Managing SSL Certificates in large environment.

Managing SSL Certificates in large environment.

Secure Home | Search | About
 General Computer Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Managing SSL Certificates in large environment. alpaca2009 05-05-2008
Posted by on May 5, 2008, 12:36 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I currently manage certificates in a rapidly growing environment. As
we grow we add more certificates. These certificates are installed on
multiple devices/servers. Each certificate could have separate
instructions for installation. We also host 3rd party certificates on
our devices to provide co-branded web sites. All of this is currently
kept track of in a spreadsheet which includes the common name,
expiration date, contact information of the user who must approve/
disapprove, special installation instructions, and location the
certificate must be installed.

Our certificate authority sends email when we close in on expiration
which helps to remind me to renew the certificate. However this email
notification along with our handy dandy spreadsheet just isn't cutting
it.

Is there anyone out there who manages certificates for a larger
organization? If so can you explain how you manage SSL certificates?
Any information would be helpful to me. I'm looking for any
information. Some things I can think of
-policies you have in place for renewal
-software you use to manage certificates
-how you store copies of the certificates
-how do you send the certificates to other users for installation
(email? do you use pgp?)
-any tools to deploy certificates to multiple cross platform devices


Of course I do many other things besides keep track of and renew
certificates. So anything to make this process more efficient for me
would be greatly appreciated.

Thanks.

Similar ThreadsPosted
how large can a CRL list get? February 27, 2006, 1:58 pm
20th Large Installation System Administration Conference September 11, 2006, 2:49 pm
Encryption Wizard Offers Large Object Binary support for Oracle Customers. May 20, 2005, 12:52 pm
AD-2k3 & SSO in Mac Rich Environment August 15, 2005, 11:46 am
SSRT051004 rev.0 - HP-UX Java Runtime Environment (JRE) Untrusted Applet Elevates Privilege August 30, 2005, 9:42 pm
SSRT051004 rev.1 - HP-UX Java Runtime Environment (JRE) Untrusted Applet Elevates Privilege October 6, 2005, 11:44 am
[security bulletin] SSRT051052 rev.0 - HP OpenView Operations and OpenView VantagePoint Java Runtime Environment (JRE) Remote Privileged Access October 19, 2005, 8:02 pm
[security bulletin] SSRT051052 rev.1 - HP OpenView Operations and OpenView VantagePoint Java Runtime Environment (JRE) Remote Privileged Access October 21, 2005, 6:23 pm
X.509 Digital Certificates March 7, 2005, 8:56 pm
Chaining x.509 certificates April 27, 2005, 3:46 pm

The site map in XML format XML site map

Contact Us | Privacy Policy