Subscribe:
Showing posts with label SSL Certificate. Show all posts
Showing posts with label SSL Certificate. Show all posts

Monday, 6 February 2012

SSL Certificate, TLS and HTTPS basics


SSL Certificates /TLS provide encryption and authentication for HTTPS.
For maximum security
  • Ensure SSLv2 is disabled
  • Generate private keys for certificates yourself, do not let your CA do it
  • Use an appropriate key length (usually 2048 bit in 2011)
  • If possible, disable client-initiated renegotiation
  • Consider to manually limit/set cipher suites
Rationale
The CA has no need-to-know for your private key. Depending on the cipher suite used, the private key can allow adversaries to decrypt passively eavesdropped communications. Thus, even if you trust the CA, it is better to avoid any risk. Generate a key and a CSR Key and provide only the CSR to the CA.
Increasing key length increases security, but also significantly increases the CPU load for connection establishment. 1024 bit keys will not be accepted by Mozilla Firefox anymore for certificates that expire after the year 2013. 2048 bit keys should be enough for all applications for quite a few years – using larger key sizes seems to be overkill. (All information based on 2011.) Note: The large CPU overhead of connection establishment can be used by (D)DoS attackers. Such DDoS attacks are harder to detect and defend against when client-initiated renegotiation is supported.

SSL Certificates /TLS supports a large set of “cipher suites”, each defining a set of cryptographic mechanisms used to secure the connection. Some of them do provide perfect forward secrecy, some do not. (Perfect forward secrecy means that if the private key becomes available to an attacker, he cannot decrypt data that was eavesdropped before he got the key). Usually, the client (browser) and server choose a cipher suite by first exchanging which suites are mutually supported, and the client’s preferred suite is then chosen. Depending on setup, the server may choose the cipher suite, ignoring the client’s preference. Most defaults are reasonably sane, but for either high-speed or high-security applications, you may want to consider restricting the supported/preferred suites to fast or high-security suites. If you want to exclude clients that do not support sufficient security (e.g. ancient “export control” limited clients), make sure to disable those cipher suites. When configuring cipher suites, carefully check the setup to make sure you do not allow “ADH” suites that do not authenticate the server! If you are unsure, keep the default, and always verify the effects of your settings!

Tuesday, 13 December 2011

SSL Certificate and Cyber Security

This article provides plenty of information about Cyber Security and usefulness of SSL certificates to protect your ecommerce website. Know about how to protect Cyber Security & Online transaction(payment) with SSL Certificates.

Since last 20 to 25 years world is rapidly changed to cyber world. Cyber made all things fast and closest. Living miles away, people can see, speak, and live as sitting on coffee table. Cyber innovation changed the growth of world beyond imagination in last 25 years. When a computer was invented it was a giant and now people use it as notebook. Technology is developing rapidly with unmeasured growth.

A rapid growth of cyber required security and safety. People started talking online, shopping online, banking online even getting married online. Let’s talk about cyber security, many online shoppers, sellers and bankers were abused by Hackers (Kind of thieves). These thieves were major problem on cyber invention. People started feeling unsecure started avoiding online dealings. Innovation is on growth and did not want to stop or running back to zero. Technology gurus found key to secure online data and this key is SSL certificate.

What are hackers and hacking?

Hackers are thieves who try to gain un-authorized access to your computer via network or program. Stealing data from computer or network is called hacking. Like as thieves Hackers do not knock your door. They get un-authorized access and start stealing your personal data. You realize once see loose of data, money and everything

Who invented SSL certificate?

SSL certificates are developed on protocol SSL (Secure Socket Layer) by Netscape in 1994. Netscape used encryption and decryption technology to make data unreadable for hackers. Incase hackers steal encrypted data then even he can not read get correct data.

Later technology established SSL certificate standards and authorized few organizations to work as SSL certificate issuer. They are called SSL CA – Certificate Authorities. Few of them are VeriSign, GeoTrust, Thawte, Equifax, Entrust, Global Sign, RapidSSL, Comodo. All these CAs are authorized for issuing Web Trust certificates. SSL technology started supporting up to 256 bit encryption to secure online data.

Conclusion:

As online shopper, seller or banker trust only SSL certificate website. Real merchants always used SSL certificate securing customer credit card details and private information. Do not get abused with good web designs and words, as scammers always use such scamming ideas. Trust only ssl certificate secured websites.
To know more about Different types of SSL Security Certificate visit  https://www.thesslstore.com/

Source: cybernewsnetwork

Monday, 27 June 2011

ComodoSSLstore offers COMODO Code Signing Certificate at $99/year and save $80.00 Flat

As COMODO is one of the largest global supplier of SSL certificates, ComodoSSLstore.com of comodo reseller offer Code Signing SSL certificate for security solution with lowest prices worldwide. The Code signing (digital signature) certificate authenticate your software with a public key encryption.


Online PR News – 02-June-2011 –St. Petersburg, FL— ComodoSSLstore.com is authorized Platinum Partner of Comodo SSL Certificate Authorities, SSL certificate to the Global Security Solution Provider. They are offering market price matches program and the best of Platinum Support of 24 / 7 hours by e-mail, live chat and phone.

ComodoSSLstore.com offer Comodo SSL certificates on very cheap price compared to Comodo (CA) and all other COMODO SSL Certificate Resellers worldwide. ComodoSSLstore believe in striving for electronic commerce and online business security and confidence at the lowest price, just as if you bought directly from Comodo, because they buy in large quantities and pass the savings to their customer.

It is strongly recommended for each publisher intends to use the code or other content on the Internet or corporate networks to spread to have a code signing certificate. Software and other content providers who provide additional security to their clients and produces content should make sure that content not be changed or modified nor the signature. ComodoSSLstore offers lowest price COMODO SSL Code Signing certificate for the security of such vendors. One can buy or renew their code signing certificate with Comodo 

code signing certificate which is offered just for $ 99/year.

Code Signing Certificates
Comodo price: $179.95
ComodoSSLstore price: $99.00

This is huge amount of saving, isn’t it?
Publishers who distribute code or content on the Internet, risking their modified product or imitation again greeted by malicious third parties. With a Comodo Code Signing Certificate allows developers to digitally sign their software before distributing them over the Internet to protect end-users to download the software is original and has not been modified by someone else.

Why Comodo Code Signing Certificate?

Customer Confidence
Code signing certificate insure the integrity of the code that it has not been modified or edited that your customers download from your site.

Authenticity
After downloading, end users can be sure that the code they obtained really came from you, helping you preserve your business reputation and intellectual property. Digital ID's allow customers to identify the author of digitally signed code and contact them should an issue or query arise.

Seamless Integration with Industry-Standard Technology

A trusted Certificate Authority, such as COMODO insures that the code is signed and most of the browsers will not accept action commands from downloaded code.

Ease of Use
Code signing certificates are easy to use in conjunction with the vendor software tools that developers use to create products, macros and objects.

Based in St. Petersburg, Florida, A leader in Internet security solutions, https://comodosslstore.com offers affordable Secure Socket Layer (SSL) certificates, 24/7 support, and sophisticated e-commerce products that are easy-to-use. COMODO SSL Store provides SSL Certificates for multinational companies and top universities throughout the world, allowing them to encrypt communications and commerce over the Internet and to increase trust and transactions. If you would like to discuss a business opportunities and strategic partnership please contact us at product-manager@comodosslstore.com or call (888) 481 5388.


Monday, 13 June 2011

How is SSL desperately out of order?

The analysis in each year or so, the crisis, has become fractures in the system to function as the foundation of the Internet to publish three deep trust.

In 2008, SSL is a devastating weakness, the Secure, VeriSign certificate was issued by subsidiaries. The following year, more than two months after the basic weakness in Internet Explorer it was published, Chrome and Safari Minting was qualified to continue to fool the browser product.


And in 2010, the mystery of the root certificate, Security RSA will ultimately remain unresolved for four days to go until her father accepted the credentials of the orphans Mac OS X and Mozilla's software is included.
This year, it was hackers unknown, Komodo, to break into the server of reseller or certification authority that is used most widely in the world, Google documents for websites and other important mail counterfeits, the revelation last month. This means that had been Fraud several conversations on the web most intimate one at that time users of these browsers, counterfeit goods, Chrome Google is, Mozilla Firefox is blacklisted using each of the two IE took 7 and 8.

SSL provides encryption, electronic commerce and other confidential, as a way to secure Internet communications, made its debut in 1994. In the heart of the system, the private key, web publishers, the rightful owner of the domain to which visitors access the user's connection is not hacking, you can prove fraud. Countless Web sites to prevent people who can monitor the traffic that passes between the two parties, passwords, and encrypt e-mail and other data using SSL Certificate.

This is to exaggerate the difficulty Google is reliability, product, Microsoft, and SSL websites operated by Bank of America where millions of other companies. Moreover, repeated failures, it was suggested that the system is hopelessly broken in its current state.


"Right now, it's just an illusion of security" is a fine Marlinspike repeatedly poked holes in the SSL's technology foundation, security researchers said."Depending on what you think is a threat; you can basically trust them at different levels, which have a fairly serious problem."


SSL has been concerned about the vulnerability of the critics, Comodo, VeriSign, Go Daddy Book review biting best for the business practices of the certification authority called the other for short, CA is known. The root certificate, Internet Explorer, Firefox and included in other major browsers, they can be removed without creating confusion in the vast belt of the Internet.


In that sense, the U.S. government for its decision, they Citigroup received several multi-billion dollar bailout from tax payers and American International Group, is like any other investment companies "too big to fail.


"SSL's current security is dependent on external entities for these reasons are there for us to trust them," said Marlinspike. "They do not have a strong incentive to work because it is not responsible.


In December the same year, Comodo agency, the researchers were affiliated with other open source software outfit that issued the certificate Mozilla.com no questions asked as well.


Please come just sloppily report issued certificates. Last week, an analyst at the Electronic Frontier Foundation, CA is "local host", "exchange" and "Exchange01, such as more than 37,000 so-called qualified domain names to ensure that the SSL certificate issue."These are added to your domain and many organizations have found a prefix used to specify the Microsoft Exchange server and other internal resources.


Go Daddy has, but it was the worst offender, another CA, but was found guilty, in fact, that attention to helping the attackers targeted a large number of corporate intranets and mail servers, Chris Palmer said EFF said.


"The signature 'local host' is a humorous, CA, to create a real risk that they sign the names of other qualified," said Palmer wrote. The attacker E or webmail names, such as CA when it is possible to receive a signed certificate do? Such attacks are completely 'in man in the in the middle attack, webmail organization will be able to spoof the identity of the server! "

Darwin market is really an actor can reject the user with uneven results. But it is impossible in the world of SSL. Large CA and responsibility to verify the millions of certificates that were issued previously, the manufacturer of the browser, without breaking the site to buy them, to remove the root certificate from their software.


As a result, almost all browsers, despite the gaffe, Comodo, VeriSign's unbridled confidence, CA continues to another place. Also, because it is controlled by the Chinese government's Ministry of Information Industry, to approve the certificate produced by the China Internet Network Information Center claims that not a lot of confidence. China has accused guilty of hacking a huge campaign against it and dozens of other even Google, to trust the VeriSign SSL Certificate, can the Chrome browser.

Tuesday, 7 June 2011

UCC SSL: If You Need SSL on Many different Domains



This means that buying an SSL Certificate for example dot com will not give you SSL security for anotherdomain dot com or secure.example dot com. 

Got multiple subdomains needing SSL security? 

Wildcard SSL is your best option. This solution isn't enough for those who need SSL on multiple domains. What about them? Unified Communications Certificate (UCC) SSL is the answer.

Know the Difference between Wildcard and UCC SSL

A Wildcard in the certificate's Common Name lets one certificate be used on different subdomains. For instance, the Common Name *.example dot com enables you use one wildcard certificate for www.example dot com, work.example dot com, or settings.example dot com, but not on example.net, anothername dot com, or shop.anothername dot com. 

The good thing is that UCC SSL will function just fine in the final example. UCC SSL, instead of using the Common Name field, uses the Subject Alternative Name (SAN) field on the certificate. The SAN let you add more domains that will use one UCC SSL certificate. Only one UCC SSL certificate will be enough for example dot com, secure. Example dot com, another name dot com, anothername.net, and one more dot com. Depending on your deal with the certificate provider, you are allowed to add a specific number of domains or subdomains on the certificate.

Benefits to UCC SSL

The most obvious benefit to using UCC SSL Certificates is to cut costs. If you only use a few domains, you may be fine with typical SSL certificates that cost about $150 each. But once you need five domains, you will need to come up with $750. Think how much you can save on 3 domain names when UCC SSL costs only $300 each.

Sometimes, you can get additional domains on the same certificate at $40 each. Some providers will even let you add a limited number of subdomains on the UCC SSL certificate at no charge as a bonus.

UCC SSL is good for another reason, and that's manageability. Most people will cringe at the thought of having to purchase, set up, and then renew annually several SSL certificates. It's a difficult task to whoever is supposed to manage them. Errors can be easily made when managing a number of certificates. Delays from fixing errors will cost you time and money. Just think about how that compares to worrying about just a single UCC SSL certificate. It's a whole lot easier to manage a single certificate. Errors are easily minimized.


Unlike with Wildcard Certificates, UCC SSL certificates may be used with Extended Verification (EV). In other words, visitors that view the SSL secured pages of your website will see a greed address bar on their browser. This will enhance the confidence of customers or clients when they use your website.

Are There Any Drawbacks?

Using UCC certificates does have some drawbacks. Security is the first that comes to mind. Only one private decryption key is used by all the servers that use a single UCC SSL certificate. Several servers usually host multiple domains. This means that if someone manages to compromise one of your servers and retrieve the decryption key, every on every server that uses the same certificate is also compromised.

If, for some reason, your UCC SSLCertificate is revoked, all domains will not work. That basically means that you have to close your website until you either get a new UCC certificate, or get a certificate for every single domain on your site.

Monday, 6 June 2011

VeriSign Trust Seals: Good for Business or Waste of Money?


For many consumers, the Internet is still considered the Wild, Wild West when it comes to making purchases, making it difficult for small businesses to drive traffic to their websites. In response, small businesses to add their sites to trust seals to help the customer concerns about security and legitimacy convenience.


These seals, offered by various antivirus software makers, including VeriSign and McAfee let consumers know that a site is genuine, no transactions are safe and free of malware. 

"There is a lot of fraudulent activity on the Web these days and consumers are aware of," said Tina Hou, senior product marketing manager for trust services at Symantec, which recently was acquired by VeriSign Identity Authentication and security. "People go to Amazon.com, because they know it's a relatively safe organization. Small businesses do not have that luxury." 

The internet is flooded with scams against hackers looking for people to steal information and it seems no company is off limits, regardless of size. Large companies have recently been the subject of attacks, but as a security breach happens to a small business, restoring trust is almost impossible. Many small businesses do not have the resources to public relations campaigns to launch and establish customer service helps the consumer. 

Trust not only seals a level of comfort to consumers online, but some also have a scan company website daily to identify any malware. 

RELATED LINKS do not Fall for these common mistakes IT when it comes to IT security, Offense Saves Companies "When people come to the site to see the seals and they know the site is a secure site to transact or leaves," said Hou. VeriSign's seal, Hou said that was viewed more than 650 million times a day and a small business will cost $ 299 per year. The stamp is also evident in search results on Google (NASDAQ: GOOG), Yahoo (NASDAQ: YHOO) Bing and some comparison shopping before Web surfers click on links. 

According to Hou, which VeriSign Trust Seal has the added benefit of preventing a small company on a blacklist on Google by catching all malware early. Google scans periodically all tags sites for malware and found websites to host malicious software, forcing users to click through a warning to the site - a devastating blow to a small business. 


Small businesses can choose from a variety of trust seals, including one from the Better Business Bureau and VeriSign has an SSL certificate that consumers know that a site is legitimate, and transactions. Regardless of the type, advises small businesses to keep the seal clearly visible on their websites and in any place that requires customer interaction, such as providing payment information. 

Do they work? 

Trust Seals give small businesses increased credibility, but does it translate into tangible results? According to Hou, Symantec introduced a number of studies with users of the VeriSign Seal and found that sites with a seal 25% increase in traffic on average saw.

According Cazoodle, which search engines is to shop, holiday homes and apartments, has seen an increase of 9.36% on the through traffic in the last eight months for companies whose results include the VeriSign seal.
"Trust is very important these days especially in relation to small businesses," says Hou.


Read more: http://smallbusiness.foxbusiness.com/technology-web/2011/05/27/trust-seals-good-business-waste-money/