SlideShare una empresa de Scribd logo
1 de 16
Descargar para leer sin conexión
TLS i praktiken
En vansinnig utmaning för demo-djävulen…
Anslutning
KLIENT SERVER
Hello!
Hello!
ID-kort (certifikat)
Kan jag lita på det
här?
Kolla certifikat
Litar jag på utfärdaren?
Är den som ger mig certifikatet

rätt innehavare?
Är det rätt server för det jag försöker
ansluta mig till?
Behöver jag veta?
Säker anslutningOpportunistisk anslutning
ABSOLUT.Nej.
Gubbtjuv i mitten
KLIENT SERVERGubbtjuv
Lyssnar på

all kommunikation.

Klartext.
Tror att hen har

en säker anslutning.
Tror att användaren har

en säker anslutning.
TLS TLS
Test #1 - okänd
certifikatutfärdare
https://test1.tls-o-matic.com
FEL! RÄTT
Installera certifikat från 

http://www.tls-o-matic.com/ca

och testa igen!
Test #2 - fel servernamn
https://test2.tls-o-matic.com:402
FEL!
Test #3 - fel servernamn i
alternativ-listan (SAN)
https://test3.tls-o-matic.com:403
FEL!
Test #4 - jokercertifikat

(wildcard)
https://test4.tls-o-matic.com:404

https://test4test.tls-o-matic.com:404
RÄTT
Test #5- ännu ej giltigt
certifikat
https://test5.tls-o-matic.com:405
FEL!
Test #6- historiskt certifikat

(ej längre giltigt)
https://test6.tls-o-matic.com:406
FEL!
Test #7- Ogiltig utfärdare
https://test7.tls-o-matic.com:407
FEL!
Test #8- Dubbelsidig
identifiering
https://test8.tls-o-matic.com:408
FEL!
Test #9- Mycket svagt
certifikat
https://test9.tls-o-matic.com:409
FEL!
Test #10 & #11-
Certifikatkedja
https://test10.tls-o-matic.com:410
RÄTT
https://test11.tls-o-matic.com:411
Kör själv, testa din
applikation
www.tls-o-matic.com

Más contenido relacionado

Destacado

Steve Vinoski Rest And Reuse And Serendipity
Steve Vinoski Rest And Reuse And SerendipitySteve Vinoski Rest And Reuse And Serendipity
Steve Vinoski Rest And Reuse And Serendipity
deimos
 
Webcasting In The Efl Class 1
Webcasting In The Efl Class 1Webcasting In The Efl Class 1
Webcasting In The Efl Class 1
cristiarnau
 
APG Awards: Tate Tracks
APG Awards: Tate TracksAPG Awards: Tate Tracks
APG Awards: Tate Tracks
Matt Springate
 
Newcomers Breakfast
Newcomers BreakfastNewcomers Breakfast
Newcomers Breakfast
Terri Bays
 

Destacado (19)

Poesia Seria
Poesia SeriaPoesia Seria
Poesia Seria
 
May Ttf Lts 18 Th March 2009
May Ttf Lts 18 Th March 2009May Ttf Lts 18 Th March 2009
May Ttf Lts 18 Th March 2009
 
Italia
ItaliaItalia
Italia
 
Test De Memorie
Test De MemorieTest De Memorie
Test De Memorie
 
Steve Vinoski Rest And Reuse And Serendipity
Steve Vinoski Rest And Reuse And SerendipitySteve Vinoski Rest And Reuse And Serendipity
Steve Vinoski Rest And Reuse And Serendipity
 
Sesion 1
Sesion 1Sesion 1
Sesion 1
 
Webcasting In The Efl Class 1
Webcasting In The Efl Class 1Webcasting In The Efl Class 1
Webcasting In The Efl Class 1
 
電腦作業
電腦作業電腦作業
電腦作業
 
APG Awards: Tate Tracks
APG Awards: Tate TracksAPG Awards: Tate Tracks
APG Awards: Tate Tracks
 
Funcion Finanzas
Funcion FinanzasFuncion Finanzas
Funcion Finanzas
 
Libraries in a Transliterate, Technology Fluent World
Libraries in a Transliterate, Technology Fluent World Libraries in a Transliterate, Technology Fluent World
Libraries in a Transliterate, Technology Fluent World
 
Newcomers Breakfast
Newcomers BreakfastNewcomers Breakfast
Newcomers Breakfast
 
Blogging Best practices: 40 tips in 40 minutes
Blogging Best practices: 40 tips in 40 minutesBlogging Best practices: 40 tips in 40 minutes
Blogging Best practices: 40 tips in 40 minutes
 
Weaving Your Marketing Loose Ends into a Tight Plan
Weaving Your Marketing Loose Ends into a Tight PlanWeaving Your Marketing Loose Ends into a Tight Plan
Weaving Your Marketing Loose Ends into a Tight Plan
 
Last day
Last dayLast day
Last day
 
Search and Social Media
Search and Social MediaSearch and Social Media
Search and Social Media
 
Gestión de configuración con mercurial y etckeeper
Gestión de configuración con mercurial y etckeeperGestión de configuración con mercurial y etckeeper
Gestión de configuración con mercurial y etckeeper
 
The road to hell is paved with cut and paste
The road to hell is paved with cut and pasteThe road to hell is paved with cut and paste
The road to hell is paved with cut and paste
 
Writing for leads: How professionals can market themselves online
Writing for leads: How professionals can market themselves onlineWriting for leads: How professionals can market themselves online
Writing for leads: How professionals can market themselves online
 

Más de Olle E Johansson

Más de Olle E Johansson (20)

Cybernode.se: Securing the software supply chain (CRA)
Cybernode.se: Securing the software supply chain (CRA)Cybernode.se: Securing the software supply chain (CRA)
Cybernode.se: Securing the software supply chain (CRA)
 
CRA - overview of vulnerability handling
CRA - overview of vulnerability handlingCRA - overview of vulnerability handling
CRA - overview of vulnerability handling
 
Introduction to the proposed EU cyber resilience act (CRA)
Introduction to the proposed EU cyber resilience act (CRA)Introduction to the proposed EU cyber resilience act (CRA)
Introduction to the proposed EU cyber resilience act (CRA)
 
The birth and death of PSTN
The birth and death of PSTNThe birth and death of PSTN
The birth and death of PSTN
 
WebRTC and Janus intro for FOSS Stockholm January 2019
WebRTC and Janus intro for FOSS Stockholm January 2019WebRTC and Janus intro for FOSS Stockholm January 2019
WebRTC and Janus intro for FOSS Stockholm January 2019
 
Kamailio World 2018: Having fun with new stuff
Kamailio World 2018: Having fun with new stuffKamailio World 2018: Having fun with new stuff
Kamailio World 2018: Having fun with new stuff
 
Kamailio on air
Kamailio on airKamailio on air
Kamailio on air
 
Webrtc overview
Webrtc overviewWebrtc overview
Webrtc overview
 
Realtime communication over a dual stack network
Realtime communication over a dual stack networkRealtime communication over a dual stack network
Realtime communication over a dual stack network
 
The Realtime Story - part 2
The Realtime Story - part 2The Realtime Story - part 2
The Realtime Story - part 2
 
Sip2016 - a talk at VOIP2DAY 2016
Sip2016 - a talk at VOIP2DAY 2016Sip2016 - a talk at VOIP2DAY 2016
Sip2016 - a talk at VOIP2DAY 2016
 
Sips must die, die, die - about TLS usage in the SIP protocol
Sips must die, die, die - about TLS usage in the SIP protocolSips must die, die, die - about TLS usage in the SIP protocol
Sips must die, die, die - about TLS usage in the SIP protocol
 
SIP :: Half outbound (random notes)
SIP :: Half outbound (random notes)SIP :: Half outbound (random notes)
SIP :: Half outbound (random notes)
 
Kamailio World 2016: Update your SIP!
Kamailio World 2016: Update your SIP!Kamailio World 2016: Update your SIP!
Kamailio World 2016: Update your SIP!
 
SIP & TLS - Security in a peer to peer world
SIP & TLS - Security in a peer to peer worldSIP & TLS - Security in a peer to peer world
SIP & TLS - Security in a peer to peer world
 
2015 update: SIP and IPv6 issues - staying Happy in SIP
2015 update: SIP and IPv6 issues - staying Happy in SIP2015 update: SIP and IPv6 issues - staying Happy in SIP
2015 update: SIP and IPv6 issues - staying Happy in SIP
 
TCP/IP Geeks Stockholm :: Introduction to IPv6
TCP/IP Geeks Stockholm :: Introduction to IPv6TCP/IP Geeks Stockholm :: Introduction to IPv6
TCP/IP Geeks Stockholm :: Introduction to IPv6
 
Why is Kamailio so different? An introduction.
Why is Kamailio so different? An introduction.Why is Kamailio so different? An introduction.
Why is Kamailio so different? An introduction.
 
RFC 7435 - Opportunistic security - Some protection most of the time
RFC 7435 - Opportunistic security - Some protection most of the timeRFC 7435 - Opportunistic security - Some protection most of the time
RFC 7435 - Opportunistic security - Some protection most of the time
 
SIP and DNS - federation, failover, load balancing and more
SIP and DNS - federation, failover, load balancing and moreSIP and DNS - federation, failover, load balancing and more
SIP and DNS - federation, failover, load balancing and more
 

Tio tester av TLS - Transport Layer Security (TLS-O-MATIC.COM)