• No results found

Multiple SSL Certificates on a single IP address without losing any backward compatibility

N/A
N/A
Protected

Academic year: 2021

Share "Multiple SSL Certificates on a single IP address without losing any backward compatibility"

Copied!
26
0
0

Loading.... (view fulltext now)

Full text

(1)

Authentication. Security. Trust.

Multiple SSL Certificates on a single IP

address

(2)

www.globalsign.com

Authentication. Security. Trust.

Business Development Director

Business Development Director for

GlobalSign

Previously CTO of a European hosting

company

Over 10 years of

experience in the

hosting industry

Expert in digital certificate solutions

Dedicated to increasing awareness of

the requirements for online security

Thinking out of the box, detecting

problems and providing solutions

(3)

INTERNATIONAL FOOTPRINT

Customers spanning all industries

(4)

www.globalsign.com

Authentication. Security. Trust.

(5)

Digital Certificates in practice

SSL

Encryption &

Identity

Assurance

Secure

Email

Adobe PDF &

Microsoft

Office

document

security

(6)

www.globalsign.com

Authentication. Security. Trust.

(7)

Multiple

SSL Certificates

on a

single IP address

(8)

www.globalsign.com

Authentication. Security. Trust.

More demands and requirements for SSL

Article 17 of Directive 95/46/EC of the European Parliament

Security of processing

Member States shall provide that the controller

must implement

appropriate

technical

and

organizational measures

to protect personal data

against accidental or unlawful destruction or

accidental

loss, alteration

, unauthorized disclosure or

access

, in particular where the processing involves the

transmission of data over a network

, and against all other unlawful forms of processing. Having

regard to the state of the art and the cost of their implementation, such measures shall ensure a level of security appropriate

to the risks represented by the processing and the nature of the data to be protected.

(9)
(10)

www.globalsign.com

Authentication. Security. Trust.

Why do I need a

(11)

Request for a secure connection

74.125.136.103 : 443

www.google.com

1

2

3

4

5

- www.google.co.uk

- www.google.gr

- www.google.com

- www.google.fr

- www.google.de

www.google.com

(12)

www.globalsign.com

Authentication. Security. Trust.

All versions of Internet Explorer on Windows XP

Android 2.x [Gingerbread] default browser (other

browsers like Opera do support SNI on Android)

BlackBerry Browser

Windows Mobile up to 6.5

(13)
(14)

www.globalsign.com

Authentication. Security. Trust.

(15)

28% of 21% =

5.8%

Internet Explorer Windows XP

+ mobile traffic

=

Or 8% of your world wide visitors?

8%

of worldwide internet users

do not support Server Name

(16)

www.globalsign.com

Authentication. Security. Trust.

What are the alternative

solutions?

(17)

One SSL Certificate for multiple

domain names from different

organisations.

The certificate contains the

hosting company’s details.

Domain control is verified for

each domain.

Private key accessible by server

or network administrator with

(18)

www.globalsign.com

Authentication. Security. Trust.

Performance of multi-domain certificates

750 names:

716 ms

450 names:

518 ms

1 name:

198 ms

(19)

Every

100ms

delay

costs

1% of sales

(20)

www.globalsign.com

Authentication. Security. Trust.

No support for OV, EV

One certificate shared by

many websites

Many hostnames are

visible in the certificate

Visitor needs to

download a bigger

certificate (slower)

(21)

What if we could use the

best of both solutions?

92% SNI

(22)

www.globalsign.com

Authentication. Security. Trust.

SNI combined with CloudSSL

User requests website

(23)

No additional costs

Sites can use all types of certificates (including EV)

One SSL Certificate installed via the regular way, a

second SSL Certificate (one per IP) can be updated

automatically.

No need for DNS updates

(24)

www.globalsign.com

Authentication. Security. Trust.

How does it work?

1

2

3

(25)
(26)

www.globalsign.com

Authentication. Security. Trust.

Thank you!

Please come to our

booth

for a

Live Demo

Paul van Brouwershaven

References

Related documents

Commercial aircraft programs inventory included the following amounts related to the 747 program: $448 of deferred production costs at December 31, 2011, net of previously

UPnP Control Point (DLNA) Device Discovery HTTP Server (DLNA, Chormecast, AirPlay Photo/Video) RTSP Server (AirPlay Audio) Streaming Server.. Figure 11: Simplified

For the poorest farmers in eastern India, then, the benefits of groundwater irrigation have come through three routes: in large part, through purchased pump irrigation and, in a

(i) In TFDE any new data file created by user or temporary files, cache files, backup files etc created by operating system or application software are not encrypted

National Conference on Technical Vocational Education, Training and Skills Development: A Roadmap for Empowerment (Dec. 2008): Ministry of Human Resource Development, Department

The projected gains over the years 2000 to 2040 in life and active life expectancies, and expected years of dependency at age 65for males and females, for alternatives I, II, and

Using a likert scale reading interest survey, a released SOL reading comprehension test, and teacher observations data were collected to determine if independent choice in a