are you ready for the new ssl landscape

25
Are you ready for the new SSL landscape? Paul van Brouwershaven Technology Solutions Director

Upload: paul-van-brouwershaven

Post on 08-Aug-2015

24 views

Category:

Documents


2 download

TRANSCRIPT

Page 1: Are you ready for the new SSL landscape

Are you ready for the

new SSL landscape? Paul van Brouwershaven

Technology Solutions Director

Page 2: Are you ready for the new SSL landscape

About me Paul van Brouwershaven

Technology Solutions Director

Page 3: Are you ready for the new SSL landscape

What we provide

User, Machine &

Device

Authentication

Transport Layer

Security (TLS)

Code

Signing Secure

Email

Document

Signing

Identity and

Access

Management

Page 4: Are you ready for the new SSL landscape

Please open your browser!

• Let us know what you think!

• Scan the QR code and click to answer

globalsign.com/whd-vote/

Page 5: Are you ready for the new SSL landscape

It’s about you and

your customer!

Page 6: Are you ready for the new SSL landscape

SSL is dead

And has been for a long time

actually!

Page 7: Are you ready for the new SSL landscape

TLS & Hosting

Page 8: Are you ready for the new SSL landscape

GlobalSign and the Hosting industry

API

OneClickSSL

CloudSSL

SNI /

CloudSSL

Page 9: Are you ready for the new SSL landscape

Security is more than just TLS

• Phishing

• Spam

• Malware

• SQL Injections

• Cross Site Scripting (XSS)

• Authentication & Authorization

• Information leakage

• Storage

• ……

Page 10: Are you ready for the new SSL landscape

What priority level is TLS in your

security plan?

Page 11: Are you ready for the new SSL landscape

TLS and Identity

Assurance

Page 12: Are you ready for the new SSL landscape

Identity Assurance

Domain Validation Certificate

Extended Validation Certificate

• Shows who is behind the padlock

• Enhances trust and improves conversions

Page 13: Are you ready for the new SSL landscape

What prevents you from providing

certificates with identity

assurance?

Page 14: Are you ready for the new SSL landscape

Best practice

implementation

Page 15: Are you ready for the new SSL landscape

ALPN Session

identifiers

Best practices

Legacy

support

Compliance

Cipher

suites

OCSP

stapling

Forward

secrecy

ECC

SNI

Configuration

management

Server &

software

maintenance

HSTS

Legal

restrictions

Key

size

CT

Page 16: Are you ready for the new SSL landscape

Do you see the complexity of best

practices as an obstacle to

deploying TLS?

Page 17: Are you ready for the new SSL landscape

How often do you review your

TLS configurations?

Page 18: Are you ready for the new SSL landscape

Would you switch to a more

efficient ‘protocol’ even if it cost

you a percentage of visitors?

Page 19: Are you ready for the new SSL landscape

TLS by default

Page 20: Are you ready for the new SSL landscape

IoT growing requirements

Source: ariasystems.com

Page 21: Are you ready for the new SSL landscape

HTTP connections indicated as insecure

Source: httpvshttps.com

Page 22: Are you ready for the new SSL landscape

HTTP/2, SPDY Improves performance

Source: httpvshttps.com

Page 23: Are you ready for the new SSL landscape

Would you like to provide TLS by

default?

Page 24: Are you ready for the new SSL landscape

Questions?

Paul van Brouwershaven

[email protected]

Page 25: Are you ready for the new SSL landscape

Thank you!

Paul van Brouwershaven

[email protected]