Presentation is loading. Please wait.

Presentation is loading. Please wait.

Alpha Five User Group, Bill Parker, SSL Security and WAS, July 2007 SSL Security with Alpha Five App Server Protecting sensitive or personal data.

Similar presentations


Presentation on theme: "Alpha Five User Group, Bill Parker, SSL Security and WAS, July 2007 SSL Security with Alpha Five App Server Protecting sensitive or personal data."— Presentation transcript:

1 Alpha Five User Group, Bill Parker, SSL Security and WAS, July 2007 SSL Security with Alpha Five App Server Protecting sensitive or personal data.

2 Alpha Five User Group, Bill Parker, SSL Security and WAS, July 2007 Types of Web Pages Unsecure Plain Text http:// Secure – SSL (secure sockets layer) TLS (transport layer security) Encrypted between browser and server https://

3 Alpha Five User Group, Bill Parker, SSL Security and WAS, July 2007 Other Types of Secure Web Communications in Alpha Email – digitally signed and encrypted. Must use routines external to Alpha. Encrypt a Zip attachment to email. SSL/TLS Email – from web server to mail server only. Not to recipient’s inbox.

4 Alpha Five User Group, Bill Parker, SSL Security and WAS, July 2007 SSL Decisions What Certification Authority What Type of Certificate What Encryption Level What Type of Browsers and Web Servers

5 Alpha Five User Group, Bill Parker, SSL Security and WAS, July 2007 Certification Authority Trusted 3 rd Party They do the verification of the SSL application GoDaddy Thawte GeoTrust Verisign others

6 Alpha Five User Group, Bill Parker, SSL Security and WAS, July 2007 Types of Certificates Self-Signed – free Turbo – ($20 - $149) High Assurance – ($90 - $400) Extended Validation – gets a green address bar in Vista. – ($500 - $1,500) (low rates are for GoDaddy)

7 Alpha Five User Group, Bill Parker, SSL Security and WAS, July 2007 Encryption Level 40-bit 512-bit* 1024-bit* - used by most financial institutions 2048-bit* * supported by Alpha Application Server

8 Alpha Five User Group, Bill Parker, SSL Security and WAS, July 2007 Browser and Web Server Export restriction on 128-bit encryption lifted in 2000. Modern browsers (IE 5.5+) support 128-bit encryption. Modern web servers support 128-bit encryption. Notes on older operating systems and SGC (Server-Gated Cryptography)

9 Alpha Five User Group, Bill Parker, SSL Security and WAS, July 2007 How to do it 1) Create a certificate request from the Alpha Application Server settings screen. 2) Send the request to a Certification Authority and get back a certificate file 3) Install the key (created in #1) and certificate files in the Alpha App Server 4) Insure that port 443 is open in firewall and router

10 Alpha Five User Group, Bill Parker, SSL Security and WAS, July 2007 How to do it (cont.) 5) URL links must use https://

11 Alpha Five User Group, Bill Parker, SSL Security and WAS, July 2007 If a Security Warning Pops Up in the Browser Insure that the URL specified in the CSR matches exactly Always happens with a Self-Signed certificate

12 Alpha Five User Group, Bill Parker, SSL Security and WAS, July 2007 Using a Self-Signed Cert or if info does not match

13 Alpha Five User Group, Bill Parker, SSL Security and WAS, July 2007 Demo – before Cert request

14 Alpha Five User Group, Bill Parker, SSL Security and WAS, July 2007 Demo – Certificate Signing Request (CSR)

15 Alpha Five User Group, Bill Parker, SSL Security and WAS, July 2007 Demo – CSR Result

16 Alpha Five User Group, Bill Parker, SSL Security and WAS, July 2007 Demo – Cert Installed

17 Alpha Five User Group, Bill Parker, SSL Security and WAS, July 2007 Demo - live

18 Alpha Five User Group, Bill Parker, SSL Security and WAS, July 2007 Links http://luxsci.com/info/about_ssl.html - See section on SSL in Action http://luxsci.com/info/about_ssl.html Wikipedia – more technical Wikipedia GoDaddy Certs – describes different Cert levels GoDaddy Certs


Download ppt "Alpha Five User Group, Bill Parker, SSL Security and WAS, July 2007 SSL Security with Alpha Five App Server Protecting sensitive or personal data."

Similar presentations


Ads by Google