Subscribe:
Showing posts with label EV-SSL-News. Show all posts
Showing posts with label EV-SSL-News. Show all posts

Sunday, 4 September 2011

SSL CERTIFICATE ISSUE EXPOSES BUG IN MAC OS X



A bug in the Mac OS X Keychain software was exposed when a recently a Dutch certificate issuing authority has issued a fraudulant SSL certificate for *.google.com. This was caused by a hack of the DigiNotar system and 200 certificates were issued. DigiNotar is one of the largest certificate issuing authorities, it is trusted by a large number of browsers and operating systems.
 
Many vendors have issued fixes for the root certificate and most users are secure against it. Mozilla has issued an update on how to manually remove the certificate, Microsoft has also issued a notice and list of affected operating systems on its security advisory board. However, a bug seems to have surfaced on the Mac OS X. Its Keychain software does not seem to recognize that the DigiNotar certificate has been manually removed.
 
As it turns out, this is because of the EV-SSL (Extended Validation SSL) certificate, Keychain ignores the fact that the certificate has been marked as Untrusted by the user. Keychain should ideally override the EV-SSL with the users preferences but that’s not happening so far.
 
Here’s how to manually disable the certificate in Keychain as there is no official fix for it so far.
 
1.       Open the Keychain Access app (found in /Applications/Utilities or just search for it using the Spotlight menu in the top-right corner of your screen)
2.       Click on System Roots and then Certificates on the left side of the Keychain Access window. In the search bar in the top-right corner of the window, type “diginotar” (without quotation marks)
3.       Double-click on DigiNotar Root CA, click on the triangle next to Trust to expand that section, and then next to “When using this certificate:” select “Never Trust”


Thursday, 28 July 2011

Skyypay Renews GeOTrust's EV SSL Certification


Casper, WY, July 3, 2011 – Skyy Services is proud to announce its renewal of GeoTrust’s EV (Extended Validation) SSL Certificate for its SkyyPay service (www.skyypay.com).  SkyyPay, the leading universal online payment processing provider, has yet again proven its commitment to provide a high level of security in protecting customers’ sensitive data.
GeoTrust
This certification confirms that SkyyPay customers may perform secure online transactions and conduct business over the Internet in complete security and confidence.  The EV SSL Certificate uses a more rigid standard of verification process that most companies can’t pass, therefore resulting in a high rejection ratio.
“The GeoTrust EV SSL Certification maximizes the security of our digital transactions and reinforces the legitimacy of our company,” said Ms. Meek, General Manager of Skyy Services.  “Customers will see the GeoTrust logo on our SkyyPay website and be reassured that all their transactions are safe.”After undergoing a long and thorough verification process, Skyy Services was able to renew its GeoTrust EV SSL Certificate, enabling SkyyPay as a leading online payment processing service to achieve this certification.  Obtaining this highest level of authentication re-affirms Skyy Services’ commitment to offer customers with products and services that are compliant with global standards.
About Skyy Services
Skyy Services is a full spectrum e-commerce agency providing innovative technology solutions to individuals and businesses worldwide.  The company’s wide array of online services help clients build, manage and grow their online business.  Founded in 2009, Skyy Services is headquartered in Hong Kong with branch offices in the Philippines and the United States.  For more information on Skyy Services and its products, please visit http://www.skyyservices.com.

About GeoTrust
A wholly owned subsidiary of Symantec, Corp. (NASDAQ: SYMC), GeoTrust is the world’s largest digital certificate provider.  More than 100,000 customers in over 150 countries trust GeoTrust to secure online transactions and conduct business over the Internet.  GeoTrust’s range of digital certificate and trust products enable organizations of all sizes to maximize the security of their digital transactions cost-effectively.  For more information, please visit http://www.geotrust.com.


Monday, 25 July 2011

EV SSL Certificates Gaining in Popularity


A recent report from Netcraft found that Extended Validation SSL certificates continue to gain ground and are being used on more websites. This is from data collected over a four-year period.

Some reports point out that EV certs account for only a percent or two of total SSL certificates in use. This is a misleading stat. This statistic includes free websites and very low traffic sites, which are not a good representation of ecommerce websites.

Netcraft found that almost one-third of the top 1,000 busiest websites that have an SSL certificate are using an EV certificate. That’s a number worth noting…

Green is good

EV SSL certs are the ones that turn the URL address bar green (or to the left of the address bar in some browsers) and display the full company name as well. They are designed to show consumers that the company is who they say they are when shopping with them.

It’s an effective weapon to combat fraudulent websites that pretend to be legitimate companies.
Obtaining an EV certificate is much more involved for a merchant. It requires proof that your company is legit. It’s not easy for a fraudster to get past these checks.

We go into more details about EV SSL Certificates in a recent blog post.

It pays to stand out in a crowd

As the online landscape becomes more crowded, and companies try so hard to be different and stand out from the pack, a EV cert. is one way to do just that.

If your competitors do not use an EV SSL Certificate, then that makes your secure checkout pages stand out.
Some will argue that the average online shopper doesn’t know the difference.

I say, if it causes even a handful of orders to be tipped in your favor, isn’t it worth it? Why wouldn’t you do all that you can to prove to your customers that your store is a safe and secure place to shop?

More people are recognizing that green means “safe and secure”. With Firefox 4, they even abandoned the padlock and went with only colors to denote the safety of a page.

And if your competitors already have EV Certificates? All the more reason to get one, so your store doesn’t look like the insecure one.

Thursday, 7 July 2011

EFF Reveals More Bad Digital Certificate Signing Practices

The Electronic Frontier Foundation warns that certification authorities (CAs) have signed tens of thousands of digital certificates for unqualified names, some of which even passed extended validation.

The EFF, one of the leading digital rights watchdogs, has reached this conclusion after analyzing data from its SSL Observatory project that looks for weaknesses in the public key infrastructure (PKI).Digital SSL Certificates are used to establish encrypted connections and trust on the Internet, which makes them a vital part of its security.

It's, therefore, no wonder that a recent security incident where a hacker managed to obtain rogue certificates for high-profile domains like google.com, mail.live.com, mail.yahoo.com and others from Comodo has put the practices of certification authorities under the microscope.

The EFF warns that aside from hardcoding usernames and passwords in tools used by resellers and failing to perform proper checks for certificate requests received from them, CAs also sign unqualified names.

In practice, there should be a single certificate per domain or subdomain. However, it turns out that some CAs have signed certificates for names like "exchange", "mail" or "wiki," which cannot be accessed over the Internet and are sometimes used on local networks.

"In fact, the most common unqualified name is 'localhost,' which always refers to your own computer! It simply makes no sense for a public CA to sign a certificate for this private name," writes Chris Palmer, EFF's technology director.

Another name for which there are thousands of valid certificates in existence is "exchange" and variations of it, like "exchange01", "exchange02" etc. But not only have CAs signed certificates for unqualified names, many of them signed multiple ones for the same host.

In total, the EFF has counted 37,244 valid certificates that shouldn't exist. A separate investigation performed in January uncovered 10 EV certificates of the same type.

This represents a very serious abuse of trust, because EV SSL stands for extended validation and these certificates are supposed to be issued after extensive identity checks.

The main concern is that if any of these certs falls in the hands of attackers, they can be used to impersonate mail and other types of servers on networks that uses those names internally.

Source URL:-News.Softpedia.Com