No Image

Announcing a Change to the Certificate for the NGINX Plus Repository

2016-06-08 KENNETH 0

Announcing a Change to the Certificate for the NGINX Plus Repository In our ongoing efforts to improve the security of our products, we’ve made a change that affects the way NGINX Plus is installed and updated. We are replacing the self-signed certificate we previously used to secure the NGINX Plus repository with a certificate from GlobalSign, a well-known and trusted Certificate Authority (CA). With a CA-signed certificate, clients can now verify the certificate we present and be assured that the code they are downloading is from NGINX. The next time you install or update NGINX Plus, you might see an error such as: On Amazon Linux, CentOS, Oracle Linux, and RHEL: curl#60 – “Peer’s certificate issuer has been marked as not trusted by the user.” On Debian and Ubuntu: server certificate verification failed. CAfile: /etc/ssl/nginx/CA.crt CRLfile: none If you get [ more… ]

No Image

Supporting HTTP/2 for Google Chrome Users

2016-06-08 KENNETH 0

Supporting HTTP/2 for Google Chrome Users table, th, td { border: 1px solid black; } th { background-color: #d3d3d3; align: left; padding-left: 5px; padding-bottom: 2px; padding-top: 2px; line-height: 120%; } td { padding-left: 5px; padding-bottom: 5px; padding-top: 5px; line-height: 120%; } Users of the Google Chrome web browser are seeing some sites that they previously accessed over HTTP/2 falling back to HTTP/1. This is because of a policy change in the most recent update to Chrome, released in late May, which removes support for NPN, one method for upgrading a connection to HTTP/2. The only way Chrome users can continue using HTTP/2 to access these websites is by switching to a different browser. Website administrators can restore HTTP/2 support for Chrome users by upgrading their OpenSSL installation to the recently released 1.0.2 version. Unfortunately, this requires either a major operating system [ more… ]

No Image

Microsoft Bounty Program expansion – .NET Core and ASP.NET RC2 Beta Bounty

2016-06-08 KENNETH 0

Microsoft Bounty Program expansion – .NET Core and ASP.NET RC2 Beta Bounty Today I have another exciting expansion of the Microsoft Bounty Program. Please visit https://aka.ms/BugBounty to find out more. As we approach release for .NET Core and ASP.NET, we would like to get even more feedback from the security research community. We are offering a bounty on the .NET Core and ASP.NET Core RC2 Beta Build which was announced on May 16, 2016. The program highlights are: Bounty applies to .NET Core, ASP.NET Core RC2 and any subsequent release candidates during the bounty period, or the final RTM version if released within the bounty period. Supported platforms are Windows, OS X and Linux. The bounty will run June 7, 2016 to September 7, 2016. Bounty payouts will range from $500 USD to $15,000 USD. You can install the RC2 from [ more… ]

No Image

네트워크 보안 시스템 구축과 보안 관제 – 보안 관제편

2016-06-08 KENNETH 0

네트워크 보안 시스템 구축과 보안 관제 – 보안 관제편 저자 : 장상근 출판사 : 한빛미디어 책정보 : http://www.hanbit.co.kr/realtime/books/book_view.html?p_code=E8691785380   개요 대상 독자 ”보안 시스템을 구축하고 보안 관제를 하려는 기업과 공공기관의 보안 담당자 보안 시스템 구축과 보안 관제를 배우려는 학생” 이라고 저자는 설명을 하고 있다. 더불어 네트워크와 운영체제(Linux)에 대한 기본 지식을 권장 한다. 대상 독자를 쓰려다가 갑자기 기억나서 책의 앞부분을 봤더니 내가 하고 싶은 얘기가 비슷하게 써있다…;   특징 및 장/단점 리눅스에 대한 사전 지식을 요구하긴 하지만 입문자를 위한 책이다. 입문자를 위한 책이라면 리눅스 상에서 보안이든, 서비스 관련 프로그램이든… 명령어를 알려 주는 가장 좋은 방법은 (상황에) 따른 예제를 먼저 보여주고 사용된 옵션을 설명 하는 것 옵션만 장황하게 설명후에, 실제 활용은 학습자의 몫이라면 효율이 조금 떨어질것 같다. 라는 생각을 항상 하고 있다. 이 책은 깊은 내용은 아니지만 전반적인 안내와 프로그램의 사용법을 안내 해주고 있는데.. (내가 좋아하는 ”스토리 텔링” 요소는 없지만 ㅋ)  자세한 설치법 [ more… ]