SSL Best Practices

BEST PRACTICES

The following information is provided to help you test whether you use SSL version 3, and to help you disable it.
To encourage security best practices, Authorize.Net strongly recommends using the highest version of TLS your configuration will support. For most configurations this should be TLS 1.2.

We also recommend including support for TLS 1.1, in case there are issues with your current TLS 1.2 configuration.

We will allow TLS 1.0 connections as well, but as a best practice we recommend using TLS 1.0 as an option of last resort. We may discontinue support for TLS 1.0 at a future date.

Connections that require SSL v3 will be refused. However, your server may continue to support SSL v3 as long as it uses TLS as its preferred protocol. We recommend disabling SSL v3 as a security best practice, regardless.

TESTING

To test your externally facing server configuration for TLS support, visit https://www.ssllabs.com/ssltest/index.html.

You can compare the results to the Authorize.Net SSL configurations to maximize compatibility with the protocols and ciphers we support: 

For internal servers, a vulnerability scanner or vulnerability management suite may be needed. Here are a few possible options for you. (Note, these are not recommendations--DigitalJetstream does not endorse the use of a particular product, nor do we claim a product is suitable for all uses.)

https://www.trustwave.com/Services/SpiderLabs-Services/Vulnerability-Management/ (commercial)

https://www.qualys.com/enterprises/qualysguard/vulnerability-management/ (commercial)

http://www.tenable.com/products (commercial)

http://www.bolet.org/TestSSLServer/ (open source)

http://code.google.com/p/sslaudit/ (open source)

 

  • 102 Usuários acharam útil
Esta resposta lhe foi útil?

Artigos Relacionados

Who does POODLE affect?

Any merchant using Internet Explorer 6 (IE6) to access secure DigitalJetstream.com pages or any...

How to edit your .htaccess file

Getting To Know Your .htaccess File The .htaccess file contains directives (instructions) that...

What is SSL Version 3 (i.e. SSLv3) and what uses it?

SSLv3 is a cryptographic protocol utilized to securely submit data over the HTTPS protocol....

Why Do I Need SSL

Why do I need an SSL If your website requires someone to enter their personal information,...

What should I do to make sure I can access secure DigitalJetstream pages after November 4th?

If you are using a version of Internet Explorer older than 7.0, please visit...