Need Suggestions on web server security using SSL.

From: Ken Varn (nospam)
Date: 09/24/04


Date: Fri, 24 Sep 2004 14:23:13 -0400

We are in the process of building a spec. for a network based embedded
device that uses remote web browser configuring. The user will basically
have a logon and password that can be used to access the device. There
could be multiple devices on the network. The customer basically will set
the workstation ID and IP address locally on the device.

We are considering using SSL to protect the logon identity of the user that
accesses our device through Internet Explorer, however, we are limited in
our knowledge of using SSL. One of the bottlenecks that we are trying to
figure out is that an SSL certificate is bound by the ID of the box. If the
user is in control of changing the ID, we need to be able to generate a
certificate that matches that box on the fly. Is there such a mechanism for
doing this or should be looking at a different solution?

The whole SSL thing seems to be tailored around one or more centralized web
servers. Our customers may install hundreds of our devices on their
network. We want to insure the security of the logons to these devices, but
still somehow be able to manage the certificates automatically if the device
ID changes. The use of a trusted authority for generation of the
certificate does not sound like a viable option, we would generate the
certificate ourselves.

Can someone give me information on where I can find out how to incorporate a
solution to using web browser encryption in embedded devices?



Relevant Pages

  • RPC over SSL problem
    ... The Exchange server is a member of the domain and the mailboxes are stored ... I can access OWA through SSL after I accept the certificate with Internet ... I have used the rpcping utility from the inside network and it works. ...
    (microsoft.public.exchange2000.admin)
  • Re: HTTP Authentication
    ... Don't I need some kind of certificate for SSL? ... Generally you'll need a certificate if you are a server. ... of your web browser? ...
    (comp.lang.tcl)
  • Re: Problem with RWW, can list computers/servers, cannot get logge
    ... > other RWW functionality including admining the companyweb. ... > When I browse to that FQDN and the certificate is presented for approval, ... >>> to which the network in connected. ... >>> connection might not be enabled or the computer might be too bust to ...
    (microsoft.public.windows.server.sbs)
  • Re: Isolation of the Root CA
    ... A lot has to do with the complexity of your network and your security needs. ... Certificate Authorities with maybe six or eight issuing CA's for various ... > One major thing I can't seem to grasp is the installation of the Root CA. ...
    (microsoft.public.win2000.security)
  • Re: Problem with RWW, can list computers/servers, cannot get logge
    ... I believe I have the certificate address handled correctly, ... >> to which the network in connected. ... The client could not establis a connection to the remote ... >> connection might not be enabled or the computer might be too bust to ...
    (microsoft.public.windows.server.sbs)