Tag Archives: SSL

sed syntax error

By royalibrahim

Hi,

In the following excerpt of shell script code: I could not understand the sed syntax. Could anyone shed some light on this?

Code:

configure_ssl()
{
jboss_conf_file=$1
echo "Configuring SSL for -" ${jboss_conf_file}

isSSLSetup=`echo cat ${jboss_conf_file} | grep <Connector port="${jboss_ssl_port}"`
echo "isSSLSetup - " ${isSSLSetup}
if [ -z ${isSSLSetup} ];then
echo " Connector already present. Existing..."
else

sed -e "/.*<Connector port="8080"/ {

<Connector port="${jboss_ssl_port}" address="${jboss.bind.address}"

maxThreads="100" minSpareThreads="5" maxSpareThreads="75"

scheme="https" secure="true" clientAuth="false"

keystoreFile="${keystore_file}"

sslProtocol="TLS" />
};" -i ${CONTROL_PANEL_REPOS_DIR}${jboss_conf_file}

fi
# sed -e "/.*<Connector port="8080"/ { };" -i ${CONTROL_PANEL_REPOS_DIR}${jboss_conf_file}

if [ $? -eq 0 ]; then
echo "SSL was setup successfully for -" ${jboss_conf_file}
else
echo "SSL setup failed for -" ${jboss_conf_file}
fi
}


…read more

Source: FULL ARTICLE at The UNIX and Linux Forums

Following attacks, Networks Solutions reports MySQL hiccups

Network Solutions warned on Monday of latency problems for customers using MySQL databases just a week after the hosting company fended off distributed denial-of-service (DDoS) attacks.

“Some hosting customers using MySQL are reporting issues with the speed with which their websites are resolving,” the company wrote on Facebook. “Some sites are loading slowly; others are not resolving. We’re aware of the issue, and our technology team is working on it now.”

Network Solutions, which is owned by Web.com, registers domain names, offers hosting services, sells SSL certificates and provides other website-related administration services.

On July 17, Network Solutions said it came under a DDoS attack that caused many of the websites it hosts to not resolve. The company said later in the day that most of the problems had been fixed, and it apologized two days later.

To read this article in full or to leave a comment, please click here

…read more

Source: FULL ARTICLE at PCWorld

Network Solutions restores service after DDoS attack

Network Solutions said Wednesday it has restored services after a distributed denial-of-service (DDoS) attack knocked some websites it hosts offline for a few hours.

The company, which is owned by Web.com, registers domain names, offers hosting services, sells SSL certificates and provides other website-related administration services.

Network Solutions wrote on Facebook around mid-day Wednesday EDT that it was under attack. About three hours later, it said most customer websites should resolve normally.

Some customers commented on Facebook, however, that they were still experiencing downtime. Many suggested a problem with Network Solutions’ DNS (Domain Name System) servers, which are used to look up domain names and translate the names into an IP addresses that can be requested by a browser.

To read this article in full or to leave a comment, please click here

…read more

Source: FULL ARTICLE at PCWorld

Restart of services if port no is changed in /etc/services in RHEL

By RHCE

I had a doubt if any services need to be restarted if port no in /etc/services in an RHEL setup is changed. For eg, the port no of 443 for SSL may need to be changed.

I hope my query is clear whether any services need to be restarted if port no in /etc/services is changed.

Please revert with the reply to my query

Regards

From: http://www.unix.com/red-hat/221227-restart-services-if-port-no-changed-etc-services-rhel.html

SSL certificate generation on OS level or application level

By RHCE

We have a RHEL 5.8 server at the production level and we have a Java application on this server. I know of the SSL certificate generation at the OS (RHEL) level but it is implemented on the Java application by our development team using the Java keytool. My doubt is that is the SSL generation can be done at the OS level or at the application level also?

I hope, my query is clear that can the SSL generation be done at the application level also in addition to the SSL generation at the OS level.

Please revert with the reply to my query

Regards

From: http://www.unix.com/red-hat/220843-ssl-certificate-generation-os-level-application-level.html

How to check port used for SSL?

By RHCE

I have RHEL 5.8 in our production environment. We are using SSL, my query is how to find the port used for SSL. In /etc/services, it shows 443 but when I give

Code:

netstat –tulpn | grep 443

Or

netstat –tulp | grep https


I do not get any output.

I hope, my question is clear of how to find the port used for SSL.

Please revert with the reply to my query.

Regards

…read more

Source: FULL ARTICLE at The UNIX and Linux Forums

Ftp: SSL_connect error while connecting from source to destination server Solaris 10

By muraliinfy04

Hi Everyone,
I am using solaris 10.I am facing a different problem here with tlsftp.I have intalled all steps for tlsftp and able to connect to the destination server from the source server.It worked for some days.But recently when i am connectin it is giving below error.I am not finding the exact reason for it.Appreciate your response on it.



ordermp in /orderm $ tlsftp -z opts=33 ftp.elit.eds.com 990
Connected to ftp.elit.eds.com.
ftp: SSL_connect error error:00000000:lib(0):func(0):reason(0)
: Connection reset by peer
Login failed. SSL connection negotiation failed.ordermp in /orderm

Earlier successful connection it worked.


tlsftp -z opts=33
ftp.elit.eds.com 990
Connected to ftp.elit.eds.com.
[SSL Cipher AES128-SHA]
220-
220- Welcome to the ELIT FTP Server
220-
220- Use of this system is restricted to authorized users.
220- User activity is monitored and recorded by system personnel.
220- Anyone using this system expressly consents to such monitoring
220- and recording. BE ADVISED: if possible criminal activity is detected,
220- system records, along with certain personal information,
220- may be provided to law enforcement officials.
220
331 Username “vssmomdev01” needs password
230 User “VSSMOMDEV01” successfully logged in from IP /130.172.153.143
Remote system type is UNIX.
ftp> ls

Appreciate your quick help on this.Advance thanks

…read more

Source: FULL ARTICLE at The UNIX and Linux Forums

CORRECTING and REPLACING ILS Proton Successfully Launches Satmex 8 Satellite for Satmex

By Business Wirevia The Motley Fool

Filed under:

CORRECTING and REPLACING ILS Proton Successfully Launches Satmex 8 Satellite for Satmex

BAIKONUR COSMODROME, Kazakhstan–(BUSINESS WIRE)– In the boilerplate for Satmex, please note removal of the stock exchange and ticker symbol.

The corrected release reads:

ILS PROTON SUCCESSFULLY LAUNCHES SATMEX 8 SATELLITE FOR SATMEX

International Launch Services (ILS), a leader in providing mission integration and launch services to the global commercial satellite industry, today announced that it has successfully carried the Satmex 8 satellite into orbit on an ILS Proton launch vehicle for Satélites Mexicanos S.A. de C.V. (Satmex) of Mexico City, Mexico.

The ILS Proton Breeze M vehicle launched from Pad 39 at the Baikonur Cosmodrome at 01:07 today local time (19:07 GMT and 15:07 EDT on March 26). Utilizing a standard 5-burn Geostationary Transfer Orbit (GTO) mission design, the Breeze M successfully released the Satmex 8 satellite into orbit 9 hours and 13 minutes after launch. The satellite, built on the flight-proven 1300 platform, weighed nearly 5.5 metric tons at liftoff and was the 25th Space Systems/Loral (SSL) satellite launched on an ILS Proton rocket. This was also the first Satmex satellite launched by ILS and the first ILS Proton launch of the year.

Satmex 8 will replace Satmex 5 and will provide enhanced performance and capacity in North, Central and South America at 116.8 west longitude. This new high-power, fixed service satellite has 24 C- and 40 Ku-band transponders, and will improve the current continental and regional services for video contribution and distribution, broadband, cellular backhaul and distance learning.

Satmex 8 adds 45% of total capacity over Satmex 5 which translates to 94% of increased capacity on Ku band to fulfill the growing demand for satellite services in the Americas.

This was the 384th launch for Proton since its maiden flight in 1965 and the 78th ILS Proton launch. The Proton Breeze M vehicle was developed and built by Khrunichev Research and Production Space Center of Moscow, Russia‘s premier space industry manufacturer and majority shareholder in ILS.

“We want to thank Satmex for entrusting us with the launch of the Satmex 8 satellite. We also want to express our sincere appreciation for the ILS, Khrunichev, Satmex, and SSL teams for their tireless work in ensuring the mission’s success,” said ILS President Phil Slack.

Satmex President and CEO Patricio Northland added, “We are delighted with the …read more
Source: FULL ARTICLE at DailyFinance

Andrea Veri: Setting up your SSL certificates on OpenLDAP by using a Mozilla NSS database

I’ve recently spent some time setting up TLS/SSL encryption (SSSD won’t send a password in clear text when an user will try to authenticate against your LDAP server) on an OpenLDAP istance and as you may know the only way for doing that on a RHEL / CentOS environment is dealing with a Mozilla NSS database (which is, in fact, a SQLite database). I’ve been reading all the man pages of the relevant tools available to manipulate Mozilla NSS databases and I thought I would have shared the whole procedure and commands I used to achieve my goal. Even if you aren’t running an RPM based system you can opt to use a Mozilla NSS database to store your certificates as your preferred setup.

On the LDAP (SLAPD) server

Re-create *.db files

mkdir /etc/openldap/certs
modutil -create -dbdir /etc/openldap/certs

Setup a CA Certificate

certutil -d /etc/openldap/certs -A -n “My CA Certificate” -t TCu,Cu,Tuw -a -i /etc/openldap/cacerts/ca.pem
where ca.pem should be your CA’s certificate file.

Remove the password from the Database

modutil -dbdir /etc/openldap/certs -changepw ‘NSS Certificate DB’

Creates the .p12 file and imports it on the Database

openssl pkcs12 -inkey domain.org.key -in domain.org.crt -export -out domain.org.p12 -nodes -name ‘LDAP-Certificate’
pk12util -i domain.org.p12 -d /etc/openldap/certs

where domain.org.key and domain.org.crt are the names of the certificates you previously created at your CA’s website.

List all the certificates on the database and make sure all the informations are correct

certutil -d /etc/openldap/certs -L

Configure /etc/openldap/slapd.conf and make sure the TLSCACertificatePath points to your Mozilla NSS database

TLSCACertificateFile /etc/openldap/cacerts/ca.pem
TLSCACertificatePath /etc/openldap/certs/
TLSCertificateFile LDAP-Certificate

Additional commands

Modify the trust flags if necessary

certutil -d /etc/openldap/certs -M -n “My CA Certificate” -t “TCu,Cu,Tuw”

Delete a certificate from the database

certutil -d /etc/openldap/certs -D -n “My LDAP Certificate”

On the clients (nslcd uses ldap.conf while sssd uses /etc/sssd/sssd.conf)

On /etc/openldap/ldap.conf

BASE dc=domain,dc=org
URI ldaps://ldap.domain.org

TLS_CACERTDIR /etc/openldap/certs
TLS_REQCERT allow

On /etc/sssd/sssd.conf

ldap_tls_reqcert = allow
ldap_uri = ldaps://ldap.domain.org

How to test the whole setup

ldapsearch -x -b 'dc=domain,dc=org' -D "cn=Manager,dc=domain,dc=org" '(objectclass=*)' -H ldaps://ldap.domain.org -W -v

Troubleshooting

If anything goes wrong you can run SLAPD with the following args for its debug mode:

/usr/sbin/slapd -d 256 -f /etc/openldap/slapd.conf -h “ldaps:/// ldap:///”

…read more
Source: FULL ARTICLE at Planet Ubuntu

ILS Proton Successfully Launches Satmex 8 Satellite for Satmex

By Business Wirevia The Motley Fool

Filed under:

ILS Proton Successfully Launches Satmex 8 Satellite for Satmex

BAIKONUR COSMODROME, Kazakhstan–(BUSINESS WIRE)– International Launch Services (ILS), a leader in providing mission integration and launch services to the global commercial satellite industry, today announced that it has successfully carried the Satmex 8 satellite into orbit on an ILS Proton launch vehicle for Satélites Mexicanos S.A. de C.V. (Satmex) of Mexico City, Mexico.

The ILS Proton Breeze M vehicle launched from Pad 39 at the Baikonur Cosmodrome at 01:07 today local time (19:07 GMT and 15:07 EDT on March 26). Utilizing a standard 5-burn Geostationary Transfer Orbit (GTO) mission design, the Breeze M successfully released the Satmex 8 satellite into orbit 9 hours and 13 minutes after launch. The satellite, built on the flight-proven 1300 platform, weighed nearly 5.5 metric tons at liftoff and was the 25th Space Systems/Loral (SSL) satellite launched on an ILS Proton rocket. This was also the first Satmex satellite launched by ILS and the first ILS Proton launch of the year.

Satmex 8 will replace Satmex 5 and will provide enhanced performance and capacity in North, Central and South America at 116.8 west longitude. This new high-power, fixed service satellite has 24 C- and 40 Ku-band transponders, and will improve the current continental and regional services for video contribution and distribution, broadband, cellular backhaul and distance learning.

Satmex 8 adds 45% of total capacity over Satmex 5 which translates to 94% of increased capacity on Ku band to fulfill the growing demand for satellite services in the Americas.

This was the 384th launch for Proton since its maiden flight in 1965 and the 78th ILS Proton launch. The Proton Breeze M vehicle was developed and built by Khrunichev Research and Production Space Center of Moscow, Russia‘s premier space industry manufacturer and majority shareholder in ILS.

“We want to thank Satmex for entrusting us with the launch of the Satmex 8 satellite. We also want to express our sincere appreciation for the ILS, Khrunichev, Satmex, and SSL teams for their tireless work in ensuring the mission’s success,” said ILS President Phil Slack.

Satmex President and CEO Patricio Northland added, “We are delighted with the successful ILS Proton launch and orbit of Satmex 8, the latest satellite in our expanding fleet. Satmex offers fixed satellite transmission services to more than 90% of the population in the Americas, and this important addition will provide enhanced performance and capacity to our coverage areas. It also positions us well for future launches of advanced models that will mark …read more
Source: FULL ARTICLE at DailyFinance

U.S. Department of Energy Honors PPG Scientists for Advances in OLED Lighting

By Business Wirevia The Motley Fool

Filed under:

U.S. Department of Energy Honors PPG Scientists for Advances in OLED Lighting

PPG develops low-cost integrated glass substrate for commercial OLED lighting

PITTSBURGH–(BUSINESS WIRE)– PPG Industries (NYS: PPG) has been recognized by the U.S. Department of Energy (DOE) for “significant achievements” in advancing organic light-emitting diode (OLED) lighting technology. Dennis O’Shaughnessy, Ph.D., PPG associate director for flat glass research and development, accepted the award on behalf of the PPG team during the 2013 Solid-State Lighting (SSL) R&D (Research and Development) Workshop in Long Beach, Calif.

PPG‘s advances are the result of a two-year project initiated with the DOE in 2010 to promote the commercialization and mass production of OLED lighting. The PPG team led by Abhinav Bhandari, Ph.D., project engineer, has demonstrated a float glass-based integrated substrate with scalable light-extraction technologies and transparent conductive films for OLED lighting applications.

The results indicate significant cost and performance advantages over conventional indium tin oxide (ITO)-coated display-grade glass substrates. PPG‘s light-extraction technologies are compatible with the conventional float glass manufacturing process and result in significant enhancement of device efficiencies, according to O’Shaughnessy.

Dick Beuke, PPG vice president, flat glass, said the new glass substrate is one of several major initiatives PPG is advancing to reduce energy use in the U.S. “At PPG, we are proud to be developing glass technologies to make OLED lighting more viable for mass use,” he said. “This research enhances and complements the work our scientists are doing in architectural glass and coatings to make homes and buildings more energy efficient, and in solar technology to help that industry achieve grid parity.”

Mehran Arbab, Ph.D., PPG director, glass science and technology, said, “OLED lights have the potential to emit four times as much light per watt as incandescent bulbs. Widespread commercial use of this technology could significantly reduce energy use in homes, buildings and workplaces.”

PPG was the only company honored in the OLED lighting area at the three-day workshop, which brought together nearly 300 researchers, manufacturers and industry insiders who are promoting and monitoring the latest developments in SSL technology. The DOE supports SSL R&D efforts to accelerate market introduction of high-efficiency, high-performance SSL products. Its mission for the SSL R&D portfolio is to “create a new, U.S.-led market for high efficiency, general illumination products through the advancement of semiconductor technologies, to save energy, reduce costs and enhance the quality of the lighted environment.”

PPG: BRINGING …read more
Source: FULL ARTICLE at DailyFinance

GE's Albeo™ LED High Bay Lighting Fixture Wins 2013 Product Innovation Award

By Business Wirevia The Motley Fool

Filed under:

GE’s Albeo™ LED High Bay Lighting Fixture Wins 2013 Product Innovation Award

EAST CLEVELAND, Ohio–(BUSINESS WIRE)– (NYSE: GE) – GE Lighting’s Albeo™ ABHX-Series LED High Bay Lighting fixture, a product of its recent acquisition of Albeo Technologies, has earned a 2013 Architectural SSL Magazine Product Innovation Award. The award recognizes cutting-edge LED and solid-state luminaires and fixtures.

GE Lighting’s Albeo(TM) ABHX-Series LED High Bay lighting fixture is an ideal solution for business owners looking for quality high bay luminaires that reduce maintenance and energy costs. (Photo: General Electric)

The ABHX-Series LED lighting fixture can replace a range of legacy lighting systems—400-watt to 1500-watt HID and four- to eight-lamp T5/T8 HIF high-bay lighting—in warehouses, storage areas and other commercial spaces with high ceilings. It can be equipped with wireless and motion controls, and it offers more lumens from fewer modules compared to the original award-winning H-Series, which was the first one-for-one LED replacement for up to 1500-watt metal-halide systems.

“Winning the Product Innovation Award from SSL validates our distinct way of approaching the high bay market,” said Jeff Bisberg, CEO of Albeo Technologies, a GE Lighting business. “LED high bay lighting has significant growth potential for industrial buildings and warehouses because of its tremendous light quality and cost savings. We are committed to offering the very best high bay products that will save business owners in maintenance and energy costs while fulfilling their unique lighting needs.”

Two dozen designers and lighting specialists comprised the judges panel, which recognized manufacturers for outstanding products with attributes, qualities, functionality and/or performance beyond industry standards.

For more information about GE‘s high bay fixtures, visit www.gelighting.com. To learn more about GE‘s commitment to innovative solutions to today’s environmental challenges while driving economic growth, visit www.ecomagination.com.

About GE Lighting

GE Lighting invents with the vigor of its founder Thomas Edison to develop energy-efficient solutions that change the way people light their world in commercial, industrial, municipal and residential settings. The business employs about 15,000 people in more than 100 countries, and sells products under the Reveal® and Energy Smart® consumer brands, and Evolve™, GTx™, Immersion™, Infusion™, Lumination™, Albeo™ and Tetra® commercial brands, all trademarks of GE. General Electric (NYS: GE) works on things that matter to build a world that works better. For more information, …read more
Source: FULL ARTICLE at DailyFinance

Konversation 1.5-rc1 (KDE Chat Application)

Thumbnail

Konversation 1.5-rc1
(KDE Chat Application)
Konversation is a user-friendly Internet Relay Chat (IRC) client built on the KDE Platform.

— What’s new —

1.5-rc1:
Konversation 1.5-rc1 is the first test release for our next major release. The 1.5 development cycle has lead to significant new features in many areas of the application, from support for SASL and client certificate authentication on the protocol side, to all-new topic management UI, overhauled authentication UI, per-tab spell-checking language settings, user-configurable nick context menu entries and mouse spring-loading in the frontend and all-new versions of major bundled scripts. Improved Ignore, Watched Nicknames and Edit Paste functionality and behavior, performance improvements in some critical codepaths and many other bug fixes and minor UI touch-ups round things out.

1.4:
The dominant theme in Konversation v1.4 is improvements and feature additions to the user interface, particularly to text views, dialogs, (context) menus and input line commands. However, nearly all areas of the application have seen some amount of improvements in this release, as is to be expected given the relatively long relase cycle: Connection behavior, IRC protocol handling, scripting support, encryption support, user documentation – new features, polish and certainly also bug fixes are to be found in all of them. In summary, we hope you will enjoy the best Konversation yet.

— Essential links —

Konversation’s website: http://konversation.kde.org/
Wiki: http://userbase.kde.org/Konversation
Report bugs and wishes at: https://bugs.kde.org/enter_bug.cgi?product=konversation
Older releases: http://konversation.kde.org/wiki/Releases

changelog:
Changes from 1.4 to 1.5-rc1:
* The user interface for the Auto Identify settings in the Identities dialog has been extended by a combo box that allows choosing the type of authentification to be performed. Depending on the chosen type, different input fields are shown below the combo box.
* The server password-based authentification supported by some networks is now configurable in the Identities dialog as well, making it more discoverable and allowing to keep Auto Identify settings generally with the Identity rather than requiring going through the Edit Server dialog.
* SASL PLAIN authentification is now supported. To use, pick SASL as the Auto Identify type in the Identities dialog and fill in your account name and password.
* Standard NickServ authentification has been further improved. The command sent to to the service, previously hard-coded to “identify”, is now configurable, and the name of the service now defaults to “nickserv” in new identities (the previous default was an empty field).
* Added support for authenticating via a SSL Client Certificate in the form of a PEM file if Konversation is built against KDE Platform v4.8.3 or higher. Choosing this type of authentication in the Identities dialog forces SSL to be enabled for a connection, overriding any server settings.
* Added the ability to set a different spell-checking language for every tab, from the context menu of the input box. The chosen language setting is preserved across application restarts.
* The Topic tab …read more
Source: FULL ARTICLE at KDE Apps

Jabber/XMPP with latest Plasma Active on Nexus 7

accounts-ui

With the latest Plasma Active rootfs tarball for Nexus 7 there is also working Jabber/XMPP. I didn’t notice this at first as the system time was set two years in the past and due to this the certificate for the Jabber server was silently failing.

Essentially, instant messaging functionality is provided via telepathy. This way different IM protocols (like Jabber/XMPP or ICQ) can be used. Right now there is “just” support for Jabber/XMPP working in the current Plasma Active version.

The tools/apps used for getting everything to work are the apps from Nemomobile: accounts-ui and qmlmessages (“Messages” in apps view). Both come pre-installed with the latest Plasma Active Nexus 7 rootfs tarball.

I set up Jabber/XMPP as follows:

  1. Open the “accounts-ui” app.
  2. Add a new XMPP account (first field is username@jabber-server.com, second field is the password).
  3. Click the newly created account.
  4. In the menu chose first “Enable” and afterwards “Request Online”.
  5. Refresh. You should see your presence (in the field “Current:”) change to “available”.

Make sure that your system time is set properly and that your jabber-server has a valid SSL certificate. Self-signed certificates (e.g., as is the case for jabber.org) won’t work. Also note that you won’t get feedback if something with the certificate is wrong. It will simply appear to be stuck in changing your presence.

To chat open the qmlmessages (“Messages” in apps view) app and start a chat with someone. The “To:” name is your-buddies-username@your-buddies-jabber-server.org.

accounts-ui-new-account
accounts-ui-fresh-account
accounts-ui-fresh-account-menu
accounts-ui-fresh-account-enabled-connecting
chat

…read more
Source: FULL ARTICLE at Planet KDE

Dell SonicWALL SuperMassive E10800 Earns Coveted 'Recommend' Rating in NSS Labs 2013 Next Generation

By Business Wirevia The Motley Fool

Filed under:

Dell SonicWALL SuperMassive E10800 Earns Coveted ‘Recommend’ Rating in NSS Labs 2013 Next Generation Firewall Security Value Map for Second Year in a Row

  • Demonstrated one of the highest security effectiveness ratings in the industry, with scores of 100 percent in stability and reliability, firewall, application control and identity awareness tests
  • Resistance to known evasion, obfuscation and fragmentation techniques was perfect
  • Demonstrated scalability with 16.6 Gbps of Next-Gen Firewall performance and multi-gigabit SSL decryption and inspection throughput

ROUND ROCK, Texas–(BUSINESS WIRE)– Dell, a leading provider of connected security offerings, announced today that its Dell SonicWALL™ SuperMassive™ E10800 Next-Generation Firewall running SonicOS 6.0 has earned the highest rating of ‘Recommend’ from NSS Labs, which provides independent validation for IT administrators who seek the best performing security required for their modern corporate network and deployment scenarios. To achieve this ranking, SuperMassive excelled in one of the industry’s most comprehensive, real-world tests of Next-Gen Firewalls and secured a leading position in NSS Labs’ Security Value Map for the second consecutive year.

The SuperMassive demonstrated one of the highest security effectiveness ratings and scored 100 percent in the stability and reliability, firewall, application control, and identity awareness tests. Resistance to known evasion, obfuscation and fragmentation techniques was also perfect, with the Dell SonicWALL Next-Gen Firewall achieving a 100 percent score across the board in all related tests. The SuperMassive E10800 was tested and rated by NSS Labs at 16.6 Gbps of Next-Gen Firewall throughput, and was able to scale into multi-gigabit throughput in the computationally expensive SSL decryption tests while maintaining extremely competitive TCO.

NSS Labs analysis states, “a Next-Gen Firewall must provide granular control based upon applications, not just ports. This capability is needed to re-establish a secure perimeter where unwanted applications are unable to tunnel over HTTP/S. As such, granular application control is a requirement of Next-Gen Firewalls since it enables the administrator to define security policies based upon applications rather than ports alone.” The SuperMassive E10800 earned scores of 100 percent for ‘Block Unwanted Applications’ and for ‘Block Specific Action.’ NSS Labs testing found that the Dell SonicWALL SuperMassive E10800 correctly enforced complex outbound and inbound policies consisting of multiple rules, objects and applications. SuperMassive is capable of enforcing application control on every port, including non-standard ports for a particular application.

According the NSS Labs Next-Generation Firewall Product Analysis, “Resistance to …read more
Source: FULL ARTICLE at DailyFinance

Perl to extract ssl certs from xml file

By jhamaks

HI Guys,

I’m a newbie in perl. I have a task where there’s an xml file which has ssl certs stored in it. The file would look like –

Now, i want to extract each of the SSL certs from this file and store them at some location on the same machine. The cert file to be saved on the disk should have the filename as the common name(CN) of that ssl cert.

I know that using openssl cmd i should get the common name of the cert file, but how to get the common name(CN) from the ssl string (as you see above) instead of file?

Can someone help with any regex to extact the ssl cert from the file of above format ? I guess the tag “” at the end of the string can be used to create the regex ?
Please help.

Thank you.

…read more
Source: FULL ARTICLE at The UNIX and Linux Forums

Microsoft's Tough Friday: Software giant battles hackers, malware, and a cloud outage

While workers at many companies were ending their work week Friday, Microsoft techs were scrambling to put out operational fires.

Late on Friday afternoon, Microsoft discovered that its worldwide Azure cloud service had gone offline when an expired security certificate prevented users from accessing the network.

Meanwhile, the company also discovered that a malware infection already discovered on internal computers at Facebook, Apple, and Twitter had crept into its in-house systems, too.

Azure fails

All encrypted traffic on Azure was disrupted when an SSL certificate expired, Microsoft explained at a company website. Unencrypted traffic was unaffected by the certificate snafu, the company added.

To read this article in full or to leave a comment, please click here

…read more
Source: FULL ARTICLE at PCWorld