This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Transport Layer Protection Cheat Sheet

From OWASP
Revision as of 01:24, 6 October 2009 by MichaelCoates (talk | contribs)

Jump to: navigation, search

Page is under contruction - [email protected]

Introduction

Benefits

Confidentiality

Integrity

Replay Protection

End Point Authentication

Rules for Transport Layer Protection

Server Configuration

Architecture & Design

Rule #1 - Use SSL for All Login Pages and All Authenticated Pages

Rule #2 - Use SSL on Networks (External and Internal) Transmiting Sensitive Data

Rule #3 - Do Not Provide Non-SSL Pages for Secure Content

Rule #4 - Do Not Perform Redirectsfrom Non-SSL Login to SSL Login Page

Rule #5 - Do Not Mix SSL and Non-SSL Content

Certificate & Protocol Configuration

Configuration

Certificate Considerations

Client Configuration

Certificate Validation

Trusted Root Store

Revocation List Checking

Additional Controls