Szilárd Pfeiffer
A free software fanatic developer, a security commited engineer, a free-culture enthusiastic jounalist, an agile believer manager.
Pfeiffer Szilárd
Security Researcher & Evangelist
Nyilvános kulcsú infrastruktúra
elméleti hibák
konfigurációs hibák
teljesítmény problémák
politikai tényezők
Szerver szoftverek
Kliens szoftverek
implementációs nehézségek
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua.
a8ae2f4a56baf78845c041c833946d00
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua.
a8ae2f4a56baf78845c041c833946d00
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua.
Certificate Transparency (CT)
DNS Certification Authority Authorization (CAA)
DNS-based Authentication of Named Entities (DANE)
0 issue "ca.example.net" 0 issuewild "ca.example.net"
0 iodef "mailto:security@example.com" 0 iodef "http://iodef.example.com/"
_25._tcp.mail.example.com. IN TLSA
2 0 1( E8B54E0B4BAA815B06D3462D65FBC7C0 CF556ECCF9F5303EBFBB77D022F834C0 )
257 3 13 mdsswUyr3DPW132mOi8V9xESWE8jTo0dxCjjnopKl+GqJxpVXckHAeF+ KkxLbxILfDLUT0rAK9iUzy1L53eKGQ==
Certificate Revocation List (CRL)
Online Certificate Status Protocol (OCSP)
Responders
Stapling
Tanúsítvány érvényességi időtartam
Location
CRL
✗
Access
Size
✗
✗
OCSP
✗
✗
✓
Privacy
✗
✓
OCSP Stapling
✓
✓
✓
✓
Full Chain
✗
✓
✓
OCSP Multi Stapling
✓
✓
✓
✓
✓
?
Support
✓
✓
✓
setenv.add-response-header=("Public-Key-Pins"=>"Value")
add_header Public-Key-Pins 'Value' always;
Header always set Public-Key-Pins "Value"
pin-sha256="GRAH5Ex+kB4cCQi5gMU82urf...";
report-uri="https://example.com/report/hpkp";
max-age=15768000;
includeSubDomains
setenv.add-response-header=("Expect-Staple"=>"Value")
add_header Expect-Staple 'Value' always;
Header always set Expect-Staple "Value"
max-age=31536000;
report-uri="https://example.com/report/staple";
includeSubDomains;
preload
setenv.add-response-header=("Expect-Staple"=>"Value")
add_header Expect-Staple 'Value' always;
Header always set Expect-Staple "Value"
max-age=31536000;
report-uri="https://example.com/report/staple";
enforce
Configuration
Updates
Snippet
Generators
Checkers
Online
Offline
ssl.use-sslv2 = "disable" ...
ssl_protocols TLSv1.2 TLSv1.3;
SSLProtocol +TLSv1.2 +TLSv1.3
!TLSv1.1 !TLSv1.0 !TLSv1 !SSLv2 !SSLv3
ssl.cipher-list = "CipherSuiteString"
ssl_ciphers CipherSuiteString
SSLCipherSuite CipherSuiteString
HIGH:!PSK:!SRP:!aNULL:!aDSS:!kRSA:!ARIA:!CAMELLIA:!SHA:!AESCCM
honor-cipher-order = "enable"
ssl_prefer_server_ciphers On;
SSLHonorCipherOrder On
Always On
-
ssl_stapling on;
SSLUseStapling on
Should Be On
Transport Layer Security
Secure Shell
Security Headerök
By Szilárd Pfeiffer
A free software fanatic developer, a security commited engineer, a free-culture enthusiastic jounalist, an agile believer manager.