Dear Experts,
On our PCI security scan I have 2 items I need help deciding what I should do with.
As far as getting a specific certificate for our web hosting server machine, I am ok with that. Should I do that? And if I do, does it need to point to SERVER.iondata.com? Also, what use is the security certificate for the machine itself anyways? Do you guys suppose that maybe FTP uses it or something and that is why securitymetrics sees it?
Here is the first one:
Synopsis:
The SSL certificate chain for this service ends in an unrecognized self-signed certificate.
Impact:
The X.509 certificate chain for this service is not signed by a recognized certificate authority. If the remote host is a public host in production, this nullifies the use of SSL as anyone could establish a man-in-the-middle attack against the remote host. Note that this plugin does not check for certificate chains that end in a certificate that is not self-signed, but is signed by an unrecognized certificate authority.
Resolution:
Purchase or generate a proper certificate for this service.
Data Received:
The following certificate was found at the top of the certificate chain sent by the remote host, but is self-signed and was not found in the list of known certificate authorities : |-Subject : CN=SERVER.iondata.com
Also, the second item really confuses me.. iondataexpress.com has it's own security certificate and it's working great. How is security metrics even seeing the certificate for the machine, and why does that matter? They aren't complaining about our other certificate for our other website on the machine?
How do you see a certificate chain? I'd like to see what they're talking about, because maybe then it'd make more sense.
And the 2nd:
Title
SSL Certificate with Wrong Hostname
close
Synopsis:
The SSL certificate for this service is for a different host.
Impact:
The commonName (CN) of the SSL certificate presented on this service is for a different machine.
Resolution:
Purchase or generate a proper certificate for this service.
Data Received:
The identities known by SecurityMetrics are : iondataexpress.com
www.iondataexpress.com The Common Name in the certificate is : SERVER.iondata.com
Thanks guys! I'm mainly looking for understanding on what these items mean and advice on what approach I should take to fix them..
~Jeffrey
Option 1 - reissue with this SAN name added
Option 2 - if you have multiple static IP address's with your broadband change your PCI scan to point to another IP address