Detecting threats with inbound SSL (TLS) decryption

Today we have the answer to the question – Without SSL decryption how many threats/attempted vulnerability exploits/other bad stuff will I miss that are coming from the internet at my internally hosted (externally published) web sites and services? To run some simple tests (which will be detected as malicious attacks) I’m going to be running the Nessus scanner against a… Read more



Requesting a CSR from Dell iDRAC gives you a blank file

A interesting quirk of an issue with this one; when generating a CSR to secure the iDRAC (version 8) interface on a Dell T430 server it appears that you can’t use an apostrophe in any of the fields else you are presented with a empty/blank csr.txt file (see right). The work around is simple if a little annoying (especially when CSRs… Read more



Knackered your iDRAC 8 web console by uploading a Custom SSL Certificate Signing Certificate? – Fix

A bit of an interesting one today; while provisioning a pair of shiny new Dell T430s I had obtained and uploaded a valid 3rd party signed SSL certificate to the iDRAC interface with a view to ensuring that whenever an administrator accessed the interface they didn’t get a invalid certificate warning. However after uploading the certificate and restarting iDRAC I was presented… Read more



Free SSL security certificates for school

One of my goals of this site is to raise the profile (even if just a little) of the issues that UK schools face throughout the year. One such problem is how to deploy remotely accessible services (VPNs/Terminal Server/Citrix VDI/or the famous Home Access Plus+) in a secure but low cost manner. Obviously a key part of these services is security… Read more