This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "Transport Layer Protection Cheat Sheet"

From OWASP
Jump to: navigation, search
(Page Creatoin)
 
m
Line 1: Line 1:
= Introduction =
+
Page is under contruction - [email protected]<br>
  
== Benefits ==
+
= Introduction  =
Confidentiality
 
  
Integrity
+
== Benefits  ==
  
Replay Protection
+
Confidentiality
  
End Point Authentication
+
Integrity
  
== Server Configuration ==
+
Replay Protection
  
=== Architectural Design ===
+
End Point Authentication
  
=== Configuration ===
+
= Rules for Transport Layer Protection<br> =
  
=== Certificate Considerations ===
+
== Server Configuration<br> ==
  
== Client Configuration ==
+
=== Architecture &amp;&nbsp;Design ===
  
Certificate Validation
+
=== Rule #1 - Use SSL for All Login Pages and All Authenticated Pages<br> ===
  
Trusted Root Store
+
=== Rule #2 - Use SSL on Networks (External and Internal) Transmiting Sensitive Data<br> ===
  
Revocation List Checking
+
=== Rule #3 - Do Not Provide Non-SSL Pages for Secure Content<br> ===
 +
 
 +
=== Rule #4 - Do Not Perform Redirectsfrom Non-SSL Login to&nbsp;SSL&nbsp;Login Page ===
 +
 
 +
=== Rule #5 - Do Not Mix SSL and Non-SSL&nbsp;Content ===
 +
 
 +
 
 +
 
 +
=== Certificate &amp;&nbsp;Protocol Configuration ===
 +
 
 +
Configuration
 +
 
 +
=== Certificate Considerations  ===
 +
 
 +
== Client Configuration  ==
 +
 
 +
Certificate Validation
 +
 
 +
Trusted Root Store
 +
 
 +
Revocation List Checking  
  
 
== Additional Controls ==
 
== Additional Controls ==

Revision as of 01:24, 6 October 2009

Page is under contruction - [email protected]

Introduction

Benefits

Confidentiality

Integrity

Replay Protection

End Point Authentication

Rules for Transport Layer Protection

Server Configuration

Architecture & Design

Rule #1 - Use SSL for All Login Pages and All Authenticated Pages

Rule #2 - Use SSL on Networks (External and Internal) Transmiting Sensitive Data

Rule #3 - Do Not Provide Non-SSL Pages for Secure Content

Rule #4 - Do Not Perform Redirectsfrom Non-SSL Login to SSL Login Page

Rule #5 - Do Not Mix SSL and Non-SSL Content

Certificate & Protocol Configuration

Configuration

Certificate Considerations

Client Configuration

Certificate Validation

Trusted Root Store

Revocation List Checking

Additional Controls