Top Banner
In Headers/ Padlocks / site Seals / CA’s we trust !
86

In headers / Padlocks / Certificate authorities / site seals we trust

Apr 16, 2017

Download

Internet

pipasnacave
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: In headers / Padlocks / Certificate authorities / site seals we trust

In Headers/ Padlocks / site Seals / CA’s we trust !

Page 2: In headers / Padlocks / Certificate authorities / site seals we trust

Test my SSL site…

Page 3: In headers / Padlocks / Certificate authorities / site seals we trust

Certificate authorities…

Available online testing services

checking: - server headers - https cert instalations

Page 4: In headers / Padlocks / Certificate authorities / site seals we trust

Certificate authorities…

checking: - server headers - https cert instalations

Test my server please

Page 5: In headers / Padlocks / Certificate authorities / site seals we trust

Certificate authorities…

Test my server please

Page 6: In headers / Padlocks / Certificate authorities / site seals we trust

Certificate authorities… checking https / cert instalations

GeoTrust

GeoTrust, a leading certificate authority,

provides retail and reseller services for SSL encryption, and website authentication, digital

signatures, code signing, secure email, and enterprise SSL products

Page 7: In headers / Padlocks / Certificate authorities / site seals we trust

Certificate authorities… checking https / cert instalations

GeoTrust

Page 8: In headers / Padlocks / Certificate authorities / site seals we trust

Certificate authorities… checking https / cert instalations

GeoTrust

Page 9: In headers / Padlocks / Certificate authorities / site seals we trust

Certificate authorities… checking https / cert instalations

Server: header field :)

Page 10: In headers / Padlocks / Certificate authorities / site seals we trust

Certificate authorities… checking https / cert instalations

HSTS header field :)

Page 11: In headers / Padlocks / Certificate authorities / site seals we trust

Certificate authorities… checking https / cert instalations

HSTS header field :)

Page 12: In headers / Padlocks / Certificate authorities / site seals we trust

Certificate authorities… checking https / cert instalations

RapidSSL

RapidSSL is on a mission to help you secure your domain with SSL as fast as possible. We’ve

streamlined and automated every part of the enrollment and authentication processes

Page 13: In headers / Padlocks / Certificate authorities / site seals we trust

Certificate authorities… checking https / cert instalations

RapidSSL

Page 14: In headers / Padlocks / Certificate authorities / site seals we trust

Certificate authorities… checking https / cert instalations

Server: header field :)

Page 15: In headers / Padlocks / Certificate authorities / site seals we trust

Certificate authorities… checking https / cert instalations

HSTS header field :)

Page 16: In headers / Padlocks / Certificate authorities / site seals we trust

Certificate authorities… checking https / cert instalations

HSTS header field :)

Page 17: In headers / Padlocks / Certificate authorities / site seals we trust

Certificate authorities… checking https / cert instalations

Symantec

Cyber Security Services

Strengthen your security with our experts,

global threat intelligence, advanced monitoring, incident response, and cyber readiness services.

Page 18: In headers / Padlocks / Certificate authorities / site seals we trust

Certificate authorities… checking https / cert instalations

Symantec

Page 19: In headers / Padlocks / Certificate authorities / site seals we trust

Certificate authorities… checking https / cert instalations

Server: header field :)

Page 20: In headers / Padlocks / Certificate authorities / site seals we trust

Certificate authorities… checking https / cert instalations

HSTS header field :)

Page 21: In headers / Padlocks / Certificate authorities / site seals we trust

Certificate authorities… checking https / cert instalations

HSTS field :)

Page 22: In headers / Padlocks / Certificate authorities / site seals we trust

Certificate authorities… checking https / cert instalations

wait there must be something better…

Page 23: In headers / Padlocks / Certificate authorities / site seals we trust

Certificate authorities… checking https / cert instalations

Thawte

As a leading global certificate authority,

Thawte provides online security trusted by millions

around the world. Expert support, robust

authentication practices, and easy online management make Thawte the best value for SSL

certificates and code signing certificates.

Page 24: In headers / Padlocks / Certificate authorities / site seals we trust

Certificate authorities… checking https / cert instalations

Thawte

Page 25: In headers / Padlocks / Certificate authorities / site seals we trust

Certificate authorities… checking https / cert instalations

Server: header field :)

Page 26: In headers / Padlocks / Certificate authorities / site seals we trust

Certificate authorities… checking https / cert instalations

HSTS header field :)

Page 27: In headers / Padlocks / Certificate authorities / site seals we trust

Certificate authorities… checking https / cert instalations

HSTS header field :)

Page 28: In headers / Padlocks / Certificate authorities / site seals we trust

Certificate authorities… checking https / cert instalations

See a pattern here?

Page 29: In headers / Padlocks / Certificate authorities / site seals we trust

Certificate authorities… checking https / cert instalations

Security headers in apache2.conf

Page 30: In headers / Padlocks / Certificate authorities / site seals we trust

Certificate authorities… checking https / cert instalations

My Server Signature =)

It runs on ZxSpectrum !!

Page 31: In headers / Padlocks / Certificate authorities / site seals we trust

Certificate authorities… checking https / cert instalations

should i report this?…i’ve tried…

Page 32: In headers / Padlocks / Certificate authorities / site seals we trust

Certificate authorities… checking https / cert instalations

should i report this?…i’ve tried

Page 33: In headers / Padlocks / Certificate authorities / site seals we trust

Certificate authorities… checking https / cert instalations

should i report this?…i’ve tried

Page 34: In headers / Padlocks / Certificate authorities / site seals we trust

Certificate authorities… checking https / cert instalations

and…got a hit

Page 35: In headers / Padlocks / Certificate authorities / site seals we trust

Certificate authorities… checking https / cert instalations

and…got a hit

Page 36: In headers / Padlocks / Certificate authorities / site seals we trust

Certificate authorities… checking https / cert instalations

OK, now someone who really knows security…

Page 37: In headers / Padlocks / Certificate authorities / site seals we trust

Certificate authorities… checking https / cert instalations

OK, now someone who really knows security…

Page 38: In headers / Padlocks / Certificate authorities / site seals we trust

Certificate authorities… checking https / cert instalations

OK, now someone who really knows security…

Page 39: In headers / Padlocks / Certificate authorities / site seals we trust

Certificate authorities… checking https / cert instalations

OK, now someone who really knows security…

Page 40: In headers / Padlocks / Certificate authorities / site seals we trust

Certificate authorities… checking https / cert instalations

OK, now someone who really knows security…

Certificate fields: OU, CN, blah

Page 41: In headers / Padlocks / Certificate authorities / site seals we trust

Certificate authorities… checking https / cert instalations

OK, now someone who really knows security…

Page 42: In headers / Padlocks / Certificate authorities / site seals we trust

Certificate authorities… checking https / cert instalations

OK, now someone who really knows security…

Page 43: In headers / Padlocks / Certificate authorities / site seals we trust

Certificate authorities… checking https / cert instalations

OK, now someone who really knows security…

Page 44: In headers / Padlocks / Certificate authorities / site seals we trust

Certificate authorities… checking https / cert instalations

OK, now someone who really knows security…

Page 45: In headers / Padlocks / Certificate authorities / site seals we trust

Certificate authorities… checking https / cert instalations

OK, now someone who really knows security…

Page 46: In headers / Padlocks / Certificate authorities / site seals we trust

Certificate authorities… checking https / cert instalations

OK, now RapidSSLonline.com

Now, let’s check the CSR checking service

Page 47: In headers / Padlocks / Certificate authorities / site seals we trust

OK, now RapidSSLonline.com

Page 48: In headers / Padlocks / Certificate authorities / site seals we trust

OK, now RapidSSLonline.com

Page 49: In headers / Padlocks / Certificate authorities / site seals we trust

OK, now RapidSSLonline.com

CSR email field

Page 50: In headers / Padlocks / Certificate authorities / site seals we trust

OK, back to RapidSSLonline.com

OK, i’ve tried to report… and got this mail…

Page 51: In headers / Padlocks / Certificate authorities / site seals we trust

OK, back to RapidSSLonline.com

OK, i’ve tried to report… and got this mail…

Page 52: In headers / Padlocks / Certificate authorities / site seals we trust

https://sslshopper.com Both tests:

SSL checker / server header CSR decoder

Page 53: In headers / Padlocks / Certificate authorities / site seals we trust

https://sslshopper.com Both tests:

SSL checker / server header CSR decoder

Page 54: In headers / Padlocks / Certificate authorities / site seals we trust

https://sslshopper.com

Page 55: In headers / Padlocks / Certificate authorities / site seals we trust

https://sslshopper.com

Page 56: In headers / Padlocks / Certificate authorities / site seals we trust

https://sslshopper.com

Page 57: In headers / Padlocks / Certificate authorities / site seals we trust

https://sslshopper.com

Page 58: In headers / Padlocks / Certificate authorities / site seals we trust

https://sslshopper.com

Page 59: In headers / Padlocks / Certificate authorities / site seals we trust

https://sslshopper.com -> private key?? what ??

Page 60: In headers / Padlocks / Certificate authorities / site seals we trust

Let’s try “European leader in website security…”

Page 61: In headers / Padlocks / Certificate authorities / site seals we trust

Let’s try “European leader in website security…”

Page 62: In headers / Padlocks / Certificate authorities / site seals we trust

Let’s try “European leader in website security…”

Page 63: In headers / Padlocks / Certificate authorities / site seals we trust

Let’s try “European leader in website security…”

Page 64: In headers / Padlocks / Certificate authorities / site seals we trust

Let’s try “European leader in website security…”

Page 65: In headers / Padlocks / Certificate authorities / site seals we trust

Let’s try “European leader in website security…”

Page 66: In headers / Padlocks / Certificate authorities / site seals we trust

Let’s try “European leader in website security…”

Page 67: In headers / Padlocks / Certificate authorities / site seals we trust

Let’s try “European leader in website security…”

Page 68: In headers / Padlocks / Certificate authorities / site seals we trust

Let’s try “European leader in website security…”

Page 69: In headers / Padlocks / Certificate authorities / site seals we trust

Let’s try “European leader in website security…”

Page 70: In headers / Padlocks / Certificate authorities / site seals we trust

Let’s try “European leader in website security…”

Page 71: In headers / Padlocks / Certificate authorities / site seals we trust

Let’s try “European leader in website security…”

Page 72: In headers / Padlocks / Certificate authorities / site seals we trust

OK, now some other sites:

Page 73: In headers / Padlocks / Certificate authorities / site seals we trust

OK, other sites:

Page 74: In headers / Padlocks / Certificate authorities / site seals we trust

OK, other sites:

Page 75: In headers / Padlocks / Certificate authorities / site seals we trust

OK, other sites:

Page 76: In headers / Padlocks / Certificate authorities / site seals we trust

OK, other sites:

Page 77: In headers / Padlocks / Certificate authorities / site seals we trust

OK, other sites:

Page 78: In headers / Padlocks / Certificate authorities / site seals we trust

OK, other sites:

Page 79: In headers / Padlocks / Certificate authorities / site seals we trust

OK, other sites:

Page 80: In headers / Padlocks / Certificate authorities / site seals we trust

OK, other sites:

Page 81: In headers / Padlocks / Certificate authorities / site seals we trust

OK, other sites: private key??

Page 82: In headers / Padlocks / Certificate authorities / site seals we trust

OK, other sites: CDN

KEYCDN also offers a great test

Page 83: In headers / Padlocks / Certificate authorities / site seals we trust

OK, other sites: CDN

Page 84: In headers / Padlocks / Certificate authorities / site seals we trust

OK, other sites: CDN

Page 85: In headers / Padlocks / Certificate authorities / site seals we trust

OK, other sites: CDN

Page 86: In headers / Padlocks / Certificate authorities / site seals we trust

The End