(Note: This site is for Archive purposes only -SkyWebs is no longer in business.)
|
SSL Authentication and Encryption Stronghold Web Server implements authentication and encryption using the Secure Socket Layer (SSL). SSL is a protocol for transmitting encrypted data over TCP/IP networks. It serves two important purposes:
EncryptionEncryption is the encoding of data in order to hide its content from everyone except its intended recipient. The mathematical algorithms used to encrypt data are called ciphers. The Secure Socket Layer (SSL) is a protocol for exchanging encrypted data over TCP/IP networks, including the World Wide Web. Stronghold Web Server uses SSL to encrypt transactions for privacy. Ciphers fall into two categories:
Symmetric algorithms are faster than public key algorithms, but public key algorithms are required to maintain privacy during the exchange of the faster symmetric keys. To preserve both efficiency and privacy, secure Web transactions begin with a public key exchange, followed by the exchange of a session key that follows a faster, symmetric algorithm.
Session Key Exchange The beginning of a secure Web session works like this:
A session may last for one or many transactions, and a session key encrypts the entire session. Each time a new session begins, the client generates a new session key. In the unlikely event that a third party discovers the session key, he cannot use that key to decrypt subsequent sessions because a new one is generated for every session. The security of the private key in any asymmetric key pair is crucial to the security of a site. To protect your private key, Stronghold stores it in encrypted form and requires a pass phrase on startup. AuthenticationAuthentication is the positive identification of network entities, including clients and sites. Site authentication has been standard on secure servers for some time, because users require assurance that the data they receive from a site is actually being transmitted by that site, rather than by an eavesdropper or "man in the middle." If an eavesdropper can impersonate your site, he can substitute other data in place of the data the user expects to receive. Recently, major browsers also began supporting client authentication. Stronghold Web Server supports both. SSL authentication takes the form of X.509 certificates. Certificates are issued by Certification Authorities (CAs), which act as trusted third parties. Each certificate contains
The CA creates the signature by creating a hash of the body of the certificate, then encrypting it with its private key. Reputable CAs keep their private keys absolutely secret, ensuring that no one can impersonate the CA and issue unauthorized certificates. This prevents a man in the middle from intercepting a certificate, replacing its public key with his own, then spoofing a CA signature for the false certificate. When one entity receives a certificate from another, it first creates a hash of the body of the certificate, then uses the CA's public key to decrypt the signature and reveal the original hash. If the two hash blocks are identical, authentication is successful. Successful authentication verifies that
Once an entity is authenticated, its public key can safely be used to
encrypt subsequent network transactions. Secure E-Commerce Hosting
Use of the SSL server, for secure transmission
of credit card and other sensitive information. SSL: Secure
Socket Layering. Stronghold Web Server (v2.4), 128 bit encryption.
We have partnered with PaymentNet to bring you real-time payment processing via the Net. You may sign up for this service online today. As low as $99 setup and $15/month to begin. Online registration. Cybercash MCK setup is also available. *If you do not already have a merchant account with a financial institution, we can assist you in locating a financial institution to work with your company. |
| Please call (415) 927-WEBS for hosting rates, determined by the size of your site and the level of functionality required. We have solutions to fit every size of business. |
![]() |
![]() |
![]() |
SkyWebs
1001 Bridgeway Ste. 415, Sausalito, CA 94966
Email Phone (800) 961-WEBS
Our Sites
(Note: This site is for Archive purposes only -SkyWebs is no longer in business.)