Bulletproof TLS and PKI is a complete guide to using TLS encryption and PKI to deploy secure servers and web applications. Written by Ivan Ristic, author of the popular SSL Labs web site, this book will teach you everything you need to know to protect your systems from eavesdropping and impersonation attacks.
In this book, you'll find just the right mix of theory, protocol detail, vulnerability and weakness information, and deployment advice to get your job done:
- Comprehensive coverage of the ever-changing field of SSL/TLS and Internet PKI, with updates to the digital version - For IT professionals, help to understand security risks - For system administrators, help to deploy systems securely - For developers, help to secure web applications - Practical and concise, with added depth as needed - Introduction to cryptography and the Internet threat model - Coverage of TLS 1.3 as well as earlier protocol versions - Discussion of weaknesses at every level, covering implementation issues, HTTP and browser problems, and protocol vulnerabilities - Coverage of the latest attacks, such as BEAST, CRIME, BREACH, Lucky 13, RC4 biases, Triple Handshake Attack, and Heartbleed - Thorough deployment advice, including advanced technologies, such as Strict Transport Security, Content Security Policy, and pinning - Guide to using OpenSSL to generate keys and certificates and to create and run a private certification authority - Guide to using OpenSSL to test servers for vulnerabilities
By:
Ivan Ristic
Imprint: Feisty Duck Ltd
Country of Publication: United Kingdom
Edition: 2nd New edition
Dimensions:
Height: 235mm,
Width: 191mm,
Spine: 26mm
ISBN: 9781907117091
ISBN 10: 1907117091
Pages: 510
Publication Date: 10 January 2022
Audience:
College/higher education
,
Professional and scholarly
,
General/trade
,
Further / Higher Education
,
Undergraduate
Format: Paperback
Publisher's Status: Active
Part I: SSL/TLS and PKI 1. SSL, TLS, and Cryptography 2. TLS 1.3 3. TLS 1.2 4. Public Key Infrastructure Part II: Problems and Attacks 5. Attacks against PKI 6. HTTP and Browser Issues 7. Implementation Issues 8. Protocol Attacks Part III: Deployment and Development 9. Performance 10. HSTS, CSP, and Pinning 11. Configuration Guide Part IV: OpenSSL Command-Line 11. Working with OpenSSL 12. Testing TLS servers with OpenSSL
Ivan Ristic writes computer security books and builds security products. His book Bulletproof TLS and PKI, the result of more than a decade of research and study, is widely recognised as the de-facto SSL/TLS and PKI reference manual. His work on SSL Labs made hundreds of thousands of web sites more secure. Before that, he created ModSecurity, a leading open source web application firewall. More recently, Ivan founded Hardenize, a platform for continuous security monitoring that provides free assessments to everyone. He's a member of Let's Encrypt's technical advisory board.