Alliance Global Services

Security – Part III – Validate the client (client side SSL)


RIGHT Blogs                                                               RSS Feed

 

Security – Part III – Validate the client (client side SSL)

Submitted by sgamare on November 17, 2009 - 12:24pm.

This setup is little rare to find. This is typically used in extra secure installations where the server application needs to verify the identity of the client browser who is authorized to access the application. This type of setup is generally limited to within the corporate boundary. Assume an example of a mutual fund sr. trader with access to initiate transactions in multi million dollars. In this case, in addition to login credentials based security, the company wants to ensure that this request comes from a corporate machine registered on the network which has limited applications controlled and managed per corporate standards and it is not a rogue laptop on the network.
The setup in this case is generally a explicit client certificate which is generated using corporate certificate management engine (it might as well be a certificate from Verisign, Thawte, or any other known root provider). This certificate is registered on the client machine and setup to provide that to a specific server based website. During initial requests from the client to the website the client will provide the certificate for validation for the server to validate who he says he is. The server in this case might also be setup to provide certificate to provide who he says he is. The client might be prompted for login credentials by various mechanisms identified in Part I and Part II (on this page). This explicit handshake and login credential validation ensures that the application is being used appropriately by the right party in the correct environment, with "almost" impossible probability for a third party to hack that communication channel.

Feel free to leave me your comments, or request any other types of security setup we can explore

Trackback URL for this post:

http://www.allianceglobalservices.com/trackback/467


sgamare
sgamare
Director of Application Services at Alliance Global Services focused on Rightware, innovative software development practices to drive high value applications.
View my complete profile
 

RIGHT Blog

Alliance’s RIGHTBlog shares our thoughts and experiences of our most valued resource - our people. With extensive experience in four key areas: strategic guidance, outsourced product development, quality assurance and testing, and application maintenance, we share this expert knowledge and personal insight in order to exchange ideas and solutions.


Recent comments

 

 Digg It    Delicious Bookmark this on Delicious    RSS Feed