Dinocolor https://dinocolor.si/hr Kartične in varnostne rešitve Mon, 11 Nov 2019 09:50:05 +0000 hr hourly 1 https://wordpress.org/?v=7.1 https://dinocolor.si/wp-content/uploads/2019/04/cropped-android-icon-144x144-32x32.png Dinocolor https://dinocolor.si/hr 32 32 SSL/TLS Verification – Digital Identity for Your Website https://dinocolor.si/hr/ssl-tls-verification-digital-identity-for-your-website/ Mon, 11 Nov 2019 09:50:03 +0000 https://dinocolor.si/ssl-tls-verification-digital-identity-for-your-website/ Essentially an SSL/TLS certificate is a form of digital identity for your website. The level of identity differs depending on the type of certificate that you have – compare it to how a gym membership ID contrasts with a driver’s license versus a passport. Each has increasingly more information that further validates your identity. In that way, it’s similar to SSL/TLS certificate verification for the different certificate types.

How are Certificates Verified?

Verification methods for the three types of SSL/TLS certificates are required to follow strict guidelines established by the CA/Browser Forum. The verified information is included in public trust SSL/TLS certificates and differ based on the type of certificate. The most basic is domain validation (DV), the next level up is organization validation (OV), which includes some identity assurance and lastly, extended validation (EV) provides the most identity checking. The verification process escalates with each certificate type, and that is also reflected in the price.

Identity v. Undisclosed SSL/TLS Certificates

A mix of EV and OV certificates are widely used by organizations that want to provide their customers with strong encryption technology as well as deliver identity assurance. Identity assurance helps customers recognize whether or not a website is legitimate. It also prevents the brand from suffering damaging losses associated with phishing scams and other nefarious online activity.

EV and OV certificates are used primarily for client-to-server transactions where sensitive information (e.g., user name, password, credit card information, etc.) is being transferred over the Internet. Encryption ensures the data cannot be stolen as it makes its way to the organization. The identity piece gives website visitors the ability to positively identify that the website they’re on is authentic.

DV certificates only verify control over a domain separating encryption from authentication. In the absence of identity checks, DV certificates lack the critical component of having an identifiable paper trail, and that’s where they differ from EV or OV certificates. All three certificate types provide the same strong level of encryption technology.

DV Certificates

DV certificates are best used for situations that do not necessitate the important aspect of identity assurance making them a good choice when rapid acquisition of encryption-based technology for server-to-server communication is needed – for example, transferring data between two internal servers.

The purpose of a DV certificate is to provide IT professionals with a fast and affordable way to encrypt non-sensitive data that is passed over the Internet. Some CAs issue DV certificates via an automated process at no charge, the domain owner doesn’t even supply a credit card. The ability to acquire these certificates anonymously provides an opportunity for bad actors to appear legitimate without leaving a trace of identity. This is why DV certificates are associated with a high-level of phishing activity.

There has been some discussion among industry leaders surrounding the context for using DV certificates and whether or not it is sufficient for ecommerce transactions. There is no identifying information attached to a DV certificate. Without it, DV offers no value for people who want to build trust with their website visitors.

Major browsers indicate that a website is secured with DV certificate by the padlock with HTTPS in the address bar, but do not show organization details because they do not exist. These certificates validate domain ownership only, and do not tie a domain to a person, place or entity.

OV Certificates

OV certificates have been issued since the mid-nineties making them the legacy of the SSL/TLS ecosystem. These certificates have always required that the certificate subscriber complete an identity verification check. Disclosing identity provides accountability and confirmed identity shows that visitors are on the authentic site and not a look-alike.

OV certificates must be validated according to stringent industry guidelines. The process basically requires three checks before an OV certificate can be issued. The subscriber must:

show control over the domain name(s) where either the applicant shows control or the owner of the domain name authorizes control;

have their organization verified by an approved third-party system confirming their organization is registered and valid; and lastly,

be able to able to authorize certificate issuance. The CA will contact the applicant using an accepted communication method. This is typically done by phone where the phone number has been validated as registered to the named identity.

In addition to domain ownership required for DV certificates, the organization is validated for OV certificate issuance. Once validated, the certificate can be deployed and users will be able to view the website’s confirmed identity in the certificate details on most major web browsers.

EV Certificates

In addition to the checks conducted for DV and OV certificates, EV certificates require a jurisdiction check with the incorporating agency or registrant, a certificate subscriber agreement signed by a validated endorser, and certificate issuance must be approved by a validated certificate endorser.

Since EV certificates undergo an increased verification level, more identity information is provided and the authorization level is higher the result is greater reliability. Browsers will show a higher trust level for EV certificates in the web address bar than for either DV or OV certificates. This may be indicated by a green color on the lock icon or the name of verified organization depending on the browser – each browser handles this differently. High value organizations like financial services institutions typically prefer EV certificates to help their customers discern when they are on their authentic website. They are also a great choice for landing pages to confirm the organization identity and increase site trust.

EV verification gives customers more confidence to transact on a website and helps preserve brand reputation for the organizations who use the. It leaves a detailed paper trail where customers have recourse should they be victimized by any nefarious activity that takes place while transacting on that website. EV certificates are distinguished with a locked padlock, organization name and sometimes country ID in the web address bar in most major browsers. The organization’s details can be found by clicking on the padlock and searching the certificate details.

The amount of verification checking behind the various certificate types is reflected in the price. The increased vetting for EV particularly and OV certificates is what makes high assurance certificates more expensive. EV certificates come with the most comprehensive verification checking, which includes domain verification, cross-checks among several governmental and internal checkpoints that ties the entity to a specific physical location. SSL/TLS certificates are an integral part of an organizations overall IT security posture.

]]>
SSL Certificates 101 – Why Do I Need an SSL/TLS Certificate? https://dinocolor.si/hr/ssl-certificates-101-why-do-i-need-an-ssl-tls-certificate/ Mon, 11 Nov 2019 09:49:08 +0000 https://dinocolor.si/ssl-certificates-101-why-do-i-need-an-ssl-tls-certificate/ It happens all the time. Someone in the company tells you that you have to get an SSL/TLS certificate for your website. Wait. What? Nooo, it doesn’t happen all the time. But, it probably happened to you when working on a test or a special promotion site for your group, and that’s why you’re reading this blog post. There are a few things to unpack so we’ve broken it down into a seven-part series. Here’s part 1 – this section goes over some of the basics on SSL/TLS certificates and will prepare you for a polite conversation on transaction security with your company’s security group.

SSL/TLS Puts the “S” in HTTPS

In HTTPS, the “S” stands for “secure.” As consumers, we rely on organizations to secure our online transactions, and on browsers to tell us when it’s safe to transact on a website. This quick tutorial shows how to spot a secure website.

SSL/TLS certificates (they are both the same) serve two purposes – they encrypt information that is sent over the internet and they provide identity assurance, both of which help online consumers to positively identify and trust websites that are safe to transact with. An HTTP website— no “S”—lacks both identity and encryption, which means it’s not secure. Browsers now issue strong warnings to visitors who try to enter websites that are not secured by HTTPS. This usually makes the visitor queasy and they leave for another website where they feel safe to make their transaction.

How Does an SSL/TLS Certificate Work?

Public Key Infrastructure (PKI) provides the framework that enables SSL/TLS to be used for cybersecurity. PKI uses encryption to protect information that passes between a server (your website) and a client (the device the person transacting on your website is using). It uses two different types of matched cryptographic keys to secure the transaction, the public key (which your server distributes everywhere) and the private key (which is locked away on your server).

When transacting, the client and your server start with an encryption “handshake” that relies on your certificate, after which all communications between them are encrypted (so no one can intercept and read the communications in transit) and are authenticated between the client and server – that’s why encryption means security. From that point on, all the client’s personal data — login credentials, credit card information, etc. – can be transmitted securely to your server. A file that is created by a particular public key can only be decrypted by the corresponding private key on your server and vice-versa, ensuring that the transaction is going to the intended recipient and protecting the information from a cyberattack while in transit.

So, why do I need an SSL/TLS Certificate?

SSL/TLS certificates provide important advantages that can mean the difference between creating a seamless and secure website experience versus an alarming one for website visitors. Here are a few benefits that SSL/TLS provide for you:

  • Avoids browser popups that warn website visitors that your website is not secure
  • Achieves a stronger Google SEO ranking
  • Creates a safer experience for your customers
  • Builds customer trust and improves conversions
  • Encrypts the sensitive data that gets transmitted
  • Uses SSL/TLS with identity verification helping distinguish your website from fraudulent look-alikes

To sum it up, SSL/TLS certificates are essential for web-based projects that can be viewed by anyone surfing the internet – nearly 80% or all web page loads now are encrypted, and the number is rising rapidly. While there is no legal or technical requirement to use certificates, it does represent best practices and the browsers make it much friendlier for visitors to engage with websites that have HTTPS because of the security features they provide. Stay tuned for the next post in our seven-part series, which will cover what you need to know about the different certificate types.

]]>
5 Reasons Why Entrust Datacard PKI is Proper PKI https://dinocolor.si/hr/5-reasons-why-entrust-datacard-pki-is-proper-pki/ Mon, 11 Nov 2019 09:48:10 +0000 https://dinocolor.si/5-reasons-why-entrust-datacard-pki-is-proper-pki/ We know you’ve heard it before: the “we’re different” pitch. But give us a few minutes, and we think you’ll see why we’re so passionate about our PKI offering.

Well-designed PKI is complex. The technology has its own share of intricacies, but the real challenge is setting up a proper PKI: one that runs according to best practices and expert policies that reduces business risks. That’s why choosing a partner that goes beyond technology is important.

Entrust Datacard pioneered PKI technology (and we’re proud of it). You can learn about it here. But we also have a lot of customers using Microsoft Certificate Authority (CA), and we think that’s great too.

Since so many of our potential customers were already utilizing Microsoft CA –but, honestly, not managing it properly– we created Entrust Datacard Managed Microsoft CA Service. The technology is yours, but we bring deep expertise to develop a high-assurance solution with best-practice policies to back it up.

Being technology agnostic is important to us. We get to take time to learn our customers’ businesses and propose a solution that actually fits their needs. We know it’s important for you to implement a solution that fits into your ecosystem and works the way you need it to.

Here are five reasons why Entrust Datacard’s offering is proper PKI:

Flexibility. We’re proud of our PKI solutions, but we know you might have another Certificate Authority (CA) in play. That’s why we offer management solutions for both our products and Microsoft CA. The most important part of flexibility is that a solution works in your ecosystem and provides you various deployment options so you can choose the one that best suits your business.

Expertise. We have a team with unparalleled depth of knowledge. They work for us because they love PKI and they’re eager to see it managed according to best practices.

Ownership. You own it, we manage it. It’s that simple.

Scalability. Our solutions let you increase certificate volumes without the need for infrastructure investment. As the number of systems, devices, and applications grow, you can scale your solution without impeding your business.

High assurance. We’ve been at this a long time, and we love working with IT teams to make high-assurance PKI a priority. We act as your partner throughout the entire process to make sure you’re considering all the angles – even those you might not know about.

Proper PKI combines the best of product, services, expertise and ecosystems. At Entrust Datacard, we know proper PKI consists of so much more than technology and we understand how much yo ur company relies on the security of your digital certificates. We also know PKI is not easy to manage and can be a bit of a headache, to put it mildly. If you’d like help managing your PKI, our team of experts is standing by to help you with any digital certificate needs you might have.

]]>
5 Reasons Why Entrust Datacard PKI is Proper PKI https://dinocolor.si/hr/5-reasons-why-entrust-datacard-pki-is-proper-pki/ Tue, 23 Apr 2019 03:30:08 +0000 https://dinocolor.si/?p=78 We know you’ve heard it before: the “we’re different” pitch. But give us a few minutes, and we think you’ll see why we’re so passionate about our PKI offering.

Well-designed PKI is complex. The technology has its own share of intricacies, but the real challenge is setting up a proper PKI: one that runs according to best practices and expert policies that reduces business risks. That’s why choosing a partner that goes beyond technology is important.

Entrust Datacard pioneered PKI technology (and we’re proud of it). You can learn about it here. But we also have a lot of customers using Microsoft Certificate Authority (CA), and we think that’s great too.

Since so many of our potential customers were already utilizing Microsoft CA –but, honestly, not managing it properly– we created Entrust Datacard Managed Microsoft CA Service. The technology is yours, but we bring deep expertise to develop a high-assurance solution with best-practice policies to back it up.

Being technology agnostic is important to us. We get to take time to learn our customers’ businesses and propose a solution that actually fits their needs. We know it’s important for you to implement a solution that fits into your ecosystem and works the way you need it to. 

Here are five reasons why Entrust Datacard’s offering is proper PKI:

Flexibility. We’re proud of our PKI solutions, but we know you might have another Certificate Authority (CA) in play. That’s why we offer management solutions for both our products and Microsoft CA. The most important part of flexibility is that a solution works in your ecosystem and provides you various deployment options so you can choose the one that best suits your business.

Expertise. We have a team with unparalleled depth of knowledge. They work for us because they love PKI and they’re eager to see it managed according to best practices.

Ownership. You own it, we manage it. It’s that simple.

Scalability. Our solutions let you increase certificate volumes without the need for infrastructure investment. As the number of systems, devices, and applications grow, you can scale your solution without impeding your business.

High assurance. We’ve been at this a long time, and we love working with IT teams to make high-assurance PKI a priority. We act as your partner throughout the entire process to make sure you’re considering all the angles – even those you might not know about.

Proper PKI combines the best of product, services, expertise and ecosystems. At Entrust Datacard, we know proper PKI consists of so much more than technology and we understand how much yo              ur company relies on the security of your digital certificates. We also know PKI is not easy to manage and can be a bit of a headache, to put it mildly. If you’d like help managing your PKI, our team of experts is standing by to help you with any digital certificate needs you might have.

]]>
SSL Certificates 101 – Why Do I Need an SSL/TLS Certificate? https://dinocolor.si/hr/ssl-certificates-101-why-do-i-need-an-ssl-tls-certificate/ Tue, 23 Apr 2019 03:28:53 +0000 https://dinocolor.si/?p=75 It happens all the time. Someone in the company tells you that you have to get an SSL/TLS certificate for your website. Wait. What? Nooo, it doesn’t happen all the time. But, it probably happened to you when working on a test or a special promotion site for your group, and that’s why you’re reading this blog post. There are a few things to unpack so we’ve broken it down into a seven-part series. Here’s part 1 – this section goes over some of the basics on SSL/TLS certificates and will prepare you for a polite conversation on transaction security with your company’s security group.

SSL/TLS Puts the “S” in HTTPS

In HTTPS, the “S” stands for “secure.” As consumers, we rely on organizations to secure our online transactions, and on browsers to tell us when it’s safe to transact on a website. This quick tutorial shows how to spot a secure website.

SSL/TLS certificates (they are both the same) serve two purposes – they encrypt information that is sent over the internet and they provide identity assurance, both of which help online consumers to positively identify and trust websites that are safe to transact with. An HTTP website— no “S”—lacks both identity and encryption, which means it’s not secure. Browsers now issue strong warnings to visitors who try to enter websites that are not secured by HTTPS. This usually makes the visitor queasy and they leave for another website where they feel safe to make their transaction.

How Does an SSL/TLS Certificate Work?

Public Key Infrastructure (PKI) provides the framework that enables SSL/TLS to be used for cybersecurity. PKI uses encryption to protect information that passes between a server (your website) and a client (the device the person transacting on your website is using). It uses two different types of matched cryptographic keys to secure the transaction, the public key (which your server distributes everywhere) and the private key (which is locked away on your server).

When transacting, the client and your server start with an encryption “handshake” that relies on your certificate, after which all communications between them are encrypted (so no one can intercept and read the communications in transit) and are authenticated between the client and server – that’s why encryption means security. From that point on, all the client’s personal data — login credentials, credit card information, etc. – can be transmitted securely to your server. A file that is created by a particular public key can only be decrypted by the corresponding private key on your server and vice-versa, ensuring that the transaction is going to the intended recipient and protecting the information from a cyberattack while in transit.

So, why do I need an SSL/TLS Certificate?

SSL/TLS certificates provide important advantages that can mean the difference between creating a seamless and secure website experience versus an alarming one for website visitors. Here are a few benefits that SSL/TLS provide for you:

  • Avoids browser popups that warn website visitors that your website is not secure
  • Achieves a stronger Google SEO ranking
  • Creates a safer experience for your customers
  • Builds customer trust and improves conversions
  • Encrypts the sensitive data that gets transmitted
  • Uses SSL/TLS with identity verification helping distinguish your website from fraudulent look-alikes

To sum it up, SSL/TLS certificates are essential for web-based projects that can be viewed by anyone surfing the internet – nearly 80% or all web page loads now are encrypted, and the number is rising rapidly. While there is no legal or technical requirement to use certificates, it does represent best practices and the browsers make it much friendlier for visitors to engage with websites that have HTTPS because of the security features they provide. Stay tuned for the next post in our seven-part series, which will cover what you need to know about the different certificate types.

]]>
SSL/TLS Verification – Digital Identity for Your Website https://dinocolor.si/hr/ssl-tls-verification-digital-identity-for-your-website/ Tue, 23 Apr 2019 03:27:46 +0000 https://dinocolor.si/?p=72 Essentially an SSL/TLS certificate is a form of digital identity for your website. The level of identity differs depending on the type of certificate that you have – compare it to how a gym membership ID contrasts with a driver’s license versus a passport. Each has increasingly more information that further validates your identity. In that way, it’s similar to SSL/TLS certificate verification for the different certificate types.

How are Certificates Verified?

Verification methods for the three types of SSL/TLS certificates are required to follow strict guidelines established by the CA/Browser Forum. The verified information is included in public trust SSL/TLS certificates and differ based on the type of certificate. The most basic is domain validation (DV), the next level up is organization validation (OV), which includes some identity assurance and lastly, extended validation (EV) provides the most identity checking. The verification process escalates with each certificate type, and that is also reflected in the price.

Identity v. Undisclosed SSL/TLS Certificates

A mix of EV and OV certificates are widely used by organizations that want to provide their customers with strong encryption technology as well as deliver identity assurance.  Identity assurance helps customers recognize whether or not a website is legitimate. It also prevents the brand from suffering damaging losses associated with phishing scams and other nefarious online activity.

EV and OV certificates are used primarily for client-to-server transactions where sensitive information (e.g., user name, password, credit card information, etc.) is being transferred over the Internet. Encryption ensures the data cannot be stolen as it makes its way to the organization. The identity piece gives website visitors the ability to positively identify that the website they’re on is authentic.

DV certificates only verify control over a domain separating encryption from authentication. In the absence of identity checks, DV certificates lack the critical component of having an identifiable paper trail, and that’s where they differ from EV or OV certificates. All three certificate types provide the same strong level of encryption technology.

DV Certificates

DV certificates are best used for situations that do not necessitate the important aspect of identity assurance making them a good choice when rapid acquisition of encryption-based technology for server-to-server communication is needed – for example, transferring data between two internal servers.

The purpose of a DV certificate is to provide IT professionals with a fast and affordable way to encrypt non-sensitive data that is passed over the Internet. Some CAs issue DV certificates via an automated process at no charge, the domain owner doesn’t even supply a credit card. The ability to acquire these certificates anonymously provides an opportunity for bad actors to appear legitimate without leaving a trace of identity. This is why DV certificates are associated with a high-level of phishing activity.

There has been some discussion among industry leaders surrounding the context for using DV certificates and whether or not it is sufficient for ecommerce transactions. There is no identifying information attached to a DV certificate. Without it, DV offers no value for people who want to build trust with their website visitors.

Major browsers indicate that a website is secured with DV certificate by the padlock with HTTPS in the address bar, but do not show organization details because they do not exist. These certificates validate domain ownership only, and do not tie a domain to a person, place or entity.

OV Certificates

OV certificates have been issued since the mid-nineties making them the legacy of the SSL/TLS ecosystem. These certificates have always required that the certificate subscriber complete an identity verification check. Disclosing identity provides accountability and confirmed identity shows that visitors are on the authentic site and not a look-alike.

OV certificates must be validated according to stringent industry guidelines. The process basically requires three checks before an OV certificate can be issued. The subscriber must:

show control over the domain name(s) where either the applicant shows control or the owner of the domain name authorizes control;

have their organization verified by an approved third-party system confirming their organization is registered and valid; and lastly,

be able to able to authorize certificate issuance. The CA will contact the applicant using an accepted communication method. This is typically done by phone where the phone number has been validated as registered to the named identity.

In addition to domain ownership required for DV certificates, the organization is validated for OV certificate issuance. Once validated, the certificate can be deployed and users will be able to view the website’s confirmed identity in the certificate details on most major web browsers.

EV Certificates

In addition to the checks conducted for DV and OV certificates, EV certificates require a jurisdiction check with the incorporating agency or registrant, a certificate subscriber agreement signed by a validated endorser, and certificate issuance must be approved by a validated certificate endorser.

Since EV certificates undergo an increased verification level, more identity information is provided and the authorization level is higher the result is greater reliability. Browsers will show a higher trust level for EV certificates in the web address bar than for either DV or OV certificates. This may be indicated by a green color on the lock icon or the name of verified organization depending on the browser – each browser handles this differently. High value organizations like financial services institutions typically prefer EV certificates to help their customers discern when they are on their authentic website. They are also a great choice for landing pages to confirm the organization identity and increase site trust.

EV verification gives customers more confidence to transact on a website and helps preserve brand reputation for the organizations who use the. It leaves a detailed paper trail where customers have recourse should they be victimized by any nefarious activity that takes place while transacting on that website. EV certificates are distinguished with a locked padlock, organization name and sometimes country ID in the web address bar in most major browsers. The organization’s details can be found by clicking on the padlock and searching the certificate details.

The amount of verification checking behind the various certificate types is reflected in the price.  The increased vetting for EV particularly and OV certificates is what makes high assurance certificates more expensive. EV certificates come with the most comprehensive verification checking, which includes domain verification, cross-checks among several governmental and internal checkpoints that ties the entity to a specific physical location. SSL/TLS certificates are an integral part of an organizations overall IT security posture.

]]>