Our workshop “TLS in the enterprise” was held for the first time at Troopers
2018 and was our special contribution to the IT Security world to increase the
usage of TLS and point out the pitfalls, when switching to TLS.
But time is changing and TLS is a kind of standard nowadays, at least when
looking at HTTPS, but there are still a lot of things to do regarding other
protocols like
Our new workshop about
TLS/SSL in the enterprise
will be held for the 1st time at Troopers 2018. So I would like to take the
opportunity and post a short teaser about stuff we will cover in this workshop.
TLS/SSL is a complicated topic especially in enterprise environments due to the
fact, that
encrypted traffic should be inspected e.g. for malware
customers/users must be able to use important applications
crypto attacks are complex and sometimes considered to be only a problem in
theory
the internal CERT wants to have every issue fixed, if feasible or not 😉
impact of configuration changes can not be foreseen
Software inventory is incomplete (do you want to make a bet that Heartbleed is
fixed completely in your environment ;-)? )
… and so forth
In the workshop we will cover all these points, discuss them and share our
experience regarding feasibility and useful mitigating controls. We will explain
the most common SSL vulnerabilities/attacks, demonstrate tools to test (and
sometimes to exploit) them, point out pitfalls and recommend what to do. Let us
have a look at one example, Heartbleed: