Comodo Certificate Manager

Similar documents
Comodo Certificate Manager

Comodo SecureBox Management Console Software Version 1.9

Comodo Certificate Manager Version 5.7

IMPLEMENTING A SOLUTION FOR ASSURING KEYS AND CERTIFICATES

Domain Control Validation in Comodo Certificate Manager

Cloud SSL Certificate Services

Comodo cwatch Web Security Software Version 1.1

Comodo Certificate Manager Version 5.7

Comodo Certificate Manager

Comodo Certificate Manager

Comodo Certificate Manager Software Version 5.6

ABOUT COMODO. Year Established: 1998 Ownership: Private Employees: over 700

Comodo Certificate Manager

Comodo Certificate Manager Version 5.7

Comodo Certificate Manager Software Version 5.7

Comodo One Software Version 3.16

Comodo Certificate Manager

SHA-1 to SHA-2. Migration Guide

Comodo Certificate Manager Version 6.0

Domain Control Validation in Comodo Certificate Manager

Comodo Certificate Manager

Comodo Certificate Manager

Comodo Certificate Manager Software Version 5.0

Enterprise Certificate Console. Simplified Control for Digital Certificates from the Cloud

Comodo cwatch Web Security Software Version 1.0

Comodo ONE Software Version 1.8

Comodo Certificate Manager Version 5.4

Comodo IT and Security Manager Software Version 6.4

Comodo One Software Version 3.3

Comodo Certificate Manager

Comodo One Software Version 3.3

Comodo Certificate Manager. Centrally Managing Enterprise Security, Trust & Compliance

VSP18 Venafi Security Professional

Comodo IT and Security Manager Software Version 6.6

Aerohive and IntelliGO End-to-End Security for devices on your network

Comodo IT and Security Manager Software Version 6.9

Comodo Certificate Manager Version 5.7

Comodo Certificate Manager

Comodo ONE Software Version 3.3

Comodo Certificate Manager Version 5.5

Comodo IT and Security Manager Software Version 5.4

Comodo One Home Edition - FAQ

Comodo Certificate Manager

Comodo One Software Version 3.16

Comodo Certificate Manager Software Version 5.0

Comodo Certificate Manager

Domain Control Validation in Comodo Certificate Manager

Christopher Covert. Principal Product Manager Enterprise Solutions Group. Copyright 2016 Symantec Endpoint Protection Cloud

DigiCert Products. SSL Certificates

Comodo IT and Security Manager Software Version 6.9

Comodo Accounts Management Software Version 15.0

Enhancing the Cybersecurity of Federal Information and Assets through CSIP

Comodo Certificate Manager Version 5.5

Comodo Device Manager Software Version 4.0

Comodo cwatch Web Security Software Version 1.6

Comodo SecureBox Management Console Software Version 1.9

8 Must Have. Features for Risk-Based Vulnerability Management and More

Comodo Endpoint Security Manager Software Version 3.4

Importing your or Personal Authentication certificate to Android Devices

Comodo Certificate Manager Version 5.6

Asset Discovery with Symantec Control Compliance Suite WHITE PAPER

Comodo SecureBox Management Console Software Version 1.8

VMware AirWatch Integration with OpenTrust CMS Mobile 2.0

Software Version 5.0. Administrator Guide Release Date: 7th April, InCommon c/o Internet Oakbrook Drive, Suite 300 Ann Arbor MI, 48104

Workspace ONE UEM Integration with OpenTrust CMS Mobile 2. VMware Workspace ONE UEM 1811

IT Security Mandatory Solutions. Andris Soroka 2nd of July, RIGA

ISO COMPLIANCE GUIDE. How Rapid7 Can Help You Achieve Compliance with ISO 27002

Comodo Certificate Manager

Continuously Discover and Eliminate Security Risk in Production Apps

Comodo Endpoint Security Manager Professional Edition Software Version 3.5

SOLUTION OVERVIEW. Enterprise-grade security management solution providing visibility, management and reporting across all OSes.

Comodo One Software Version 3.5

Comodo ONE Software Version 3.2

AKAMAI CLOUD SECURITY SOLUTIONS

The threat landscape is constantly

AXIAD IDS CLOUD SOLUTION. Trusted User PKI, Trusted User Flexible Authentication & Trusted Infrastructure

Security

1 Comodo One Home Edition - FAQ

Comodo Certificate Manager Version 5.7

VSP16. Venafi Security Professional 16 Course 04 April 2016

Comodo One Software Version 3.26

Sophos. Allan Widell Channel Account Executive. 24. August 2017

Comodo Web Application Firewall for Plesk Software Version 2.11

Importing and Using your or Personal Authentication certificate with The Bat!

Guide to Deploying VMware Workspace ONE with VMware Identity Manager. SEP 2018 VMware Workspace ONE

The SANS Institute Top 20 Critical Security Controls. Compliance Guide

GLOBALPROTECT. Key Usage Scenarios and Benefits. Remote Access VPN Provides secure access to internal and cloud-based business applications

How-to Guide: Tenable.io for Microsoft Azure. Last Updated: November 16, 2018

ELIMINATE SECURITY BLIND SPOTS WITH THE VENAFI AGENT

See What You ve Been Missing

Importing and exporting your or Personal Authentication certificate using Mozilla Firefox

Guide to Deploying VMware Workspace ONE. VMware Identity Manager VMware AirWatch 9.1

Comodo Certificate Manager

Challenges 3. HAWK Introduction 4. Key Benefits 6. About Gavin Technologies 7. Our Security Practice 8. Security Services Approach 9

Lessons from the Human Immune System Gavin Hill, Director Threat Intelligence

Importing and Using your or Personal Authentication certificate with Mac OS X Mail / Apple Mail

Importing and Using your or Personal Authentication certificate with Windows Live Mail

How-to Guide: Tenable Nessus for Microsoft Azure. Last Updated: April 03, 2018

Forescout. eyeextend for Palo Alto Networks Wildfire. Configuration Guide. Version 2.2

Comodo Server Security Server

Transcription:

Comodo Certificate Manager Simple, Automated & Robust SSL Management from the #1 Provider of Digital Certificates 1 Datasheet

Table of Contents Introduction 3 CCM Overview 4 Certificate Discovery Certificate Lifecycle Management 5 6 - Instant Issuance - Configuration & Installation - Remediation - Renewals Automation 7 Private Certification Authority Service 8 Code Signing in the Cloud 9 Administration 10 About Comodo 11 Technical Specifications & Features 12 2

Introduction Digital certificate management is complex and can be difficult to manage effectively without the right visibility, tools and policies in place. In today s environment where no one is safe from a cyber-attack, organizations need to continually monitor their web security posture to prevent or minimize damage from sophisticated attackers that are looking for any opening to exploit. Most medium to large enterprises have multiple websites, devices and web applications that require a large volume of digital certificates across their environment, including public facing websites. Often certificates need to be issued quickly by multiple administrators across different organizations, business units and countries. Keeping track of dozens (or possibly hundreds) of certificates in any environment can quickly become a challenge for administrators. Certificates need to be purchased, deployed and renewed when they have expired, which all takes time, especially when multiplied over the dozens or even hundreds of applications and domains that exist in many enterprises. Ignoring or mishandling even a single one of them can lead to unintended vulnerabilities that are susceptible to threats. That s why enterprises today need a secure digital certificate management portal like Comodo Certificate Manager (CCM) so that they can have complete control and visibility to manage their certificate needs and to strengthen their web environment. CCM is a critical solution for enterprises to protect their business, their brand, and their customers. Why enterprises need a certificate management solution: Real-time visibility into your entire website and web applications environment and inventory to maintain a secured environment Website, application & business continuity Maintain compliance to enterprise and industry policies Increase operational efficiency while reducing costs 3

Comodo Certificate Manager Overview Simple, Automated & Robust SSL Management from the #1 Provider of Digital Certificates CCM takes the complexity, cost and time out of managing digital certificates. Through a cloud-based platform, CCM enables enterprises to have complete visibility and lifecycle control over any certificate in their environment along with the tools, support and products to reduce risk, quickly respond to threats and control operational costs. With CCM customers receive the most advanced certificate management solution available, along with industry leading 24x7 support backed by the #1 leading brand in digital certificates. Entire lifecycle management for all your digital certificates from one easy-to-use online platform. Domain Validation (DV) certificates Device certificates Organization Validation (OV) certificates Private certificates (Private CA) Extended Validation (EV) certificates Self-signed certificates Multi-domain certificates Code signing & EV code signing certificates Wildcard certificates S/MIME email certificates With CCM enterprises can instantly issuance, deploy and revoke certificates to quickly scale up or down projects; have complete administration control and create custom rules for certificate requests; benefit from a lower total cost of SSL ownership, and protect their brand with a publicly trusted root compatible with all major browsers and operating systems that will eliminate self-signed certificates and certificate not trusted errors. Easy deployment, configurable controls, and fast scanning are capabilities critical for large and growing enterprises. The Industry Leader in Digital Certificate Solutions THE #1 market leader in SSL/TLS certificates* INDUSTRY BEST 99.9% trust recognition from browsers OVER 70M+ certificates issued worldwide MORE THAN OVER OVER 25% of the Fortune 1,000 use Comodo SSL solutions 700K businesses in 150+ countries use Comodo solutions 7.5B certificate revocation lookups per day 4 *Netcraft report: September 2017

Certificate Discovery Comprehensive scanning to discover all certificates in your environment regardless of the CA Built into the cloud-based console, the certificate discovery feature quickly scans your private and public networks, detects all SSL/TLS certificates currently in use regardless of the issuing Certificate Authority (CA), identifies important configuration details, and presents the data back to you in an organized, intuitive management dashboard. When administrators have real-time visibility, they can make the right decisions and take the necessary actions to protect their environment. Certificate Discovery also provides tools and guides so that enterprises can mitigate the risks of non-compliance, maintain industry best practices and adhere to corporate and compliance policies. Standard and customized reporting also includes security and vulnerability ratings on all SSL/TLS certificates, helping administrators quickly identify and take corrective actions. Key features More than half of companies have at one point lost a digital certificate, or there were certificates on their network whose origins could not be accounted for. Configurable network scans across different parts of the network Agent and agentless deployment options for load-balancers and servers Comprehensive, interactive dashboard with an easy to use interface and drill-down capabilities Custom notifications for in-console alerts or by email Get information across all SSL certificates, whether they are self-signed or issued by another CA Quickly identify and remediate rogue certificates Create custom detailed reports that include upcoming expirations, key length, hashing algorithms, and more Prevent down time from unexpected expirations with notices through email notifications and console alerts 5

Certificate Lifecycle Management Full control, visibility and simple management for issuing, installing, remediating and renewing certificates Network environments are continually expanding to include new secure web-based projects; this shift in ensuring a secure web environment means more demands on managing certificates. Managing multiple certificates with differing expiration dates (including ones issued by different vendors) creates challenges for even the most sophisticated enterprise. For enterprises with a large web environment, the process of managing the lifecycle for every SSL certificate can lead to oversight, manual errors, improper configuration, weak ciphers, and unintended expirations. CCM reduces these risks by ensuring complete lifecycle management for all enterprise web assets. CCM lifecycle management capabilities include: Instant Issuance Instantly issue, DV, OV, or EV SSL certificates for every pre-validated domain. Role-based user access enables individuals or teams the ability to issue certificates across the organization so that security can be quickly turned on for any web based project. Configuring & Installation Automatic configuration and installation of certificates using SCEP, REST, or EST to automate certificate deployment across the network. Remediation Real-time alerts enable administrators the ability to spot potential weaknesses and remotely fix or revoke certificates on demand. Renewals Certificates can be manually renewed set for automatic renewal to avoid unintended expirations or downtime. Most organizations rely on spreadsheet-based tracking methods and manual processes to keep track of certificates, resulting in many undocumented installations and increased exposure to risks. 6

Automation Simplify issuance and deployment and spend less time manually managing certificates Workflow automation has become a necessity for administrators and it enables them to save time, save costs, cut down on human errors, and improve business efficiency. Automation in website security helps enterprises maintain control while keeping secure and compliant. Through the CCM, APIs administrators can integrate directly into the platform and automate processes of the certificate lifecycle including purchasing, renewing, installing, revoking, or updating certificates across their entire environment. CCM automation tools can also be used for setting up regular scans of a network, recording all discovered certificates and then checking that the certificate was deployed correctly to avoid mistakenly using an old certificate. The automation tools help by providing critical detection for misconfigured certificates and identify potential security vulnerabilities and assign each certificate and server a grade along with offering remediation actions if needed. Certificate management platforms with automation capabilities can reduce management time by up to 60% when compared to manual management 225 Hours is the average time spent to manually manage 50 certificate each year 7

Private Certification Authority Service Issue & manage private SSL certificates in CCM Comodo Private CA is a feature in CCM designed to enable enterprises with a low-cost way to secure and manage their private intranet certificates while adhering to corporate and industry compliance standards. Through the CCM platform administrators can issue, view and manage their intranet certificates alongside of their Comodo certificates all from a single platform helping them better avoid risks, errors, or hidden costs that can be associated with self-signed certificates. Common uses for private certificates include: Intranet sites VPN or wireless authentication Device identification mobile device deployments or BYOD Internet of Things (IoT) projects Securing communications between internal services 8

Code Signing in the Cloud Secure and manage code signing certificates by storing the keys in the Comodo CCM PKI infrastructure Code Signing certificates are used by software developers to digitally sign applications and software programs to prove that the file a user is downloading is genuine and has not been compromised. This is especially important for publishers who distribute their software through third-party download sites, which they may have no control over. Major operating systems will show end users an error message if the software they are trying to install is not signed by a trusted CA. The CCM platform has both a hosted and cloud based service that provides a fast and simple interface through which developers can upload, sign and quickly collect their signed software. The service ensures certificate keys are securely stored and available only to authenticated users, helping to mitigate the risk of accidental loss or theft and protect users from downloading compromised software. CCM is also capable of hash signing; developers can upload a hash of their files for signing instead of the file itself. The developer would then need to embed the hash with their files. Code Signing provides authentication to assure customers that the file they are downloading is from the publisher named on the certificate. In addition, this also proves that the file has not been tampered with or hacked since it was signed. Can be used to sign:.exe.sys.dll.jar.cab.apk.msi WAR.OCX Adroid applications 9

Administration Cloud based platform to administer and manage digital certificate portfolios CCM s cloud-based management console enables centralized control, delegated administration, visibility and comprehensive management for all SSL and code-signing certificates across an enterprise. The administrative features allow enterprises to have quick access to key data with a comprehensive dashboard view, enables them to customize their settings and control user s roles and have access to a suite of full reporting capabilities. Comprehensive dashboard for quick views Active/Revoked certificates Drill down by organization See certificates set to expire within 180 days See all certificates by CA View current state of all certificates requested and issued Adjustable settings & admin controls Private key store Set up and manage users by role Quickly add and manage domains & organizations Customizable notifications and email templates Create custom rule sets Fully reporting capabilities Automated or on demand reporting Historical logs Certificates Private key controller 10

About Comodo The Comodo organization is a global innovator of cybersecurity solutions, protecting critical information across the digital landscape. Building on its unique position as the world s largest certificate authority, Comodo authenticates, validates and secures networks and infrastructures from individuals to mid-sized companies to the world s largest enterprises. Comodo provides complete end-to-end security solutions across the boundary, internal network and endpoint with innovative technologies solving the most advanced malware threats, both known and unknown. With US headquarters in Clifton, New Jersey, the Comodo organization has offices in Silicon Valley, China, India, the Philippines, Romania, Turkey, Ukraine and the United Kingdom. For more information, visit www.comodo.com. Keep up to date with our blog - https://blog.comodo.comfollow us on Twitter - Twitter@ComodoNews Connect with us on LinkedIN - https://www.linkedin.com/company/comodo 11

Technical Specifications & Features Certificate Discovery (SSL Handshake) Auto Installation of SSL Certificates Certificate Discovery (MS AD-MS CA - IIS) Server Certs Included Email certs Included Code Signing Included Private Certificates Auto Enrollment of Certificates to all domain joined objects All validation types Lifecycle Management Self Enrollment Web Interface S/MIME Enrollment by Invitation Customized Web Interfaces Key Escrow Three-level Delegated Administration Bulk DCV Access Control based on Role and IP Cloud Code Signing Service Agent Based On Premise Code Signing Service Customized Web Interfaces S/MIME Enrollment by Invitation Apache IIS F5 Big IP BlueCoat IBM Websphere Citrix Netscaler Cisco ACE Imperva WAF Certificate Discovery (SSL Handshake) Microsoft CA Symantec MPKI GlobalSign MSSL SSH Key Management Unlimited Re-issues Federated Identity Login Certificate Support Lifecycle Management Self Enrollment Web Interface 12