meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, January 10th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 10 January 2019

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Face Recog. Test; Google DNS-over-TLS; Malwarebytes vs Win7

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, January 10th, 2019 edition of the Sands and its Storm Center's Stormcast.

0:08.0

My name is Johannes Ulrich, and the day I'm recording from Jacksonville, Florida.

0:14.2

Now, TLS has really had a real good run over the last couple of years, but one area where it's still somewhat lacking is

0:22.2

internal websites and development websites. There are a couple reasons for that. Now, first of all,

0:28.2

these websites are rightfully so not exposed to the public. So tools like Let's Encrypt, for example,

0:34.7

are a little bit tricky to use in these cases.

0:37.9

The other reason is you may not necessarily want to expose these particular host names and

0:43.6

such you're using two public certificate authorities because that may end up with them showing

0:50.1

up in certificate transparency logs.

0:53.7

So the obvious solution here is to set up your own certificate authority.

0:58.5

Now there are solutions for that, but none of them are really all that intuitive and easy

1:03.5

to use.

1:04.5

Well, Philippo Valcorda now came up with a new tool that should make that easier.

1:11.5

He calls the tool MakeCERT.

1:14.4

When you install it, it automatically creates an internal certificate authority for you.

1:19.7

And then it's really just the simple command line to create random certificates that are

1:26.3

signed with this internal certificate authority. Of course,

1:29.7

all users of the particular site have to trust that certificate authority, but again, for

1:35.4

internal websites that aren't publicly accessible for development websites, that shouldn't really

1:41.2

be a big problem and makes actually testing in some cases easier

1:46.0

because you don't really have to change in the configuration as you move code life.

1:51.0

So the real new part here is how easy it is to use the tool.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.