Skip to main content
  • EDC Logo
  • Solutions
  • Products
  • Partners
  • Support & Services
  • Resources
  • About
  • Search
  • Get Started
    • Contact an Expert
    • Get Support
    • Solutions
      • Strong Identities
        1. Digital Signature
          Use secure, verifiable signatures and seals for digital documents.
        2. Machine Identity
          Issue and manage strong machine identities to enable secure IoT and digital transformation.
        3. User Identity
          Elevate trust by protecting identities with a broad range of authenticators.
        4. Identity Verification
          Enable high assurance identities that empower citizens.
        5. ID Issuance
          Issue safe, secure physical and digital IDs in high volumes or instantly.
      • Secure Payments
        1. Financial Issuance
          Issue physical and digital financial identities and credentials instantly or at scale.
        2. Digital Card Solution
          Issue digital payment credentials directly to cardholders from your bank's mobile app.
      • Trusted Infrastructure
        1. Database Security
          Secure databases with encryption, key management, and strong policy and access control.
        2. Multi-cloud Security
          Secure encryption keys, containers, and data across multi-cloud. environments.
    • Industry
        1. Financial
        2. Government
        3. Education
        1. Enterprise
        2. Healthcare
        3. Retail
    • Compliance
        1. PSD2
        2. HIPAA
        3. GDPR
        1. CMMC
        2. eIDAS
    • Cloud Security, Encryption, and Key Management
      • Cloud Security Posture Management
        1. CloudControl for AWS
        2. CloudControl for Containers
        3. CloudControl for vSphere and NSX
        4. CloudControl Foundation Edition
      • Multi-Cloud Encryption
        1. DataControl for Azure
        2. DataControl for AWS
        3. DataControl for IBM Cloud
      • Key Management
        1. KeyControl
        2. KeyControl BYOK
        3. KeyControl for Backup and Recovery
        4. KeyControl for Databases
        5. KeyControl for Hyperconverged Infrastructure
        6. KeyControl for Storage
    • Digital Certificates
      • TLS/SSL Certificates
        1. Standard OV
        2. Advantage OV
        3. Multi-Domain OV
        4. Multi-Domain EV
        5. Wildcard OV
        6. Private
      • Qualified Certificates
        1. Qualified Electronic Seal Certificates
        2. QWAC eIDAS Certificates
        3. QWAC PSD2 Certificates
      • Sales and Services
        1. Platinum Services
        2. Entrust Certificate Services
        3. Subscription Plans
        4. Knowledge Base and Support
        5. Buy Certificates
        6. Renew Certificates
      • Verified Mark Certificate (VMC) for BIMI Verified Mark Certificate (VMC) for BIMI
        Show your official logo on email communications. Download our white paper to learn all you need to know about VMCs and the BIMI standard.
        Learn More
    • Digital Signing
      • Digital Signing as a Service
        1. Signing Automation Service
        2. Remote Signing Service
      • Signing Certificates
        1. Document Signing
        2. Secure Email
        3. Code Signing
      • Signing Servers
        1. Remote Signing Server
        2. Signing Automation Server
        3. Entrust Timestamping Authority
        4. Entrust Signature Activation Module
    • Hardware Security Modules (HSM)
      • nShield HSMs
        1. nShield Connect
          Networked appliances that deliver cryptographic key services to distributed applications.
        2. nShield Edge
          Personal, USB-connected desktop HSMs.
        3. nShield Solo
          PCI-Express card-based HSMs.
        4. nShield as a Service
          Subscription-based access to dedicated nShield HSMs.
        5. nShield HSMi
      • nShield Software
        1. CodeSafe
        2. Software Option Packs
        3. eIDAS Remote QSCD
      • Management and Monitoring
        1. nShield Monitor
        2. nShield Remote Administration
      • Compliance
        1. FIPS 140-2
        2. GDPR
        3. PSD2
        4. NIST 800-53 Fedramp
        5. Common Criteria
        6. eIDAS
        7. HIPAA
        8. PCI-DSS
        9. Americas
        10. EMEA
        11. APAC
        12. Global
      • Use Cases
        1. Credentialing and PKI Applications
        2. Data Security and Encryption
        3. Cloud Security
        4. Payments
        1. View All Use Cases
    • Identity and Access Management (IAM)
      • Products
        1. Identity as a Service
          Cloud-Based IAM
        2. Identity Enterprise
          On-prem IAM
        3. Identity Essentials
          On-prem MFA solution for Windows users
      • Testimonials
      • Portfolio Capabilities
        1. Multi-Factor Authentication (MFA)
        2. Adaptive Authentication
        3. Passwordless
        4. Single Sign-On
        5. Identity Orchestration
        6. Fraud Protection
      • Workforce Identities
        1. Physical/Logical Access
        2. PIV-Compliant Government Mobility
        3. Privileged Users
        4. Safeguarding Your VPN
        5. Workstation Login
        6. Zero Trust
        7. Security and Access for Contractors
      • For Consumers and Citizens
        1. Consumer Banking
        2. Consumer Identity and Access Management (CIAM)
        3. Customer Portals
        4. Digital Citizen
        5. Digital Onboarding
    • Public Key Infrastructure (PKI)
      • Products
        1. Certificate Hub
        2. Security Manager
        3. Entelligence Security Provider
        4. ePassport
        5. Validation Authority
        6. Key Recovery Server
      • Managed Services
        1. Entrust Managed PKI
        2. PKI as a Service
        3. Cryptography as a Service
        4. Managed Microsoft PKI
        5. Managed Offline Root Certificate Authority
    • Central Issuance
      • Financial Cards
        1. Issuance Systems
        2. Inline Delivery & Insertion
        3. Standalone Delivery & Insertion
        4. Software
        5. Supplies
        6. Services
      • Government Cards
        1. Issuance Systems
        2. Inline Delivery & Insertion
        3. Standalone Delivery & Insertion
        4. Software
        5. Supplies
        6. Services
    • Instant Issuance
      • Financial Cards
        1. Issuance Systems
        2. Software
        3. Supplies
        4. Services
      • ID Cards
        1. Issuance Systems
        2. Software
        3. Supplies
        4. Services
    • Passport issuance
      • Passports
        1. Issuance Systems
        2. Software
        3. Supplies
        4. Services
      • Try Our Passport Credential Builder
        Learn More
    • Partners
      • Become an Entrust Partner
        Our partner programs can help you differentiate your business from the competition, increase revenues, and drive customer loyalty. Consider joining one or more of our Entrust partner programs and strategically position your company and brand in front of as many potential customers as possible.
        Learn More
      • Partner Directory
        Search for partners based on location, offerings, channel or technology alliance partners.
        Search for a Partner
      • Programs
        1. PartnerPlus Channel
        2. Technology Alliance
        3. nFinity HSM Technology Program
        4. IAM Managed Solution Provider
        5. Instant Issuance and Digital Issuance Managed Solution Provider
      • Partner Logins
        1. Partner Central
        2. Entrust Certificate Services Partner Portal
        3. Entrust Certificate Services Portal
        4. TrustedCare
    • Support & Services
      • Contact Support
      • TrustedCare
        Product downloads, technical support, marketing development funds.
        Learn More
      • Digital Security Knowledge Base
        Guides, white papers, installation help, FAQs and certificate services tools.
        Learn More
      • Issuance Systems Knowledge Base
        Technotes, product bulletins, user guides, product registration, error codes and more.
        Learn More
      • PKI Professional Services
      • Cryptographic Center of Excellence
        Construct best practices and define strategies that work across your unique IT environment.
        Learn More
      • Custom Cryptographic Solutions
        1. Code Signing
        2. HSM Application Integration
      • Product Deployment Services
        1. nShield Deployment Health Check
        2. nShield Remote Administration Deployment
        3. Rapid Deployment
      • Packaged Services
        1. Code Signing Gateway
        2. Double Key Encryption Integration
        3. Tokenization Solution
      • Training
        1. nShield Certified Solution Developer Training
        2. nShield Certified System Engineer Course
        3. Public Key Infrastructure Basic Training
    • Resources
      • Issuance Systems Knowledge Base
        Technotes, product bulletins, user guides, product registration, error codes and more.
        Learn More
      • Digital Security Knowledge Base
        Guides, white papers, installation help, FAQs and certificate services tools.
        Learn More
        1. Central Card Issuance
        2. Central Passport Issuance
        3. Instant Financial Card Issuance
        4. Instant ID Issuance
        5. Issuance Software
        1. Certificate Solutions
        2. PKI and IoT
        3. Identity and Access Management
        4. Hardware Security Modules (HSM)
        5. Cloud Security, Encryption and Key Management
        1. Documentation Library
        2. Training
        3. Legal and Compliance
        4. Covid 19 Updates
        5. Russia-Ukraine Conflict
    • About Entrust
      • Securing a World in Motion Since 1969
        We’ve established secure connections across the planet and even into outer space. We’ve enabled reliable debit and credit card purchases with our card printing and issuance technologies. Protected international travel with our border control solutions. Created secure experiences on the internet with our SSL technologies. And safeguarded networks and devices with our suite of authentication products.
        Explore Our History
        1. Leadership
        2. Blog
        3. Careers
        4. Events
        5. Webinars
        6. Podcasts
        7. News Articles
        8. Press Releases
        1. Contact Sales
        2. Contact Support
        3. Locations
      • Cybersecurity Institute Cybersecurity Institute
        Get critical insights and education on security concepts from our Trust Matters newsletter, explainer videos, and the Cybersecurity Institute Podcast.
        Learn More
    • Shop
      • Entrust Certificate Services Portal
        Existing Entrust Certificate Services customers can login to issue and manage certificates or buy additional services.
        Learn More
      • Entrust Certificate Services Retail
        Shop for new single certificate purchases.
        Learn More
      • Entrust Certificate Services Partner Portal
        Existing partners can provision new customers and manage inventory.
        Learn More
      • Instant Financial Card Issuance Supplies
        1. Registered Customer Login
        2. Request Access
    • Search Entrust

SSL Review: November 2018

Bruce Morton December 7, 2018

Entrust Datacard’s monthly SSL review covers SSL/TLS discussions — recaps news, trends and opinions from the industry.

Entrust Datacard…

  • Major Browsers Coordinated on Deprecating TLS 1.0 and 1.1

Half of phishing sites are using HTTPS…

  • Half of all Phishing Sites Now Have the Padlock
  • HTTPS Phishing: 49% of Phishing Websites now sport the green padlock

TLS 1.3 illustrated….

  • The New Illustrated TLS Connection

Bulletproof TLS Newsletter …

  • Bulletproof TLS Newsletter #47 – Attacking cryptography with side channels<

Other News & Notes

  • Introducing Cert Spotter API 1.0 – The Easiest Way To List A Domain’s Certificates
  • Petition: Add the .gov TLD to the HSTS preload list
  • HTTP/3 is here… sort of
  • Apple Safari testing “Not Secure” warning for HTTP websites
  • Sennheiser’s HeadSetup software is vulnerable to MITM attacks
  • Abuse MITM possible regardless of HTTPS
  • Executing a Man-in-the-Middle Attack in just 15 Minutes
Tags:

  • SSL Review
  • SSL
  • TLS
  • HTTP/3
  • Sennheiser
  • Certificate Services
Bruce Morton / VIEW ALL Bruce'S POSTS Director for Certificate Services

Bruce Morton is a pioneering figure in the PKI and digital certificate industry. He currently serves as Director for Certificate Services at Entrust, where he has been employed since 1997. His day-to-day responsibilities include managing standards implementations, overseeing Entrust’s policy authority, and monitoring Entrust Certificate Service for industry compliance.

Contact
  • Contact Sales
  • Contact Support
  • Find a Location
Company
  • About
  • Careers
  • Events
  • Webinars
Newsroom
  • Blog
  • Press Releases
  • News
Product Resources
  • Entrust Store
  • Resources
  • Library
  • Training
  • Legal and Compliance
  • Covid 19 Updates
Social
  • Twitter
  • Facebook
  • Instagram
  • LinkedIn
  • YouTube

  • English
  • 中文
  • Português
  • Français
  • Deutsch
  • Русский
  • 한국어
  • Español
  • Italiano
  • 日本語
  • Legal
  • Privacy Statement
  • Terms of Service
  • Company Policies
©2022 Entrust Corporation. All rights reserved.