{"id":1542,"date":"2019-03-04T01:00:00","date_gmt":"2019-03-04T01:00:00","guid":{"rendered":"http:\/\/inswwdev.azurewebsites.net\/au\/insights\/uncategorized\/ssl-profiles\/"},"modified":"2019-03-04T01:00:00","modified_gmt":"2019-03-04T01:00:00","slug":"ssl-profiles","status":"publish","type":"post","link":"https:\/\/www.insentragroup.com\/nz\/insights\/geek-speak\/secure-workplace\/ssl-profiles\/","title":{"rendered":"SSL Profiles"},"content":{"rendered":"<h3 style=\"padding-bottom: 15px; margin-bottom: 30px; margin-top: 40px; border-bottom: 1px solid #f16020;\">One Click-Tick to SSL Profiles<\/h3>\n<p style=\"text-align: justify;\">It\u2019s estimated more that 70% of today\u2019s internet traffic uses Transport Layer Security (TLS), and its now-deprecated predecessor, Secure Sockets Layer (SSL), to secure communications. With the new data breach laws having come in to effect ensuring that connections to your environment are fully secured is, now more than ever, a critical part of your business.\u00a0 When it comes to Citrix NetScaler services, TLS plays a very big role in securing the end to end communications. SSL profiles are a major component of the configuration in securing communications but are often misconfigured or misapplied.<\/p>\n<p>When configuring services on a NetScaler there are many parameters such as virtual servers, services, service groups, profiles, policies, etc. Collectively these make up the definition of an overall service and ensure its security. A SSL profile is a collection of these parameters that you can apply from single template built to your business requirements to many different services.\u00a0 This template can include protocol enablement and disablement, cipher groups, certificates, SSL and ECC parameters.<\/p>\n<h3 style=\"padding-bottom: 15px; margin-bottom: 30px; margin-top: 40px; border-bottom: 1px solid #f16020;\"><span>What is an SSL Profile?<\/span><\/h3>\n<p style=\"text-align: justify;\">Before we dive into SSL profiles, let\u2019s have a quick overview on the cryptographic protocols. Transport Layer Security (TLS), and its now-deprecated predecessor, Secure Sockets Layer (SSL), are cryptographic protocols designed to provide communications security over a computer network. Several versions of the protocols find widespread use in applications such as web browsing, email, instant messaging, and voice over IP (VoIP). Websites can use TLS to secure all communications between a web server (think NetScaler) and a browser (think client device).<\/p>\n<p style=\"text-align: justify;\">An SSL Profile is a great manageability enhancement and simplifies configuration and control of multiple NetScaler services such as virtual servers, services, service groups, monitors and internet services, from a single configuration item.<\/p>\n<p style=\"text-align: justify;\">The image below describes the services on a NetScaler with different components.<\/p>\n<p style=\"text-align: justify;\">These are:<\/p>\n<ul>\n<li>Ciphers<\/li>\n<li>Cipher groups<\/li>\n<li>SSL Parameters<\/li>\n<li>ECC Curves<\/li>\n<li>SSL Certificates<\/li>\n<\/ul>\n<p><img decoding=\"async\" style=\"width: 783px; height: 584px;\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/18\/2021\/02\/sslprofile_blog_img_1.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/a6ac59b837e34f3ca2a2fed358a0301e\" \/><\/p>\n<p style=\"text-align: justify;\">It takes a lot of time to apply all of these parameters to all your virtual servers, services, service groups etc\u2026 as they need to be manually and individually changed which can also introduce human error. This is where a SSL Profile shines as you can configure once and apply many times!<\/p>\n<p style=\"text-align: justify;\"><img decoding=\"async\" style=\"width: 781px; height: 547px;\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/18\/2021\/02\/sslprofile_blog_img_2.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/bcdf145386334893b2085cc540084e94\" \/><\/p>\n<p style=\"text-align: justify;\">When SSL profiles are used, management is only performed on one entity and then applied as a configuration item to the services. Let\u2019s say you need to update the<span>\u00a0<\/span><strong>Frontend<\/strong><span>\u00a0<\/span><strong>Profile<\/strong><span>\u00a0<\/span>to remove<span>\u00a0<\/span><strong>TLS 1.1<\/strong>, rather than open every configuration and adjust the security settings, you can update the profile and any changes that you make will be updated to all virtual servers that this profile is bound to. That\u2019s it! This will save you time but most importantly, minimises any errors and keeps consistency across services.<\/p>\n<h3 style=\"padding-bottom: 15px; margin-bottom: 30px; margin-top: 40px; border-bottom: 1px solid #f16020;\"><span>Enabling SSL Profiles<\/span><\/h3>\n<p style=\"text-align: justify;\">If you\u2019re not using SSL Profiles in your NetScaler, here\u2019s how to enable it:<\/p>\n<p style=\"text-align: justify;\">Logon to your NetScaler and go to<span>\u00a0<\/span><strong>System<\/strong><span>\u00a0<\/span>\u2013<span>\u00a0<\/span><strong>Profiles<\/strong><span>\u00a0<\/span>\u2013<span>\u00a0<\/span><strong>SSL<\/strong><span>\u00a0<\/span><strong>Profile<\/strong><\/p>\n<p style=\"text-align: justify;\"><strong><img decoding=\"async\" style=\"width: 771px; height: 503px;\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/18\/2021\/02\/sslprofile_blog_img_3.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/067e7d74d0f048dc81dd84fc6523ba85\" \/><\/strong><\/p>\n<p style=\"text-align: justify;\">You can edit the existing profiles or create custom profiles based on the requirements of the services they will protect.<\/p>\n<p style=\"text-align: justify;\">Further, one great configuration option that is included with NetScaler 12.1 or above is the ability to use<span>\u00a0<\/span><strong>Secure<\/strong><span>\u00a0<\/span><strong>SSL<\/strong>. This is an inbuilt SSL Profile that will give you an A+ score once bound to you virtual servers.<\/p>\n<p style=\"text-align: justify;\">To enable this, ensure the below profile is used.<\/p>\n<p style=\"text-align: justify;\"><img decoding=\"async\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/18\/2021\/02\/sslprofile_blog_img_4.jpg\" alt=\"\" width=\"508\" height=\"47\" \/><\/p>\n<p style=\"text-align: justify;\">So, if you are looking to update the security on your NetScaler devices or to address security concerns on sites presented to the external world you should be looking to take advantage of using SSL profiles, which at a minimum will provide you with:<\/p>\n<ul>\n<li>Simplified and improved management of your environment<\/li>\n<li>Ability to make a large number of changes to SSL endpoints from a single location<\/li>\n<li>Ability create custom SSL Profiles to suit your needs<\/li>\n<li>New entities can automatically get the settings from the custom or default assigned SSL Profile, ensuring consistency and security<\/li>\n<\/ul>\n<p style=\"text-align: justify;\"><strong>Thanks for reading<\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>One Click-Tick to SSL Profiles It\u2019s estimated more that 70% of today\u2019s internet traffic uses Transport Layer Security (TLS), and its now-deprecated predecessor, Secure Sockets Layer (SSL), to secure communications. With the new data breach laws having come in to effect ensuring that connections to your environment are fully secured is, now more than ever,&hellip; <a class=\"more-link\" href=\"https:\/\/www.insentragroup.com\/nz\/insights\/geek-speak\/secure-workplace\/ssl-profiles\/\">Continue reading <span class=\"screen-reader-text\">SSL Profiles<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":1543,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"content-type":"","footnotes":""},"categories":[20],"tags":[],"class_list":["post-1542","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-secure-workplace","entry"],"_links":{"self":[{"href":"https:\/\/www.insentragroup.com\/nz\/wp-json\/wp\/v2\/posts\/1542","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.insentragroup.com\/nz\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.insentragroup.com\/nz\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/nz\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/nz\/wp-json\/wp\/v2\/comments?post=1542"}],"version-history":[{"count":0,"href":"https:\/\/www.insentragroup.com\/nz\/wp-json\/wp\/v2\/posts\/1542\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/nz\/wp-json\/wp\/v2\/media\/1543"}],"wp:attachment":[{"href":"https:\/\/www.insentragroup.com\/nz\/wp-json\/wp\/v2\/media?parent=1542"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.insentragroup.com\/nz\/wp-json\/wp\/v2\/categories?post=1542"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.insentragroup.com\/nz\/wp-json\/wp\/v2\/tags?post=1542"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}