49
SSL for Server-to-Server Authentication May 2013 Lim Chin Wan

SSL for server to-server authentication

Embed Size (px)

DESCRIPTION

Server to Server Authentication with SSL, PKI in a box

Citation preview

Page 1: SSL for server to-server authentication

SSL for Server-to-Server Authentication May 2013

Lim Chin Wan

Page 2: SSL for server to-server authentication

Have you ever wanted to rob a bank?

Page 3: SSL for server to-server authentication

DOING IT THE OLD SCHOOL WAY?

Page 4: SSL for server to-server authentication

Hacking A Bank Is Easy Because We’re

All Humans!

Page 5: SSL for server to-server authentication

I think you should meet someone…

Page 6: SSL for server to-server authentication

This is Yuri.

In 2010, he and his “anonymous” friends hacked AT&T. In 2011, they hacked Sony and bought a BMW.

Page 7: SSL for server to-server authentication

This year, Yuri hit a major telco with the secret keys provided by a disgruntled employee. Then Yuri went on a nice 2 month long vacation in the Caribbean Islands.

Page 8: SSL for server to-server authentication

Sony and AT&T both used “State of the Art” encryption… yet they

were still hacked!

Page 9: SSL for server to-server authentication

So how does Yuri do it?

Page 10: SSL for server to-server authentication

“Usually, I just find one disgruntled employee. Just one.”

Page 11: SSL for server to-server authentication
Page 12: SSL for server to-server authentication

Don’t Believe Me? Let’s Play A Game…

Page 13: SSL for server to-server authentication

Can Anyone Tell Me Who These

People Are?

Page 14: SSL for server to-server authentication

Heidi Klum

Emma Watson

Page 15: SSL for server to-server authentication

Cameron Diaz

Page 16: SSL for server to-server authentication

Halle Berry

Page 17: SSL for server to-server authentication

Scarlett Johansson

Megan Fox

Page 18: SSL for server to-server authentication

Brad Pitt

Page 19: SSL for server to-server authentication

RATED TOP 10 MOST DANGEROUS CELEBRITIES IN 2012

BY McAfee

Page 20: SSL for server to-server authentication

Heidi Klum 12%

Page 21: SSL for server to-server authentication
Page 22: SSL for server to-server authentication

Because your users are your weakest link…

Page 23: SSL for server to-server authentication

They are your customers… They are your Employees... They are your vendors…

Page 24: SSL for server to-server authentication
Page 25: SSL for server to-server authentication
Page 26: SSL for server to-server authentication
Page 27: SSL for server to-server authentication
Page 28: SSL for server to-server authentication

Common Problems… • Weak password • Lack of awareness • Lack of skills • Outdated policies • Management problems

Page 29: SSL for server to-server authentication
Page 30: SSL for server to-server authentication

Who’s Responsible?

Page 31: SSL for server to-server authentication
Page 32: SSL for server to-server authentication

How can you as a bank protect your customers and

yourself?

Page 33: SSL for server to-server authentication

Implement Server-to-Server Authentication using PKI

Page 34: SSL for server to-server authentication

Your typical server room scene How many servers do you have?

Page 35: SSL for server to-server authentication

How many servers are talking to each other?

Which server is talking to which server?

How do you take control of your servers?

How many vendors do you have logged onto your servers?

Page 36: SSL for server to-server authentication

Assign each server a digital certificate

Page 37: SSL for server to-server authentication

Digital Certificates Provides

Identity to each server Expiry date

Page 38: SSL for server to-server authentication

How much does it cost?

Page 39: SSL for server to-server authentication
Page 40: SSL for server to-server authentication

Become my own CA!

Page 41: SSL for server to-server authentication

A Typical Full Scale Enterprise PKI

Page 42: SSL for server to-server authentication
Page 43: SSL for server to-server authentication

Aiyo! So complicated!

Page 44: SSL for server to-server authentication

What if?

Page 45: SSL for server to-server authentication

Become my own CA!

Next generation PKI PrimeKey PKI Appliance

Page 46: SSL for server to-server authentication

46

Why a PKI Appliance? • Make deployments easier and faster

• Minimize installation/integration efforts

• Lower the TCO with simplified management and maintenance

• Provide one source for Software/Hardware stack

Page 47: SSL for server to-server authentication

A PKI Appliance Gives You...

• Overview of all your servers in your data centre

• Better security via Server-to-Server authentication

• Control over who can access your servers

• Easy management of your server access

Page 48: SSL for server to-server authentication
Page 49: SSL for server to-server authentication

Questions? SecureMetric Technology Group Lim Chin Wan

Mobile : +6 016 261 8925 Office : +603 8996 8225 [email protected]

Formula for Strong Digital Security [email protected] www.securemetric.com