r rs security measures
play

.R .RS security measures Zarko Kecic, CTO ICANN-62 / June 2018, - PowerPoint PPT Presentation

Registry systems security .R .RS security measures Zarko Kecic, CTO ICANN-62 / June 2018, Panama City New registry software Introduced July 2016 Two ways of access Web application (responsive design) Extended EPP (minor changes)


  1. Registry systems security .R .RS security measures Zarko Kecic, CTO ICANN-62 / June 2018, Panama City

  2. New registry software Introduced July 2016 ▪ Two ways of access ▪ Web application (responsive design) ▪ Extended EPP (minor changes) ▪ Reliable HA system ▪ Modular design solution (easy to maintain) ▪ Plenty of new features Registry systems security / Zarko Kecic TechDay at ICANN62 / June 2018, Panama City

  3. Security by design Static code testing Aggressive stress and penetration tests Automated testing tools (Web and EPP) System Security ▪ Application and Data security ▪ Access control (Edge security) ▪ Reliability (HA - 100% uptime so far) Registry systems security / Zarko Kecic TechDay at ICANN62 / June 2018, Panama City

  4. HA Registry System Registry systems security / Zarko Kecic TechDay at ICANN62 / June 2018, Panama City

  5. Data security Three-tier data processing ▪ Requests processing (Web and EPP) ▪ Registry logic ▪ Data processing/DB access * All network communication is encrypted. Registry systems security / Zarko Kecic TechDay at ICANN62 / June 2018, Panama City

  6. Application security Secured by multiple firewal instances. No direct access from the Internet. Web ▪ IP filtering ▪ SSL/TLS EPP ▪ IP filtering ▪ PSK SSL/TLS Registry systems security / Zarko Kecic TechDay at ICANN62 / June 2018, Panama City

  7. Access control Known system users ▪ IP filtering ▪ SSL/TLS (PSK for EPP access) ▪ Two factor authentication (Web) Registry systems security / Zarko Kecic TechDay at ICANN62 / June 2018, Panama City

  8. Are we really secure? What about Registrar systems? ▪ SSL/TLS communication (some) ▪ 2F authentication (none) ▪ Firewall (some) ▪ Strong password requirements (some) ▪ Separate appliance for customer portal and Registry operations (some) Registry systems security / Zarko Kecic TechDay at ICANN62 / June 2018, Panama City

  9. Additional protection ▪ Registry Lock ▪ Client (Registrar) Lock (Only some registrars have implemented this correctly.) ▪ Secure Mode Any critical operation requires confirmation from a registrant or an admin contact. Registry systems security / Zarko Kecic TechDay at ICANN62 / June 2018, Panama City

  10. Questions? www.rnids.rs рнидс.срб Thank you! www.domen.rs домен.срб Registry systems security / Zarko Kecic TechDay at ICANN62 / June 2018, Panama City

Recommend


More recommend