Rootmanual:SSL: Skillnad mellan sidversioner
Hoppa till navigering
Hoppa till sök
Busk (diskussion | bidrag) mIngen redigeringssammanfattning |
Busk (diskussion | bidrag) (la till rating-kolumn och direktlänkar till ssllabs där tillämpligt) |
||
Rad 6: | Rad 6: | ||
{| class="wikitable" |
{| class="wikitable" |
||
! host !! CN !! port !! Certificate !! Protocol support !! Key exchange !! Cipher strength !! Valid from !! Valid until !! Key !! Signature algorithm !! TLS1.2 !! TLS1.1 !! TLS1.0 !! SSL3 !! SSL2 !! PFS !! HSTS !! OCSP !! NPN !! SPDY !! analyze.py (mozilla-nivå) !! annat |
! host !! CN !! port !! Certificate !! Protocol support !! Key exchange !! Cipher strength !! Rating !! Valid from !! Valid until !! Key !! Signature algorithm !! TLS1.2 !! TLS1.1 !! TLS1.0 !! SSL3 !! SSL2 !! PFS !! HSTS !! OCSP !! NPN !! SPDY !! analyze.py (mozilla-nivå) !! annat |
||
|- |
|- |
||
|webware ||admin ||443 || 100 || 95 || 90 || 90 || 2014-11-17 || 2017-11-16 || RSA2048 ||SHA256wRSA || Y || Y || Y || N || N || Y || Y || Y || Y || Y || "intermediate" || |
|webware ||[https://www.ssllabs.com/ssltest/analyze.html?d=admin.lysator.liu.se&hideResults=on admin] ||443 || 100 || 95 || 90 || 90 || A+ || 2014-11-17 || 2017-11-16 || RSA2048 ||SHA256wRSA || Y || Y || Y || N || N || Y || Y || Y || Y || Y || "intermediate" || |
||
|- |
|- |
||
|bugzilla||bugzilla||443||100 || 95 || 80 || 90 || 2015-02-03 || 2018-02-02 || RSA2048 || SHA256wRSA || Y || Y || Y || N || N || Y || Y || N || N || N || "intermediate" när OCSP || Kortvarig HSTS, OBS: Alternative name: *.bug-attachments.lysator.liu.se |
|bugzilla||[https://www.ssllabs.com/ssltest/analyze.html?d=bugzilla.lysator.liu.se&hideResults=on bugzilla] ||443||100 || 95 || 80 || 90 || A || 2015-02-03 || 2018-02-02 || RSA2048 || SHA256wRSA || Y || Y || Y || N || N || Y || Y || N || N || N || "intermediate" när OCSP || Kortvarig HSTS, OBS: Alternative name: *.bug-attachments.lysator.liu.se |
||
|- |
|- |
||
|datorhandbok||datorhandbok||443||100||95||80||90||2015-02-03 || 2018-02-02 || RSA2048 || SHA256wRSA || Y || Y || Y || N || N || Y || N || N || N || N || "intermediate" när OCSP || |
|datorhandbok||[https://www.ssllabs.com/ssltest/analyze.html?d=datorhandbok.lysator.liu.se&hideResults=on datorhandbok] ||443||100||95||80||90|| A ||2015-02-03 || 2018-02-02 || RSA2048 || SHA256wRSA || Y || Y || Y || N || N || Y || N || N || N || N || "intermediate" när OCSP || |
||
|- |
|- |
||
|enodia || |
|enodia ||[https://www.ssllabs.com/ssltest/analyze.html?d=enodia.lysator.liu.se&hideResults=on enodia] ||443 || 100 || 95 || 80 || 90 || || 2012-07-26 || 2015-07-27 || RSA2048 || SHA1wRSA || Y || Y || Y || N || N || Y || N || N || N || N || "intermediate" när OCSP och SHA256 || ska avvecklas alt. nyinstalleras |
||
|- |
|- |
||
|ftp || ftp || 443 || 100 || 95 || 90 || 90 || 2015-02-03 || 2018-02-02 || RSA2048 || SHA256wRSA || Y || Y || Y || N || N || Y || Y || Y || Y || Y || "intermediate" || |
|ftp || [https://www.ssllabs.com/ssltest/analyze.html?d=ftp.lysator.liu.se&hideResults=on ftp] || 443 || 100 || 95 || 90 || 90 || A || 2015-02-03 || 2018-02-02 || RSA2048 || SHA256wRSA || Y || Y || Y || N || N || Y || Y || Y || Y || Y || "intermediate" || |
||
|- |
|- |
||
|gluten || git |
|gluten || [https://www.ssllabs.com/ssltest/analyze.html?d=git.lysator.liu.se&hideResults=on git] || 443 || 100 || 95 || 80 || 90 || A+ || 2015-02-03 || 2018-02-02 || RSA2048 || SHA2wRSA || Y || Y || Y || N || N || Y || Y || N || Y || N || "intermediate" || |
||
|- |
|- |
||
|httpkom ||httpkom ||443 || 100 || 95 || 90 || 90 || 2015-02-03 || 2018-02-02 || RSA2048 || SHA256wRSA || Y || Y || Y || N || N || Y || N || N || N || N || "intermediate" när OCSP || |
|httpkom ||[https://www.ssllabs.com/ssltest/analyze.html?d=httpkom.lysator.liu.se&hideResults=on httpkom ||443 || 100 || 95 || 90 || 90 || A || 2015-02-03 || 2018-02-02 || RSA2048 || SHA256wRSA || Y || Y || Y || N || N || Y || N || N || N || N || "intermediate" när OCSP || |
||
|- |
|- |
||
|bernadotte ||imap || 143 || || || || || 2012-09-02||2015-09-02 || || || || || || || || || || || || || || |
|bernadotte ||imap || 143 || || || || || || 2012-09-02||2015-09-02 || || || || || || || || || || || || || || |
||
|- |
|- |
||
|jabber || lysator.liu.se ||5222|| || || || || 2015-02-03 || 2018-02-02 || RSA2048 || SHA256wRSA || || || || || || || || || || || || [https://xmpp.net/result.php?domain=lysator.liu.se&type=client IM Observatory], Observera CN vid förnyande |
|jabber || lysator.liu.se ||5222|| || || || || ||2015-02-03 || 2018-02-02 || RSA2048 || SHA256wRSA || || || || || || || || || || || || [https://xmpp.net/result.php?domain=lysator.liu.se&type=client IM Observatory], Observera CN vid förnyande |
||
|- |
|- |
||
|jskom ||jskom ||443 || 100 || 95 || 90 || 90 || 2015-02-03 || 2018-02-02 || RSA2048 || SHA256wRSA || Y || Y || Y || N || N || Y || N || N || N || N || "intermediate" när OCSP || |
|jskom ||[https://www.ssllabs.com/ssltest/analyze.html?d=jskom.lysator.liu.se&hideResults=on jskom ||443 || 100 || 95 || 90 || 90 || A ||2015-02-03 || 2018-02-02 || RSA2048 || SHA256wRSA || Y || Y || Y || N || N || Y || N || N || N || N || "intermediate" när OCSP || |
||
|- |
|- |
||
|ldap || ldap || || || |||| || 2014-11-17 || 2017-11-16 || RSA2048 || SHA256wRSA || || || || || || || || || || || || |
|ldap || ldap || || || |||| || ||2014-11-17 || 2017-11-16 || RSA2048 || SHA256wRSA || || || || || || || || || || || || |
||
|- |
|- |
||
|bernadotte ||lists ||443 || 100 || 95 || 80 || 90 || 2014-11-17 || 2017-11-16 || RSA2048 || SHA256wRSA || Y || Y || Y || N || N || Y || N || N || N || N || "intermediate" om OCSP || |
|bernadotte ||[https://www.ssllabs.com/ssltest/analyze.html?d=lists.lysator.liu.se&hideResults=on lists ||443 || 100 || 95 || 80 || 90 || A || 2014-11-17 || 2017-11-16 || RSA2048 || SHA256wRSA || Y || Y || Y || N || N || Y || N || N || N || N || "intermediate" om OCSP || |
||
|- |
|- |
||
|login || login || 443 || 100 || 95 || 90 || 90 || 2015-02-03 || 2018-02-02 || RSA2048 || SHA256wRSA || Y || Y || Y || N || N || Y || Y || Y || Y || Y || "intermediate" || |
|login || [https://www.ssllabs.com/ssltest/analyze.html?d=log.lysator.liu.se&hideResults=on login || 443 || 100 || 95 || 90 || 90 || A || 2015-02-03 || 2018-02-02 || RSA2048 || SHA256wRSA || Y || Y || Y || N || N || Y || Y || Y || Y || Y || "intermediate" || |
||
|- |
|- |
||
|bernadotte ||mail || 25 || || || || || 2012-09-02 || 2015-09-02|| || || || || || || || || || || || || || |
|bernadotte ||mail || 25 || || || || || || 2012-09-02 || 2015-09-02|| || || || || || || || || || || || || || |
||
|- |
|- |
||
|medreg|| medreg|| 443 || 100 || 95 || 80 || 90|| 2015-02-03 || 2018-02-02 || RSA2048 || SHA256wRSA || Y || Y || Y || N || N || Y || N || N || N || N || "intermediate" när OCSP || |
|medreg|| [https://www.ssllabs.com/ssltest/analyze.html?d=medreg.lysator.liu.se&hideResults=on medreg|| 443 || 100 || 95 || 80 || 90|| A || 2015-02-03 || 2018-02-02 || RSA2048 || SHA256wRSA || Y || Y || Y || N || N || Y || N || N || N || N || "intermediate" när OCSP || |
||
|- |
|- |
||
| |
|succubus||[https://www.ssllabs.com/ssltest/analyze.html?d=mrtg.lysator.liu.se&hideResults=on mrtg || 443 || 100 || 95 || 90 || 90 || A+ || 2015-02-03 || 2018-02-02 || RSA2048 || SHA256wRSA || Y || Y || Y || N || N || Y || Y || Y || Y || Y || "intermediate" || |
||
|- |
|- |
||
| |
|succubus||[https://www.ssllabs.com/ssltest/analyze.html?d=nagios.lysator.liu.se&hideResults=on nagios || 443 || 100 || 95 || 90 || 90 || A || 2015-02-03 || 2018-02-02 || RSA2048 || SHA256wRSA || Y || Y || Y || N || N || Y || N || Y || Y || Y || "intermediate" || |
||
|- |
|- |
||
| |
|succubus||[https://www.ssllabs.com/ssltest/analyze.html?d=nagiosql.lysator.liu.se&hideResults=on nagiosql || 443 || 100 || 95 || 90 || 90 || A+ || 2015-02-03 || 2018-02-02 || RSA2048 || SHA256wRSA || Y || Y || Y || N || N || Y || Y || Y || Y || Y || "intermediate" || |
||
|- |
|- |
||
|pop ||pop || || || || || || || || || || || || || || || || || || || || || |
|pop ||pop || || || || || || || || || || || || || || || || || || || || || |
||
|- |
|- |
||
|proxar ||proxar || 8006 || || || || || 2015-02-03 || 2018-02-02 || RSA2048 ||SHA256wRSA|| || || || || || || || || || ||bad || |
|proxar ||proxar || 8006 || || || || || || 2015-02-03 || 2018-02-02 || RSA2048 ||SHA256wRSA|| || || || || || || || || || ||bad || |
||
|- |
|- |
||
|proxer ||proxer || 8006 || || || || || 2015-02-03 || 2018-02-02 || RSA2048 ||SHA256wRSA || || || || || || || || || || ||bad || |
|proxer ||proxer || 8006 || || || || || || 2015-02-03 || 2018-02-02 || RSA2048 ||SHA256wRSA || || || || || || || || || || ||bad || |
||
|- |
|- |
||
|thinlinc ||thinlinc || || || || || || || || || || || || || || || || || || || || || |
|thinlinc ||thinlinc || || || || || || || || || || || || || || || || || || || || || |
||
|- |
|- |
||
|webkom ||webkom ||443 || 100 || 95 || 90 || 90 || 2012-07-26 || 2015-09-01 || RSA2048 || SHA1wRSA || Y || Y || Y || N || N || Y || N || N || N || N || "intermediate" när OCSP och SHA256 || ska avvecklas. |
|webkom ||[https://www.ssllabs.com/ssltest/analyze.html?d=webkom.lysator.liu.se&hideResults=on webkom] ||443 || 100 || 95 || 90 || 90 || A || 2012-07-26 || 2015-09-01 || RSA2048 || SHA1wRSA || Y || Y || Y || N || N || Y || N || N || N || N || "intermediate" när OCSP och SHA256 || ska avvecklas, är bara redirect till jskom. |
||
|- |
|- |
||
|bernadotte ||webmail ||443 || 100 || 95 || 80 || 90 || 2012-07-26 || 2015-09-01 || RSA2048 || SHA1wRSA || Y || Y || Y || N || N || Y || N || N || N || N || "intermediate" när OCSP och SHA256 || |
|bernadotte ||[https://www.ssllabs.com/ssltest/analyze.html?d=webmail.lysator.liu.se&hideResults=on webmail] ||443 || 100 || 95 || 80 || 90 || A || 2012-07-26 || 2015-09-01 || RSA2048 || SHA1wRSA || Y || Y || Y || N || N || Y || N || N || N || N || "intermediate" när OCSP och SHA256 || |
||
|- |
|- |
||
|webware ||webware ||443 || 100 || 95 || 80 || 90 || 2012-07-26 || 2015-07-27 || RSA2048 ||SHA1wRSA || Y || Y || Y || N || N || P || N || N || N || N || "intermediate" när OCSP och SHA256 || ska avvecklas. |
|webware ||[https://www.ssllabs.com/ssltest/analyze.html?d=webware.lysator.liu.se&hideResults=on webware] ||443 || 100 || 95 || 80 || 90 || A || 2012-07-26 || 2015-07-27 || RSA2048 ||SHA1wRSA || Y || Y || Y || N || N || P || N || N || N || N || "intermediate" när OCSP och SHA256 || ska avvecklas. |
||
|- |
|- |
||
|nyarlathotep || www || 443 || 100 || 95 || 80 || 90 || 2014-04-23 || 2017-04-22 || RSA2048 || SHA1wRSA || Y || Y || Y || N || N || Y || N || N || N || N || "intermediate" när OCSP och SHA256 || |
|nyarlathotep || [https://www.ssllabs.com/ssltest/analyze.html?d=www.lysator.liu.se&hideResults=on www] || 443 || 100 || 95 || 80 || 90 || A || 2014-04-23 || 2017-04-22 || RSA2048 || SHA1wRSA || Y || Y || Y || N || N || Y || N || N || N || N || "intermediate" när OCSP och SHA256 || |
||
|} |
|} |
||
Versionen från 11 februari 2015 kl. 12.17
https://www.ssllabs.com/ssltest/analyze.html är användbar för snabb överblick över vad som kan förbättras för ett cert, även https://github.com/jvehent/cipherscan med bl.a. analyze.py kan vara behjälplig.
https://wiki.mozilla.org/Security/Server_Side_TLS går igenom mycket som är bra att veta om hur man ställer in sin httpd, t.ex. cipher suites osv.
Inventering av certifikat
host | CN | port | Certificate | Protocol support | Key exchange | Cipher strength | Rating | Valid from | Valid until | Key | Signature algorithm | TLS1.2 | TLS1.1 | TLS1.0 | SSL3 | SSL2 | PFS | HSTS | OCSP | NPN | SPDY | analyze.py (mozilla-nivå) | annat |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
webware | admin | 443 | 100 | 95 | 90 | 90 | A+ | 2014-11-17 | 2017-11-16 | RSA2048 | SHA256wRSA | Y | Y | Y | N | N | Y | Y | Y | Y | Y | "intermediate" | |
bugzilla | bugzilla | 443 | 100 | 95 | 80 | 90 | A | 2015-02-03 | 2018-02-02 | RSA2048 | SHA256wRSA | Y | Y | Y | N | N | Y | Y | N | N | N | "intermediate" när OCSP | Kortvarig HSTS, OBS: Alternative name: *.bug-attachments.lysator.liu.se |
datorhandbok | datorhandbok | 443 | 100 | 95 | 80 | 90 | A | 2015-02-03 | 2018-02-02 | RSA2048 | SHA256wRSA | Y | Y | Y | N | N | Y | N | N | N | N | "intermediate" när OCSP | |
enodia | enodia | 443 | 100 | 95 | 80 | 90 | 2012-07-26 | 2015-07-27 | RSA2048 | SHA1wRSA | Y | Y | Y | N | N | Y | N | N | N | N | "intermediate" när OCSP och SHA256 | ska avvecklas alt. nyinstalleras | |
ftp | ftp | 443 | 100 | 95 | 90 | 90 | A | 2015-02-03 | 2018-02-02 | RSA2048 | SHA256wRSA | Y | Y | Y | N | N | Y | Y | Y | Y | Y | "intermediate" | |
gluten | git | 443 | 100 | 95 | 80 | 90 | A+ | 2015-02-03 | 2018-02-02 | RSA2048 | SHA2wRSA | Y | Y | Y | N | N | Y | Y | N | Y | N | "intermediate" | |
httpkom | [https://www.ssllabs.com/ssltest/analyze.html?d=httpkom.lysator.liu.se&hideResults=on httpkom | 443 | 100 | 95 | 90 | 90 | A | 2015-02-03 | 2018-02-02 | RSA2048 | SHA256wRSA | Y | Y | Y | N | N | Y | N | N | N | N | "intermediate" när OCSP | |
bernadotte | imap | 143 | 2012-09-02 | 2015-09-02 | |||||||||||||||||||
jabber | lysator.liu.se | 5222 | 2015-02-03 | 2018-02-02 | RSA2048 | SHA256wRSA | IM Observatory, Observera CN vid förnyande | ||||||||||||||||
jskom | [https://www.ssllabs.com/ssltest/analyze.html?d=jskom.lysator.liu.se&hideResults=on jskom | 443 | 100 | 95 | 90 | 90 | A | 2015-02-03 | 2018-02-02 | RSA2048 | SHA256wRSA | Y | Y | Y | N | N | Y | N | N | N | N | "intermediate" när OCSP | |
ldap | ldap | 2014-11-17 | 2017-11-16 | RSA2048 | SHA256wRSA | ||||||||||||||||||
bernadotte | [https://www.ssllabs.com/ssltest/analyze.html?d=lists.lysator.liu.se&hideResults=on lists | 443 | 100 | 95 | 80 | 90 | A | 2014-11-17 | 2017-11-16 | RSA2048 | SHA256wRSA | Y | Y | Y | N | N | Y | N | N | N | N | "intermediate" om OCSP | |
login | [https://www.ssllabs.com/ssltest/analyze.html?d=log.lysator.liu.se&hideResults=on login | 443 | 100 | 95 | 90 | 90 | A | 2015-02-03 | 2018-02-02 | RSA2048 | SHA256wRSA | Y | Y | Y | N | N | Y | Y | Y | Y | Y | "intermediate" | |
bernadotte | 25 | 2012-09-02 | 2015-09-02 | ||||||||||||||||||||
medreg | [https://www.ssllabs.com/ssltest/analyze.html?d=medreg.lysator.liu.se&hideResults=on medreg | 443 | 100 | 95 | 80 | 90 | A | 2015-02-03 | 2018-02-02 | RSA2048 | SHA256wRSA | Y | Y | Y | N | N | Y | N | N | N | N | "intermediate" när OCSP | |
succubus | [https://www.ssllabs.com/ssltest/analyze.html?d=mrtg.lysator.liu.se&hideResults=on mrtg | 443 | 100 | 95 | 90 | 90 | A+ | 2015-02-03 | 2018-02-02 | RSA2048 | SHA256wRSA | Y | Y | Y | N | N | Y | Y | Y | Y | Y | "intermediate" | |
succubus | [https://www.ssllabs.com/ssltest/analyze.html?d=nagios.lysator.liu.se&hideResults=on nagios | 443 | 100 | 95 | 90 | 90 | A | 2015-02-03 | 2018-02-02 | RSA2048 | SHA256wRSA | Y | Y | Y | N | N | Y | N | Y | Y | Y | "intermediate" | |
succubus | [https://www.ssllabs.com/ssltest/analyze.html?d=nagiosql.lysator.liu.se&hideResults=on nagiosql | 443 | 100 | 95 | 90 | 90 | A+ | 2015-02-03 | 2018-02-02 | RSA2048 | SHA256wRSA | Y | Y | Y | N | N | Y | Y | Y | Y | Y | "intermediate" | |
pop | pop | ||||||||||||||||||||||
proxar | proxar | 8006 | 2015-02-03 | 2018-02-02 | RSA2048 | SHA256wRSA | bad | ||||||||||||||||
proxer | proxer | 8006 | 2015-02-03 | 2018-02-02 | RSA2048 | SHA256wRSA | bad | ||||||||||||||||
thinlinc | thinlinc | ||||||||||||||||||||||
webkom | webkom | 443 | 100 | 95 | 90 | 90 | A | 2012-07-26 | 2015-09-01 | RSA2048 | SHA1wRSA | Y | Y | Y | N | N | Y | N | N | N | N | "intermediate" när OCSP och SHA256 | ska avvecklas, är bara redirect till jskom. |
bernadotte | webmail | 443 | 100 | 95 | 80 | 90 | A | 2012-07-26 | 2015-09-01 | RSA2048 | SHA1wRSA | Y | Y | Y | N | N | Y | N | N | N | N | "intermediate" när OCSP och SHA256 | |
webware | webware | 443 | 100 | 95 | 80 | 90 | A | 2012-07-26 | 2015-07-27 | RSA2048 | SHA1wRSA | Y | Y | Y | N | N | P | N | N | N | N | "intermediate" när OCSP och SHA256 | ska avvecklas. |
nyarlathotep | www | 443 | 100 | 95 | 80 | 90 | A | 2014-04-23 | 2017-04-22 | RSA2048 | SHA1wRSA | Y | Y | Y | N | N | Y | N | N | N | N | "intermediate" när OCSP och SHA256 |
P = Partial
Situationen generellt nu är att SHA1 bör ersättas med SHA256 innan 2016, vilket gör att det vore bra ifall alla certifikat vi har låtit få utgivna sammanställdes t.ex. här, så att man enkelt kan söka dem i klump när det väl drar ihop sig.