D-Link DFL-2500 User Guide - Page 262

Ssl/tls Https

Page 262 highlights

22.3. SSL/TLS (HTTPS) 243 22.3 SSL/TLS (HTTPS) The Secure Sockets Layer (SSL) protocol is a brower-based secure transaction standard alternative to IPsec-based VPNs. It requires little or no software or hardware on remote PCs, and the secure connection is mainly operated by the web browser and the web server, which is a easier implemented and more cost-efficient means compared to the IPsec scheme. Further more, it can easily provide user-by-user authentication. Built upon private key encryption and public key authentication, SSL provides privacy and data integrity between two communicating applications over TCP/IP. In the OSI module, the SSL protocol layer is placed between the connection-oriented network layer protocol TCP/IP and the application layer(e.g. HTTP). It relies on certificates for entity authentication and the entity's public key is used to negotiate the symmetric key for traffic encryption. The Transport Layer Security (TLS), is the successor to SSL and provides much the same functionality but with much firmer standardization and foothold in the IETF. The HTTP running on top of SSL/TLS is often called HTTPS, which is one common use of SSL/TLS to secure web browsing service between a browser and a web server. When you visit "secure" web sites, you may have noticed that the URLs begin with the letters "https://" rather than "http://". This is HTTP wrapped up inside SSL/TLS. Most commonly used web browsers support HTTPS, and more and more web sites use the protocol to obtain confidential user information, such as credit card numbers. There are a number of versions of the SSL/TLS protocol. D-Link firewalls fully support SSLv3 and TLSv1. D-Link Firewalls User's Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365

22.3. SSL/TLS (HTTPS)
243
22.3
SSL/TLS (HTTPS)
The
Secure Sockets Layer (SSL)
protocol is a
brower-based
secure
transaction standard alternative to IPsec-based VPNs.
It requires little or no software or hardware on remote PCs, and the secure
connection is mainly operated by the web browser and the web server,
which is a easier implemented and more cost-efficient means compared to
the IPsec scheme. Further more, it can easily provide user-by-user
authentication.
Built upon private key encryption and public key authentication, SSL
provides privacy and data integrity between two communicating
applications over TCP/IP. In the OSI module, the SSL protocol layer is
placed between the connection-oriented network layer protocol TCP/IP and
the application layer(e.g. HTTP). It relies on
certificates
for entity
authentication and the entity’s public key is used to negotiate the
symmetric key
for traffic encryption.
The
Transport Layer Security (TLS)
, is the successor to SSL and provides
much the same functionality but with much firmer standardization and
foothold in the IETF.
The HTTP running on top of SSL/TLS is often called HTTPS, which is one
common use of SSL/TLS to secure web browsing service between a browser
and a web server. When you visit ”secure” web sites, you may have noticed
that the URLs begin with the letters ”https://” rather than ”http://”.
This is HTTP wrapped up inside SSL/TLS. Most commonly used web
browsers support HTTPS, and more and more web sites use the protocol to
obtain confidential user information, such as credit card numbers.
There are a number of versions of the SSL/TLS protocol. D-Link firewalls
fully support
SSLv3
and
TLSv1
.
D-Link Firewalls User’s Guide