs to be secure?
Thanks in advance to all.