SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Government >> Human Resources

Web security service simplifies SSL issues

Web security service simplifies SSL issues

By:  Mark Els  On: 19 Jan 2006 For: Network World Canada Creator

Drill down deep enough and secure sockets layer (SSL) encryption, with its public key infrastructure (PKI) at the core, will strike most as a complex, intricate technology.

Drill down deep enough and secure sockets layer (SSL) encryption, with its public key infrastructure (PKI) at the core, will strike most as a complex, intricate technology.

Less cryptic is that the more effort a vendor puts in to making a product easier to use, the more attractive that product becomes to users. Toronto-based Soltrus Inc. recently announced four significant upgrades to its SSL security services, or Managed PKI for SSL platforms.

PKI for SSL may not be the sexiest technology around, but since it’s an intrinsic feature of a trusted e-commerce Web site, SSL certificates are no trifle for large enterprises. In an e-commerce transaction, bank account or credit card numbers are encrypted so that no one who’s spoofing or spying on the Internet can capture that information. Sensitive data sent to a Web server needs to be encrypted.

SSL enables a domain name attached to a server (a Web site) to speak to the browser on a laptop or PC in a unique encrypted session, using PKI technology. SSL uses PKI to exchange public and private encrypted keys. These keys require a certificate authority for authentication, which is where Soltrus steps in with its SSL certificates from Verisign Inc. and Managed PKI for SSL service.

“When you type in www.bmo.com or cibc.com, your browser communicates with the domain server and asks for a certificate, embedded in the Web page,” says Anthony Santilli, vice-president of marketing for Soltrus, a Canadian affiliate of Mountain View, Calif.-based Verisign.

“If it is a trusted certificate, a secure SSL session will be set up. Verisign acts as a password agency that digitally stamps the certificates to authorize trust in the authenticity of the encrypted session.”

Once the certificate has been issued, the client downloads SSL software to run on their servers to enable the encryption.

Updates announced last month include two-year validity for the SSL certificates, an improved control panel for the Web-based management services, the ability to revoke and reissue the same certificate to a domain name, as well as discounted rates for bulk buying.

Certificates are now simpler to manage and the service is more cost effective, says Rashid Niazi, a network analyst for Itergy Consulting Inc., a Montreal-based firm that specializes in Active Directory infrastructure.

Niazi says he’s able to manage certificates centrally, instead of everyone going out and making their own purchase orders.

“With a pack of 10, we can assign the certificate directly to the user and then bill back the business unit accordingly afterwards,” he says. “As an end user it’s a lot easier to manage everything.”

Ordering and issuing certificates now takes minutes instead of weeks. Niazi says he assigned three new certificates in only 15 minutes. “That’s usually a two-week process,” he says.

“It’s a lot less painstaking because I don’t have to chase after people and get purchase orders made up. Now all I do is log in, put in the information for the certificate, push it through to Verisign and they send me an e-mail back.”


Sign up for our Newsletters












Print |  Views: 1194   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Mark Els Mark Els is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

New network skills: Certificate administration
New network skills: Certificate administrationThe costs of using an external certificate authority can add up, but few companies can afford a dedicated certificate administrator
Users urged to patch serious hole in BIND 9 DNS server
Users urged to patch serious hole in BIND 9 DNS serverA security researcher has reported a serious vulnerability in BIND 9, the software widely used in the Internet’s DNS addressing system.
Qantas site hits turbulence, firewall to blame
Qantas site hits turbulence, firewall to blameQantas may be flying high following its proposed A$11 billion (US$8.6 billion) takeover by Macquarie Bank Ltd. and Texas Pacific Group Ventures Inc., but faulty server hardware on its Web site has ensured it has come crashing down to reality.
Your predictions for 2008
we've had our say ... now it's your turn. what will turn the tech industry on its head in 2008? who's buying whom? what's hot and what's hype? share your predictions for the coming year in the comment roll below.

Comments (0)

No Comments!
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.