the revolutionary changes in the ssl industry in 2017

32
www.leaderssl.nl E-mail: [email protected] | +31 20 7640722 Alexei Ivanov, LeaderTelecom B.V. Founder and CEO LeaderTelecom B.V. The revolutionary changes in the SSL industry in 2017

Upload: leadertelecombv

Post on 22-Jan-2018

132 views

Category:

Technology


2 download

TRANSCRIPT

Page 1: The revolutionary changes in the SSL industry in 2017

www.leaderssl.nlE-mail: [email protected] | +31 20 7640722

Alexei Ivanov,

LeaderTelecom B.V.

Founder and CEO LeaderTelecom B.V.

The revolutionary changes

in the SSL industry in 2017

Page 2: The revolutionary changes in the SSL industry in 2017

www.leaderssl.nlE-mail: [email protected] | +31 20 7640722

Alexei Ivanov, MBAFounder and CEO LeaderTelecom B.V. (Amsterdam, The Netherlands)

Page 3: The revolutionary changes in the SSL industry in 2017

www.leaderssl.nlE-mail: [email protected] | +31 20 7640722

Official strategic partner of

Official strategic partner with specialisation WSSP

Page 4: The revolutionary changes in the SSL industry in 2017

www.leaderssl.nlE-mail: [email protected] | +31 20 7640722

Our clients are located in 80 countries

Page 5: The revolutionary changes in the SSL industry in 2017

www.leaderssl.nlE-mail: [email protected] | +31 20 7640722

Amazing progress in HTTPS adoption has been made, with

a substantial portion of web traffic now secured by HTTPS:

Page 6: The revolutionary changes in the SSL industry in 2017

www.leaderssl.nlE-mail: [email protected] | +31 20 7640722

SSL-Market Trends

Expansion of transparency logs

(Adding of all SSL-certificates)

Page 7: The revolutionary changes in the SSL industry in 2017

www.leaderssl.nlE-mail: [email protected] | +31 20 7640722

Treatment of HTTP pages with password or

credit card form fields:

Up untill now (Chrome 53)

January 2017 (Chrome 56)

Page 8: The revolutionary changes in the SSL industry in 2017

www.leaderssl.nlE-mail: [email protected] | +31 20 7640722

Displaying of HTTP sites in Google Chrome

Page 9: The revolutionary changes in the SSL industry in 2017

www.leaderssl.nlE-mail: [email protected] | +31 20 7640722

Beginning from 1 January 2017 all sites without SSL-certificates

involved in transmitting passwords or credit card details, will be

treated as unsecured in Google Chrome

Page 10: The revolutionary changes in the SSL industry in 2017

www.leaderssl.nlE-mail: [email protected] | +31 20 7640722

Moving from SHA-1 in favor of SHA-2

Firefox will display error for SHA-1 certificates in 2017

Page 11: The revolutionary changes in the SSL industry in 2017

www.leaderssl.nlE-mail: [email protected] | +31 20 7640722

Changes in Firefox security user experience.

Secure (HTTPS) connection

Non-secure (HTTP) connection

Up untill now

Page 12: The revolutionary changes in the SSL industry in 2017

www.leaderssl.nlE-mail: [email protected] | +31 20 7640722

Web pages which collect passwords but don’t use HTTPS

starting January 2017

Page 13: The revolutionary changes in the SSL industry in 2017

www.leaderssl.nlE-mail: [email protected] | +31 20 7640722

In upcoming releases, Firefox will show popup message when a user

clicks into a username or password field

on a page that doesn’t use HTTPS

Page 14: The revolutionary changes in the SSL industry in 2017

www.leaderssl.nlE-mail: [email protected] | +31 20 7640722

Start SSL

Not trusted anymore

Page 15: The revolutionary changes in the SSL industry in 2017

www.leaderssl.nlE-mail: [email protected] | +31 20 7640722

Let's Encrypt

Great basic security instead of HTTP

Page 16: The revolutionary changes in the SSL industry in 2017

www.leaderssl.nlE-mail: [email protected] | +31 20 7640722

Advantages of Let’s Encrypt

• FREE, FREE, FREE

• Fully automated renewal process on a customer´s device

• It publishes certificates into CT logs

Page 17: The revolutionary changes in the SSL industry in 2017

www.leaderssl.nlE-mail: [email protected] | +31 20 7640722

Disadvantages of Let’s Encrypt

• No customers support

• Credibility supplied by a small CA IdenTrust

• There is a limit to a number of issued certificates

• A client is necessary, it is not possible to issue a certificate without

a running server (security breach?)

• It is dangerous to change server configuration automatically.

Page 18: The revolutionary changes in the SSL industry in 2017

www.leaderssl.nlE-mail: [email protected] | +31 20 7640722

Сlassification of SSL-Certificates

• Only domain verification required

• Ready in 5-15 minutes

1. DV-certificates (Domain Validation)

Page 19: The revolutionary changes in the SSL industry in 2017

www.leaderssl.nlE-mail: [email protected] | +31 20 7640722

• Domain and Organization Validation

• Issuance Time: 2-3 Business Days

2. OV-certificates (Organisation Validation)

Page 20: The revolutionary changes in the SSL industry in 2017

www.leaderssl.nlE-mail: [email protected] | +31 20 7640722

• The highest trust and conversions

• Extended company validation

• Green bar

3. EV-certificate (Extended Validation)

Page 21: The revolutionary changes in the SSL industry in 2017

www.leaderssl.nlE-mail: [email protected] | +31 20 7640722

What is required for validation?

1. For Organization Validation (OV)

Company should be registered in D&B or your need to provide legal opinion

letter signed by attorney or Certified public accountant

2. For Extended Validation (EV)

Company should be legally registered in government business directory in

addition to OV certificate validation requirements

Page 22: The revolutionary changes in the SSL industry in 2017

www.leaderssl.nlE-mail: [email protected] | +31 20 7640722

What is required for validation?

1. For Organization Validation (OV)

• The company needs to be legally registered with an official registration agency.

• We need to verify that the corporate contact person is a full time employee and that

they have an authority over the order.

• We also need to verify domain ownership to that the company enrolling

for the organisation has the rights to use the domain.

• We need to call the organization via 3rd party verified telephone number.

• Yes, it can be a number listed in Dun and bradstreet.

• goldenpages.be, Infobel

Page 23: The revolutionary changes in the SSL industry in 2017

www.leaderssl.nlE-mail: [email protected] | +31 20 7640722

Difference in CSR requests for different

types of SSL certificates

Page 24: The revolutionary changes in the SSL industry in 2017

www.leaderssl.nlE-mail: [email protected] | +31 20 7640722

SEO & SSL

Page 25: The revolutionary changes in the SSL industry in 2017

www.leaderssl.nlE-mail: [email protected] | +31 20 7640722

Mixed content problem

Page 26: The revolutionary changes in the SSL industry in 2017

www.leaderssl.nlE-mail: [email protected] | +31 20 7640722

Useful tools

https://www.ssllabs.com/ssltest/

Page 27: The revolutionary changes in the SSL industry in 2017

www.leaderssl.nlE-mail: [email protected] | +31 20 7640722

Useful tools

https://www.leaderssl.be/tools/ssl_converter

Page 28: The revolutionary changes in the SSL industry in 2017

www.leaderssl.nlE-mail: [email protected] | +31 20 7640722

Intermediate SSL certificates

Page 29: The revolutionary changes in the SSL industry in 2017

www.leaderssl.nlE-mail: [email protected] | +31 20 7640722

Useful tools

https://www.leaderssl.be/tools/cert_chain_resolver

Page 30: The revolutionary changes in the SSL industry in 2017

www.leaderssl.nlE-mail: [email protected] | +31 20 7640722

SSL certificate + Vulnerability scan =

Secure website

Page 31: The revolutionary changes in the SSL industry in 2017

www.leaderssl.nlE-mail: [email protected] | +31 20 7640722

Partnership program for hosting providers.

Earn more with LeaderTelecom!

• Profit growth by offering SSL-certificates to existing customers

• Professional support from the LeaderTelecom, prompt resolution

of any issues

• WHMCS module

Partner benefits:

• Increase profits by upselling effective security solutions;

• Conducting advertising campaigns, PR, case studies

Page 32: The revolutionary changes in the SSL industry in 2017

www.leaderssl.nlE-mail: [email protected] | +31 20 7640722

Thank you!

www.leaderssl.nl

[email protected]

+31 20 7640722

Zekeringstraat 17 A, 1014 BM, Amsterdam,

The Netherlands