Know Where Your Digital Certificates and Encryption Keys Are?

Companies today are turning to encryption and digital certificates to secure their data and networks in dramatic numbers, but Venafi, a prov...

Companies today are turning to encryption and digital certificates to secure their data and networks in dramatic numbers, but Venafi, a provider of Enterprise Key and Certificate Management (EKCM) solutions, says most of these security assets are lost, stolen or simply unaccounted for in epidemic proportions.

"One of the things we have experienced through our customers is this explosion in SSL certificates usage," said Jeff Hudson, chief executive officer of Venafi. "There is a groundswell need to make sure servers can identify themselves. When you have one certificate, you have one person managing it, and you have a policy, it's pretty easy. But as you grow, it gets out of control."

In its 2011 Venafi Encryption Key and Digital Certificate Management Report, released Tuesday, the company noted that a staggering 51 percent of respondents said they had experienced either stolen or unaccounted for digital certificates, or they were uncertain if their organizations had lost, stolen or unaccounted for digital certificates. Additionally, 54 percent reported they had experienced either stolen or unaccounted for encryption keys, or that they were uncertain if their organizations had lost, stolen or unaccounted for encryption keys in general.

Venafi compiled its results from market and analyst report research and a 471-respondent survey that included managers to C-level executives from enterprise organizations across a range of industries.

Email Article
Print Article
Comment on this article
Share Articles

"Over half of the people who responded to this survey have unaccounted for digital certificates," Hudson said. "When they look, they have found certificates on that network they didn't know existed. Certificates on servers can enter the network and nobody knows."

Hudson noted that having unaccounted for digital certificates on a network is a bit like running a physical high-security facility and having unauthorized people walking around.

"It doesn't make a lot of sense for obvious reasons," he said. "Losing digital certificates is the same as putting great locks on your doors but then putting a key underneath the mat, giving one to the handy man, all the children, the delivery guy�all of a sudden you have no idea who has access to your house. They keys are all over the place."

It's the same with encryption keys, he said if the keys are not managed, it's not worth encrypting your data.
Related Articles

eEye Automates Vulnerability and Compliance Management
How Cybercriminals Make Their Millions
Cisco: Cybercriminals Will Focus on Money Laundering in 2011
WikiLeaks Raises Questions of Information Security

"If you want to do a good job encrypting you have to know who has the keys and be able to rotate them and expire them," he said.

While digital certificates and encryption keys are critical components of information security programs, they can become dangerous liabilities if they fall into the wrong hands. Hudson noted that it is well documented that digital certificates played a key role in the Stuxnet attack that destroyed multiple centrifuges in an Iranian nuclear facility in July 2010.

Much of the problem with managing digital certificates and encryption keys can be attributed to the explosive growth in their use. Venafi found that 46 percent of its respondents are managing at least 1,000 digital encryption certificates, and 20 percent are managing more than 10,000. Further, 88 percent of organizations have multiple administrators managing encryption keys, and 22 percent have more than 10 administrators managing the keys. In addition, 83 percent of organizations manage technologies from at least two different certificate authorities (CAs), and 18 percent deal with more than five CAs. Forty-two percent of organizations manage encryption technologies from at least four vendors, while eight percent are dealing with more than 10 vendors.

"One of the things we do when we work with prospects is we help them do a survey of where all their certificates are," Hudson said. "Then we sit down and go through what their current processes are for managing these things. Managing this stuff is hugely manually intensive. There are people in it everywhere. Sometimes they aren't even documented."

He added, " All these things are actually about the movement of keys and the movement of data around keys, and all of that can be done in an automated way."

To help manage the problem, Venafi on Tuesday announced Venafi Encryption Director 6, designed to automate management of digital certificates and encryption keys out of the box, with automated discovery, monitoring, validation, management and security. Hudson noted that it is designed for interoperability across heterogeneous environments, and to provide rapid scalability and orchestration capabilities.

Director 6 includes SSH Key Manager, Certificate Manager, Symmetric Key Manager, agent-based onboard discovery and monitoring, advanced management partitioning across firewall boundaries, enhanced operation network validation and alerting, expanded analysis and reporting of consolidated key and certificate management logs, and an actionable key and certificate management dashboard.

Venafi said Encryption Director 6 will ship in the second quarter of 2011.



By Kaila Piyush HackingArticles4all.blogspot.com

COMMENTS

Name

Admin,10,Aircel,2,Airtel,2,Android,10,Android free Application,16,Android Tiricks,12,Angry Birds,2,Apache,1,backtrack5,2,Blogger Tips,4,BSNL,2,cmd,10,Computer Tricks,84,Download,57,Earn More,1,Facebook Symbol,6,Facebook Tricks,12,Games,4,Gaming Tricks,4,Google,6,Google Gravity,1,Google Tricks,14,Google+ Tricks,8,Hackers Special,8,Hacking,69,Hacking Special,8,huawei,3,Idea,2,Increase Backlink,1,internet trick,62,iOS Tricks,1,iPhone Tricks,2,Java Script Trick,2,keygen,6,mobile browser,4,mobile tricks,34,MySQL,1,Notepad Tricks,6,Password Cracking,8,Phishing,2,PHP,1,proxy trick,1,Reliance,1,Samsung,1,Security Tips,9,Server,1,SMTP,1,sql injection,5,Tata Docomo,2,Technology,8,ucweb,4,Unlock Idea Netsetter,5,Unlock iphone,1,Unlock Vodafone all modem,3,Unlock Vodafone ZTE K3770-z,1,Vodafone,2,Web Designing,1,Windows Tricks,22,Wireless Hacking,9,wireless Modem Unlock,6,WordPress Themes,2,Youtube,1,
ltr
item
SMART SUPPORT ME: Know Where Your Digital Certificates and Encryption Keys Are?
Know Where Your Digital Certificates and Encryption Keys Are?
SMART SUPPORT ME
https://smartsupportme.blogspot.com/2011/08/know-where-your-digital-certificates.html
https://smartsupportme.blogspot.com/
http://smartsupportme.blogspot.com/
http://smartsupportme.blogspot.com/2011/08/know-where-your-digital-certificates.html
true
76892010980255686
UTF-8
Loaded All Posts Not found any posts VIEW ALL Readmore Reply Cancel reply Delete By Home PAGES POSTS View All RECOMMENDED FOR YOU LABEL ARCHIVE SEARCH ALL POSTS Not found any post match with your request Back Home Sunday Monday Tuesday Wednesday Thursday Friday Saturday Sun Mon Tue Wed Thu Fri Sat January February March April May June July August September October November December Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec just now 1 minute ago $$1$$ minutes ago 1 hour ago $$1$$ hours ago Yesterday $$1$$ days ago $$1$$ weeks ago more than 5 weeks ago Followers Follow THIS CONTENT IS PREMIUM Please share to unlock Copy All Code Select All Code All codes were copied to your clipboard Can not copy the codes / texts, please press [CTRL]+[C] (or CMD+C with Mac) to copy