This month's Heartbleed bug awakened the world to the importance of a healthy SSL public key infrastructure to the proper functioning of the Internet. Yet, despite the continued high growth in SSL traffic, organizations often leave life-cycle management of SSL certificates to spreadsheets, which are labor intensive and error prone, or standalone software solutions, which must be deployed and managed. This creates the risk of a security breach or of a poor customer experience when invalid, expired or otherwise faulty certificates remain in use.
"As our web presence grew organically, we risked losing visibility into the health of our SSL certificate base," said
"It is time for companies to mature the management of their SSL assets," said
Because
- Drill-down charts that summarize statistics about expired or soon-to-expire certificates, top 10 certificate authorities (CA), certificate by key size and self-signed certificates;
- Detailed reports that can be filtered on multiple criteria including issue and expiration dates, key size, host name, validity, self-signed certificates and certificates at risk due to Heartbleed;
- The ability to create charts and reports specific to customer-defined asset groups;
- Access to specific information about each certificate including validity dates, IP address and host, issuer and certificate path, key size, fingerprint, raw certificate data and associated vulnerabilities, including their severity;
- Ability to export data in CSV, XML and other formats.
In addition, customers subscribing to the QualysGuard Continuous Monitoring (CM) service can set up alerts based on SSL certificate information, such as expired/days until expiration, self-signed certificates, name of Certificate Authority, weak key size and other validity measures.
"The SSL public key infrastructure underpins the security of internet traffic and e-commerce," said
Please visit www.qualys.com/heartbleed/ for more information on how to use the new dashboard to help identify certificates that should be revoked because of Heartbleed.
Upcoming Webinar on Heartbleed Recovery
On
About QualysGuard Cloud Platform
The QualysGuard Cloud Platform and its integrated suite of security and compliance solutions help provide organizations of all sizes with a global view of their security and compliance posture, while reducing their total cost of ownership. The QualysGuard Cloud Suite, which includes Vulnerability Management, Continuous Monitoring, Web Application Scanning, Malware Detection Service, Web Application Firewall, Policy Compliance, PCI Compliance, Questionnaire and Qualys SECURE Seal, enables customers to automatically identify their IT assets, collect and analyze large amounts of IT security data, discover and prioritize vulnerabilities and malware, recommend remediation actions and verify the implementation of such actions.
About
For more information, please visit www.qualys.com.
Source:
News Provided by Acquire Media