ssl certificates for secure websites dan roberts kent network users group wednesday, 17 march 2004

11
SSL Certificates SSL Certificates for Secure Websites for Secure Websites Dan Roberts Kent Network Users Group Wednesday, 17 March 2004

Upload: bridget-ford

Post on 18-Jan-2016

212 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: SSL Certificates for Secure Websites Dan Roberts Kent Network Users Group Wednesday, 17 March 2004

SSL CertificatesSSL Certificatesfor Secure Websitesfor Secure Websites

Dan Roberts

Kent Network Users Group

Wednesday, 17 March 2004

Page 2: SSL Certificates for Secure Websites Dan Roberts Kent Network Users Group Wednesday, 17 March 2004

Two Features of Two Features of SSL Website SecuritySSL Website Security

Encrypted data channel for privacy

SSL certificate for identity verification– Is the organization who it claims to be?– Is this a legitimate company?

Page 3: SSL Certificates for Secure Websites Dan Roberts Kent Network Users Group Wednesday, 17 March 2004

Website withWebsite withCA-signed SSL CertificateCA-signed SSL Certificate

“I am wfs.kent.edu.. you can verify my identity with VeriSign.”

Through your browser’s pre-established trust relationship with VeriSign, you automatically trust anyone who presents one of their certificates.

Page 4: SSL Certificates for Secure Websites Dan Roberts Kent Network Users Group Wednesday, 17 March 2004

Website withWebsite withSelf-signed SSL CertificateSelf-signed SSL Certificate

“I am webmail.kent.edu.. you can verify my identity with webmail.kent.edu”

Since there is no pre-existing trust relationship with webmail.kent.edu in your browser, a security alert message appears.

Page 5: SSL Certificates for Secure Websites Dan Roberts Kent Network Users Group Wednesday, 17 March 2004

Self-signed SSL CertificatesSelf-signed SSL Certificates

Free and unlimited supplyOnly trust relationship between users and

server already existsUse for:

– Internal development– Intranet applications

Page 6: SSL Certificates for Secure Websites Dan Roberts Kent Network Users Group Wednesday, 17 March 2004

Self-signed SSL CertificatesSelf-signed SSL Certificates

Kent has its own self-signing Certification Authority (CA) at http://cert.kent.edu– Installed on growing number of campus PCs

Certificate signing requests can be submitted to Greg Dykes or Dan Roberts

Page 7: SSL Certificates for Secure Websites Dan Roberts Kent Network Users Group Wednesday, 17 March 2004

CA-signed SSL CertificatesCA-signed SSL Certificates

Expensive (VeriSign $250-$400/cert per yr)Useful when trust is not a given

– Allows user to verify your identity– Eliminates warning message

Use for:– Public-facing web sites– Transactions involving commerce and/or

exchange of personal information

Page 8: SSL Certificates for Secure Websites Dan Roberts Kent Network Users Group Wednesday, 17 March 2004

Alternative to VeriSignAlternative to VeriSign

GeoTrust– Trusted root certification authority– Same pre-established trust as VeriSign– Managed PKI services with certificate request

processing tools for supporting constituents– Less cost (less than $150/cert per year)– Quantity and multi-year discounts available– Website: http://www.geotrust.com

Page 9: SSL Certificates for Secure Websites Dan Roberts Kent Network Users Group Wednesday, 17 March 2004

GeoTrust’s CA certificateGeoTrust’s CA certificateGeoTrust’s CA certificate has 99.9% browser penetration, GeoTrust’s CA certificate has 99.9% browser penetration, and appears in your computer’s Trusted Root Certification and appears in your computer’s Trusted Root Certification Authority container as “Equifax”Authority container as “Equifax”

Page 10: SSL Certificates for Secure Websites Dan Roberts Kent Network Users Group Wednesday, 17 March 2004

DiscussionDiscussion

University-wide opportunity to lower costs and centralize certificate management– Use self-signed certificates internally– Use alternate CA for public-facing sites

Concerns? Questions? Suggestions?Interested in participating?

Page 11: SSL Certificates for Secure Websites Dan Roberts Kent Network Users Group Wednesday, 17 March 2004

Contact InformationContact Information

Dan Roberts

Administrative Computing Services

[email protected]

330-672-5373