Subscribe:
Showing posts with label RapidSSL-Wildcard. Show all posts
Showing posts with label RapidSSL-Wildcard. Show all posts

Sunday, 25 September 2011

Lync Deskphones and Wildcard Certificates


A critical component of any Lync deployment is the deskphone.  While some users may be comfortable with using a headset/PC combo as their primary telephony interface, I've found that most users still prefer a deskphone.

However, getting a Lync deskphone to work with Lync can be a bit tricky if you aren't diligent about following Microsoft best-practices to the letter.  You may have a Lync environment that works perfectly well for computer-based Lync clients, but you may come across various connectivity issues when you plug in a Lync deskphone that does presence and Exchange calendaring. 

I recently came across a client who were having Exchange connectivity issues with their Polycom CX600 phones.  The Polycom CX600 is likely the most popular Lync deskphone. It provides a very slick interface into Lync and Exchange so you can see your presence, contacts and upcoming meeting information. It is also very cost-effective compared to other similar products.

When users signed into Lync on their CX600 (either via keypad or USB-PC integration), they were soon presented with the following error:
 
Microsoft Exchange integration unavailable.  Connection to Exchange is unavailable due to invalid network credentials.
The CX600 uses Exchange Web Services (EWS) and autodiscover to find the connection to Exchange.  If there are issues with either service, it will pretty much guarantee that the CX600 won't connect.  I verified that both EWS and autodiscover were working properly.

When I reviewed the certificate loaded on the Exchange Client Access Server, I saw that the common name (CN) was set to their public domain (ie. contoso.com).  The Subject Alternate Names (SAN) included all the required names.  Microsoft Lync documentation recommends that you do not use certificates with the CN set to a wildcard domain name.  You CAN use wildcards in the SAN, but the CN really should be a valid name.  In this case contoso.com is the same as *.contoso.com. 

The client replaced the certificate with one whose CN matched the externally accessible name of the CAS server (owa.contoso.com) as reported by Exchange.  They issued an IISReset, restarted the CX600 and the error went away.  They now have full connectivity to Exchange via the CX600.

I've seen variations on this many times on both Exchange and Lync.  If you're only using Lync PC clients, you may never notice any issues, but as soon as you bring deskphones and even mobile phones into the mix, these sort of things often come up. 

So as a general rule, if you're creating certificates for Lync or Exchange, 
DON'T use a Wildcard SSL as the first name.

Tuesday, 23 August 2011

How SSL Certificate Work? Why you should include In the E-commerce Web Design SSL?

As a web designer, it is important to know about SSL certificates. How SSL certificate work? Read on to learn more about SSL Certificates and why it is important to include the design of your ecommerce site.

How SSL certificate work?

To send the form to the network (such as credit application), the browser must first request a protected page, the web server. Subsequently, the server sends the public key certificate for an SSL site. The browser will then ensure that the certificate is valid and reliable by the party.

Once verified, the browser uses a public key to create and encrypt a random symmetric encryption key. Then sent to a Web server with the data in encrypted form and the https URL. Once received, the web server uses a private key to decrypt the symmetric encryption. Decrypts the symmetric key and the form data and URL.

Required format and data online (HTML) is sent to the Web server encrypted with a symmetric key. The browser then decrypts the data and documents using a symmetric key and displays the information to the recipient

Why should you use SSL in your website?

You should add SSL Certificates for websites if they plan the early stages of online stores where customers can buy products. Financial information (like credit cards) and other confidential information from online forms. Without SSL, the data is easily intercepted and stolen by people who are "packet sniffing" using software that can eavesdrop on your network. Unsecure websites can be identified by the “http” in their URL. In general, these types of sites are generally informational in nature and do not have interactive online forms. Deemed secure SSL sites have "https" in their URL, and will have a padlock icon at the bottom right of the page. If you sell items and an online form without the "https", you will not get many customers.

Online forms deemed secure SSL sites have "https" in their URL, and will have a padlock icon at the bottom right of the page. If you sell items and an online form without the "https", you will not get many customers.

A good understanding of how SSL certificates work is important because sensitive financial information can be compromised and stolen. When creating a secure ecommerce website, it is essential to set during the early stages of design for the safety of clients and owners of e-commerce site.

Tuesday, 26 July 2011

Using Wildcard Certificates with the Citrix Access Gateway

Recently, I had the opportunity to install a wildcard certificate on a Citrix Access Gateway. For this install, there were two Access Gateway appliances in a DMZ and the license server, housing the Access Gateway licenses, was on the internal network. My initial research didn't turn up much, but I did find the following items within the Access Gateway Administrators Guide: 



The following are taken directly from the Access Gateway Administrator’s Guide:

 1. Using Wildcard Certificates

The Access Gateway supports validation of wildcard certificates for Secure Access Clients. The wildcard certificate has an asterisk (*) in the certificate name. Wildcard Certificates can be formatted in one of two ways, such as *.mycompany.com or www*.mycompany.com. When a wildcard certificate is used, clients can choose different Web addresses, such as http://www1.mycompany.com or http://www2.mycompany.com. The use of a wildcard certificate allows several Web sites to be covered by a single certificate.

2. Important The FQDN must match what is on the digital certificate and the license for the Access Gateway.

So, it appears to be supported, and perhaps even doable.

Then I came across this Citrix Knowledge Center article. The section of the article of most concern to me is shown below:




"Some of the problems that may occur when dealing with Access Gateway and certificates are as follows: Verification Failure error during upload of certificate.

 This will happen if you try to upload a certificate without a private key. A common situation is where a company has multiple Access Gateways and uploading the same cert to each gateway.

 The resolution in this case is to generate a new CSR and have a new certificate issued with the private key."

So, maybe it won't work since I want to use the same wildcard certificate on each Access Gateway. 

Well, I proceded to convert and install the Wildcard SSL Certificate on each Access Gateway. I set the External FQDNs on each CAG as cag1.domain.com and cag2.domain.com respectively. Upon the next reboot, I got the Verification Failure" error on each device which, in this case, caused them to reboot themselves after a few minutes. The exact error displayed on the CAG console: 




 I followed the advice given, ie, reset the server certificate and reboot the CAG. 



After the reboot, I uploaded the wildcard certificate to each CAG once again, but this time, I did not specify an External FQDN on the CAGs and rebooted. This time, the CAGs stayed up and clients could successfully use the Secure Access Client for HTTPS VPN access and the Web Interface for connecting to specific published applications. 

To recap, to use the same wildcard SSL Certificate on each CAG, I uploaded the certificate to each CAG and left the External FQDN option blank. With this configuration, connectivity to internal resources can be achieved through the CAG using the Secure Access Client or the Web Interface. 

What I'd like to know is if any of you have used wildcard certificates on your CAGs, and if so, what do your configurations look like?





GlobalSign’s Lila Kee Recognized by CRN Magazine

Filed Under: 
(The Hosting News) – GlobalSign,  one of the longest established Certification Authorities (CA) and specialists in online security, today announced that Lila Kee, Chief Product Officer and Vice President of US Business Development, has been recognized as a Power 100 Woman of the Channel by CRN Magazine. The “Who’s Who” list recognizes female executives for their accomplishments over the past year, based on their achievements and the amount of influence they wield over the technology channel.  This year’s Women of the Channel were chosen by the editors of CRN Magazine from a field of vendor channel organizations, distributors and solution providers.


As Chief Product Officer and Vice President of US Business Development, Lila is constantly looking for ways to optimize GlobalSign’s security offerings, 
forging strategic partnerships with other industry leaders to bring the most cutting edge security solutions to the channel.  Over the past year, Lila led the Product Development strategy and implementation of GlobalSign’s channel-ready client certificates as a service offering.  GlobalSign resellers and partners can now extend publically trusted digital credentials required for securing code, encrypting email, digitally signing documents and utilizing the online authentication capabilities of browsers and VPN to individuals and entities.
Lila introduced three main product types: PersonalSign, DocumentSign, and Code Signing certificates through the GlobalSign Certificate Center (GCC) partner portal, equipping resellers with an easy method to register, provision, and manage digital IDs ordered on behalf of their customers. But it was Lila’s vision for making digital signature security available to electronic document workflow service providers that has established her as a true leader in her field.  Lila was instrumental in creating and delivering Adobe Certified Document Services, (CDS) for service providers to host on behalf of Enterprise customers as a value added service to document work-flow and management activities already provided. Adding a secure signature to high stake documents associated with healthcare, financial transactions, and government services was a natural extension to these service providers.
“This year’s Power 100 Women of the Channel list honors the most successful and influential women in the IT channel – a traditionally male-centric industry.  The Power 100 list is an elite subset of our annual Women of the Channel list, which recognizes the 100 most influential women of the channel based on their overall achievements, and their influence in the technology industry,” said Kelley Damore, VP, Editorial Director, Everything Channel.“We are so proud and excited for Lila to receive this honor”, said Motoo Noda, Chief Executive Officer, GMO GlobalSign Inc.  “Lila is not only a wealth of knowledge and leading mind in the industry, but also an amazing person to work with.  Her passion for her work is infectious.  She is a great role model and someone we can all aspire to”.
The Power 100 Women of the Channel will be listed on CRN.com.  The overall Women of the Channel list will appear in the July 2011 issue of CRN Magazine.

About Everything Channel
Everything Channel is the premier provider of IT channel-focused events, media, research, consulting, and sales and marketing services. With over 30 years of experience and engagement, Everything Channel has the unmatched channel expertise to execute integrated solutions for technology executives managing partner recruitment, enablement and go-to-market strategy in order to accelerate technology sales. Everything Channel is aUBM company. To learn more about Everything Channel, visit us athttp://www.everythingchannel.com. Follow us on Twitter at http://twitter.com/everythingchnl.

About UBM plc
UBM plc is a leading global business media company. We inform markets and bring the world’s buyers and sellers together at events, online, in print and provide them with the information they need to do business successfully. We focus on serving professional commercial communities, from doctors to game developers, from journalists to jewellery traders, from farmers to pharmacists around the world. Our 6,000 staff in more than 30 countries are organised into specialist teams that serve these communities, helping them to do business and their markets to work effectively and efficiently.For more information, go to www.ubm.com

About GMO GlobalSign
Established in 1996 and as a WebTrust accredited public SSL Certificate authority, GlobalSign offers publicly trusted SSL Certificates, EV SSL, Managed SSL Services, S/MIME email security and Code Signing for use on all platforms including mobile devices. Its Trusted Root solution uses the widely embedded GlobalSign Root CA certificates to provide immediate PKI trust for Microsoft Certificate Services and internal PKI, eliminating the costs of using untrusted Root Certificates. Its partnership with Adobe to provide Certified Document Services (CDS) enables secure digitally signed PDF documents, certified transcripts and e-invoices.  These core Digital Certificate solutions allow its thousands of authenticated customers to conduct secure online transactions, data transfer, distribution of tamper-proof code, and protection of online identities for secure email and access control.  The company has a history of innovation within the online security industry and has offices in the US, UK, Belgium, Japan, and China.

About GMO Internet Group
GMO Internet Group is a leading force in the Internet industry offering one of the most comprehensive ranges of Internet services worldwide. The group is the top provider of domain registration, web hosting, ecommerce, and payment processing solutions in Japan and operates a host of other Internet 
services including global online security services, search engine marketing and online securities trading. At the center of the group is GMO Internet, Inc. (TSE: 9449) headquartered in Tokyo, Japan.  Please visit www.gmo.jp/en for further details.

Trustwave

Republished By:- SSL NEWS




Protect Your Entire Site With The Same SSL Certificate


The Thawte Wildcard SSL Certificate allows you to secure unlimited subdomains of your main domain with a single Certificate. For example, if you have the domain abc.com, any number of subdomains will be protected by this certificate: mail.abc.com, store.abc.com, etc.. You will not have to buy separate Certificates for each new subdomain as is the case with standard certificates. This solution is ideal if you use SSL for multiple subdomains – only one certificate to install, and in many cases it is more cost-effective. Please note that all subdomains must be on the same Server.

Thawte Wildcard SSL Certificates may use an IP address to all secondary domain names. The same certificate can be used to secure all subdomains associated with a domain name, sharing one IP for all subsequent years. You can configure name based virtual hosts instead of machines.

Reasons for Choosing the Thawte Wildcard SSL Certificate:

• Encryption strength from 40 to 256 bits, according to the ability of browsers clients. 
• Issue in 2 business days, depending on the fulfillment of the requirements by the applicant.
• The ubiquity is the highest available in the browser market.
• High standards of validation, through the intervention of a trusted third party such as Thawte, which guarantees the authenticity of your company and website ownership for Certification. 
• Rigorous Verification and authentication procedures integrated (domain name and identity certificate validation). The prestige of Certificate Authority (CA) authorization. 
• Protocol Secure Socket Layer (SSL), maintaining privacy of messages exchanged between the web Server and its users. 
• Recertification without limit during the lifetime of the Certificate.
• High-strength encryption technology and high reliability of the site signature to protect your transactions.

Read more:-http://www.hostreview.com/news/110726-protect-your-entire-site-with-the-same-ssl-certificate#ixzz1TCIg1zf7

VASCO Reports Results for Second Quarter and First Six Months of 2011


Revenue for the second quarter of 2011 was $43.0 million, an increase of 74% compared to the second quarter of 2010; Operating income for the second quarter of 2011 was $3.4 million, an increase of 116% compared to the second quarter of 2010. Guidance for full-year revenue growth in 2011 over 2010 increased. Financial results for the period ended June 30, 2011 and guidance for full-year 2011 to be discussed on conference call today at 10:00 a.m. E.D.T.

OAKBROOK TERRACE, Ill. and ZURICH, July 26, 2011 /PRNewswire/ -- VASCO Data Security International, Inc. (Nasdaq: VDSI) (www.vasco.com), today reported financial results for the second quarter and six months ended June 30, 2011.

Revenue for the second quarter of 2011 increased 74% to $43.0 million from $24.7 million in the second quarter of 2010, and for the first six months of 2011, increased 63% to $79.3 million from $48.7 million for the first six months of 2010.  

Net income for the second quarter of 2011 was $2.6 million, or $0.07 per diluted share, an increase of $1.2 million, or 88%, from $1.4 million, or $0.04 per diluted share, for the second quarter of 2010.   Net income for the first six months of 2011 was$5.1 million, or $0.13 per diluted share, an increase of $3.1 million, or 160%, from $2.0 million, or $0.05 per diluted share, for the comparable period in 2010.

Other Financial Highlights:
Gross profit was $26.3 million, or 61% of revenue, for the second quarter of 2011 and $49.0 million, or 62% of revenue, for the first six months of 2011. Gross profit was $17.4 million and $34.1 million for the second quarter and first six months of 2010, respectively, or 70% of revenue for both periods of 2010.
Operating expenses for the second quarter and first six months of 2011 were $22.9 million and $42.5 million, respectively, an increase of 44% from $15.9 million reported for the second quarter of 2010 and an increase of 34% from $31.8 million reported for the first six months of 2010.
Operating expenses for the second quarter and first six months of 2011 included $0.8 million and $1.3 million, respectively, of expenses related to stock-based incentives.  Operating expenses for the second quarter and first six months of 2010 included $0.6 million and $1.2 million, respectively, of expenses related to stock-based incentives.    
Operating income for the second quarter and first six months of 2011 was $3.4 million and $6.5 million, respectively, an increase of $1.8 million, or 116%, from $1.6 million reported for the second quarter of 2010 and an increase of $4.2 million, or 181%, from $2.3 million reported for the first six months of 2010. Operating income as a percentage of revenue for the both second quarter and first six months of 2011 was 8% compared to 6% and 5% for the comparable periods in 2010.  
Earnings before interest, taxes, depreciation and amortization (EBITDA) was $5.3 million and $9.8 million for the second quarter and first six months of 2011, respectively, an increase of 134% from $2.2 million reported for the second quarter of 2010 and an increase of 159% from $3.8 million reported for the first six months of 2010.
Cash balances at June 30, 2011 totaled $84.6 million compared to $86.0 million and $85.5 million at March 31, 2011 and December 31, 2010, respectively.  There were no bank borrowings at any of the periods ended June 30, 2011, March 31, 2011 or December 31, 2010.

Operational and Other Highlights:
·         VASCO acquired Alfa & Ariss, a specialist in open identity and access management, on April 1, 2011.
·         VASCO's cloud-based DIGIPASS as a Service authentication was made available for Google™ Apps.
·         Belgian cloud service provider Thinfactory put DIGIPASS as a Service at the disposal of the end-users of its online web store.
·         VASCO entered the global SSL certificate market with CertiID SSL and EV SSL Certificates.
·         VASCO launched its CertiID managed PKI offering trusted certificates to corporations' employees and business partners.
·         VASCO launched DIGIPASS 836, a smart card reader with an optical interface and replaceable batteries.
·         The University of Colorado at Boulder used VASCO's DIGIPASS GO 6 and IDENTIKEY Server to secure access to its new supercomputer and its network.
·         Indiana University deployed VASCO's DIGIPASS to provide secure access to its institutional data and online applications.
·         Soliton Systems, a leading Japanese network solution vendor, embedded VACMAN® Controller in its Net'Attest EPS series product line, its all-in-one authentication server appliances.


Guidance for full-year 2011:
VASCO is revising its guidance for the full-year 2011 as follows:
·         Expected revenue growth of more than 40% for the full-year 2011 over full-year 2010, as compared to expected full-year revenue growth of more than 20% announced at the end of the first quarter of 2011; and
·         Operating margins, excluding expenses related to the amortization of acquisition-related intangible assets, for full-year 2011 are projected to be in the range of 8% to 12% of revenue, no change from guidance previously announced, but are expected to be at the lower end of the range.


"The second quarter of 2011 continued to show strong revenue growth from our traditional businesses," stated T. Kendall Hunt, Chairman & CEO.  "Revenues in the second quarter of 2011 were the highest in the company's history, reflecting strong growth from the banking market partially offset by a decline in revenues from the enterprise and application security market.   We expect to report strong revenue growth for full-year 2011 over 2010.  We believe that our strong order intake, which includes a significant number of orders scheduled to ship and invoice in 2011 and beyond, is an important and concrete sign that our business is gaining momentum.  We also continued to invest in our DIGIPASS as a Service product line.  The addition of Google™ Apps to our platform was a significant addition and we continue to work on integrating other important SAAS applications into our platform."

"In addition to our strong order intake, we have a strong pipeline of potential new orders and we expect that we will experience continued strong revenue growth in the second half of the year, driven primarily by the performance of the banking sector," stated Jan Valcke, VASCO's President and COO. "We also believe that our non-banking business will improve as a result of programs designed to support our reseller channel and their efforts.  With the projected strong growth in revenues from the banking market in 2011, which includes high volume transactions with lower average selling prices, we expect our gross margins as a percentage of revenue will continue to be below the comparable quarters of 2010.  Looking forward, we believe that as the performance from our non-banking business improves and our services strategy gains traction, our gross margins will improve."

Conference Call Details
In conjunction with this announcement, VASCO Data Security International, Inc. will host a conference call today, July 26, 2011, at 10:00 a.m. EDT - 16:00h CET.  During the Conference Call, Mr. Ken Hunt, CEO, Mr. Jan Valcke, President and COO, and Mr.Cliff Bown, CFO, will discuss VASCO's Results for the Second Quarter and First Six Months Ended June 30, 2011.

To participate in this Conference Call, please dial one of the following numbers:

USA/Canada: +1 800-268-2160
International:  +1 303-223-4375

And mention VASCO to be connected to the Conference Call.

The Conference Call is also available in listen-only mode on www.vasco.com. Please log on 15 minutes before the start of the Conference Call in order to download and install any necessary software. The recorded version of the Conference Call will be available on the VASCO website 24 hours a day for at least 60 days.

RapidSSL Wildcard Services