Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Mozilla, in partnership with Facebook, Cloudflare, and other IETF community members, has announced technical specifications for a new cryptographic protocol called "Delegated Credentials for TLS." Delegated Credentials for TLS is a new simplified way to implement "short-lived" certificates without sacrificing the reliability of secure connections. Learn more about Delegated Credentials for TLS in an informative The Hacker News article: . In short, the new TLS protocol extension aims to effectively prevent the misuse of stolen certificates by reducing their maximum validity period to a very short span of time, such as a few days or even hours. Before jumping into how Delegated Credentials for TLS works, you need to understand the current TLS infrastructure, and of course, about the core problem in it because of which we need Delegated Credentials for TLS. The link for this article located at The Hacker News is no longer available. . Uncover the advantages of Utilizing Delegated Credentials in TLS to bolster security through diminished certificate lifespan for reinforced safeguarding.. Delegated Credentials,TLS Security,Short-Lived Certificates,Cryptographic Protocol,Certificate Management. . LinuxSecurity.com Team
Customers of HTTPS certificate reseller Trustico are reeling after being told their website security certs – as many as 23,000 – will be rendered useless within the next 24 hours. . This is allegedly due to a security blunder in which the private keys for said certificates ended up in an email sent by Trustico. Those keys are supposed to be secret, and only held by the cert owners, and certainly not to be disclosed in messages. In the wrong hands, they can be used by malicious websites to masquerade as legit operations.. This is allegedly due to a security blunder in which the private keys for said certificates ended up. customers, https, certificate, reseller, trustico, reeling, being, their, website, security. . LinuxSecurity.com Team
Secure Sockets Layer is a standard mechanism websites use to help secure data and transactions, but according to Qualys security researcher Ivan Ristic, most SSL sites are actually misconfigured. Ristic delivered his study here at the Black Hat security conference as an update to the preliminary data he published last month. . In the final study, Ristic said he examined 867,000 SSL certificates in which the name on the certificate matched the name of the domain. In his preliminary research, Ristic documented that the vast majority -- nearly 97 percent -- of SSL certificates do not have the proper name on them and don't match the underlying domain. The link for this article located at eSecurity Planet is no longer available. . Research indicates that a significant number of SSL certificates are improperly set up, jeopardizing security measures and online exchanges.. SSL Configuration, Certificate Management, Vulnerability Awareness. . LinuxSecurity.com Team
Revoking a digital certificate does not automatically invalidate, for instance, software signatures that have been made with this certificate. What matters is the revocation date, which determines the point in time after which a signature will no longer be validated. . According to a report from anti-virus specialist Norman, the signatures of several recently discovered trojans were validated by Windows as a result, and no warning was issued before installing the malware. The trojans were signed with a key that had been stolen from a Japanese company. The corresponding certificate was reported as compromised on 29 July 2011 and revoked by its issuing Certificate Authority (CA), VeriSign, which is now part of Symantec. However, that date was also entered as the revocation date. The link for this article located at H Security is no longer available. . According to a report from anti-virus specialist Norman, the signatures of several recently discover. revoking, digital, certificate, automatically, invalidate, instance, software, signatures. . LinuxSecurity.com Team
Red Hat has unveiled an initiative dubbed 'Security in a Networked World' at the LinuxWorld tradeshow in San Francisco. As part of the programme, the Linux vendor showcased its Red Hat Certificate System that allows organisations to manage security certificates used to sign emails, or authenticate users for online banking applications. It also supports authentication through the use of smartcards. Red Hat has been working with the Apache Foundation to add support for the Firefox browser and Thunderbird email client through the use of Apache's open source Network Security Service Libraries. . The collaboration will allow users of both systems to send and receive authenticated emails with Thunderbird, while organisations including online banks and web stores can use the system to authenticate users through smartcards in combination with Firefox. The link for this article located at VNUNet is no longer available. . The collaboration will allow users of both systems to send and receive authenticated emails with Thu. unveiled, initiative, dubbed, 'security, networked, world', linuxworld, tradesho. . LinuxSecurity.com Team
Public-key infrastructure technology was once so cool. Its combination of encryption, digital certificates and other technologies appeared to be a foolproof way to ensure the security of electronic transactions. It gave agencies the tools they needed to replace paper documents with . . . . Public-key infrastructure technology was once so cool. Its combination of encryption, digital certificates and other technologies appeared to be a foolproof way to ensure the security of electronic transactions. It gave agencies the tools they needed to replace paper documents with electronic ones and paved the way for electronic government. Sometimes, though, when organizations look more closely at deploying PKI, the technology loses its allure. Instead of finding a universal remedy, many agencies have become mired in the taxing policy and technical issues that come with PKI. Encryption techniques rely on randomly generated keys that must be mapped to user identities using digitally signed documents called certificates. Managing those certificates -- developing policies and processes to issue and revoke them efficiently -- is an enormously complex and expensive task that has hampered many agency efforts to build their own PKIs. The infrastructure required to effectively deploy a PKI must include the processes involved in looking up certificates for encryption and maintaining certificate revocation lists for users who have left an agency or are otherwise no longer authorized to use the certificate. The link for this article located at FCW is no longer available. . Public-key infrastructure technology was once so cool. Its combination of encryption, digital certif. public-key, infrastructure, technology, combination, encryption, digital, certif. . Anthony Pell
Your company is negotiating a big deal with a partner, making you a bit nervous about the security of exchanging documents via email. There is a non-disclosure agreement in place, but you'd like to be absolutely certain that only the recipients can see the plans for your company's new product initiative.. . .. Your company is negotiating a big deal with a partner, making you a bit nervous about the security of exchanging documents via email. There is a non-disclosure agreement in place, but you'd like to be absolutely certain that only the recipients can see the plans for your company's new product initiative. When the partner emails their agreement to the final version of the proposed deal, you also want to be able to prove absolutely that the email really is from them. Is there a proven technology that can fulfill both needs? Public Key Infrastructure (PKI) can handle these requirements and more. You may already be using PKI without knowing it if you have relied on certificates or "certs" to identify a web server or to confirm the identity of external websites. It is a critical technology for the Internet and is used in applications as diverse as e-commerce and VPNs. Let's explore the world of PKI cryptography to learn about keys, signatures, and certificates, and to see how PKI can benefit you and protect your company's valuable digital assets. The link for this article located at is no longer available. . Your company is negotiating a big deal with a partner, making you a bit nervous about the security o. company, negotiating, partner, making, nervous, about, security. . LinuxSecurity.com Team
A mishap that compromised the integrity of two security keys used by Sun Microsystems is fueling criticism of current methods for scrambling sensitive data and verifying identities on the Web. Sun last week issued a warning that two of its applications' . . . . A mishap that compromised the integrity of two security keys used by Sun Microsystems is fueling criticism of current methods for scrambling sensitive data and verifying identities on the Web. Sun last week issued a warning that two of its applications' "certificates" had been compromised after the company inadvertently included certificate numbers in early-stage, or "alpha," code it sent to partners. A certificate verifies the identity of an application's source, in this case Sun. The alert, posted on Sun's Web site and distributed through security groups, has precipitated criticism from Internet security analysts who say the system for getting the word out about compromised certificates is inadequate. The link for this article located at News.com is no longer available. . An incident involving dual encryption tokens from Sun Microsystems brings to light issues regarding digital certificate notifications and security measures.. Certificate Management, Browser Security, Data Integrity. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.