Deploying enterprise root certificate authority
Închide
Articolul precedent
Articolul urmator
187 0
SM ISO690:2012
TATARU, Victor, TATATRU, Victoria, ZGUREANU, Aureliu. Deploying enterprise root certificate authority. In: Society Consciousness Computers, Ed. 10, 12-13 martie 2021, Chişinău. Chişinău: VasileAlecsandri University of Bacău, 2021, Ediția 10, Vol.7, pp. 58-59. ISSN ISSN-L 2359-7321.
EXPORT metadate:
Google Scholar
Crossref
CERIF

DataCite
Dublin Core
Society Consciousness Computers
Ediția 10, Vol.7, 2021
Conferința "Creation of the Society of Consciousness"
10, Chişinău, Moldova, 12-13 martie 2021

Deploying enterprise root certificate authority


Pag. 58-59

Tataru Victor, Tatatru Victoria, Zgureanu Aureliu
 
Academy of Economic Studies of Moldova
 
Proiecte:
 
Disponibil în IBN: 11 mai 2023


Rezumat

Purpose: In this paper we examine the internal structure of a certification authority and security policies applying to such centers and analyze how OpenSSL protocol works in this context. Also we reveal how to prepare everything necessary for the issuance of "full" TLS / SSL certificates for use both in companies and for individuals. As a result, a process for the automated issuance of certificates for the needs of an enterprise will be proposed. Findings: Owning our own certification center in a large range of IT industries allows, for example, to analyze and protect corporate network traffic, encryption of network tunnels, development and testing of software and web sites, corporate email, etc. With the frequency need of using TLS / SSL certificates, we often have to face many inconveniences. So, for example, in most cases, in order to obtain a TLS / SSL certificate for an IP address (not for a DNS name, such as “www.tataru.it”), we have to prove the legal ownership of this IP address or of the range of IP addresses. Moreover, a public certification authority do not provide certificates for domain names from the local group (.local, .localhost etc.) or for local IP addresses (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16). Research limitations/implications: This article discusses a local certification authority. Certificates issued and signed by it will not be trusted by everyone and will remain so until the root certificate is trusted by adding it to the Trusted Root Certification Authorities directory. Practical implications: Owning our own certification center give a beneficial effect on the convenience of network administration, in general on the security of the corporate network, and it may lead to reducing the financial burden of the enterprise. Originality / value: Analysis and protection of corporate network traffic is an integral part of the corporate information security process. Testing applications that provide encryption at the development stage using local certificates have a positive effect on the development process.

Cuvinte-cheie
RootCA, intermediate, OpenSSL, TLS, SSL