Laboratory Week 13 - Web Browser Security Settings
Learning Objective:
Understanding the ways security settings are made in Netscape Navigator and Microsoft Internet Explorer (IE).
Before doing the tutorial, please read:
- Week 12 lectures.
Software required:
This lab requires use of Netscape Navigator 4.x or Microsoft Internet Explorer 5.0+ web browsers. The software is available in the internal labs.
Instructions and Exercises:
Most web connections to a secure servers happens without you even realising it. Most browsers, including the latest versions of Netscape Navigator and Microsoft IE comes with support for SSL. In our example, we will use the secured versions of Murdoch University's home pages. Please do the following with both Netscape Navigator and Miscrosoft IE.
Establishing an secure connection:
- Start up Netscape Navigator and Internet Explorer.
- Access the URL https://www.murdoch.edu.au.
- You are now in a page served by a secure server. There are two indications of this:
- The URL starts with https (for secure HTTP) instead of http.
- There is a padlock icon on the status bar at the bottom of the browser.
In the current Netscape Navigator, the padlock is on a yellow background on the bottom left corner. This padlock is usually unlocked and on a normal background when accesing insecure pages (access a normal page and see what it looks like).
Older versions of Navigator uses a complete and broken key icons for secure and insecure pages.
In IE, the padlock appears on the right side of the status bar. When accessing normal pages, the padlock is not there.Getting Information about the secure session
- There are a few ways to get information about the secure session:
In Netscape Navigator, select the menu item View>Page Info. On the bottom frame, look at the Security and Certificates fields.
In Netscape Navigator, you can also click on the Security tool on the tool bar, or click on the padlock icon. Then click on Security Info on the list of items, and click on the View Certificate button.
In IE, you can get the same information by selection the menu item File>Properties, then click on the Certificate button. Alternatively, just click on the padlock icon.
- Whichever way you chose to use in 1 (try them all!), you will get information on the
- Certifying authority (CA) who issued the certificate.
- The organization the certificate was issued to and its domain name - this is to verify that the organization is who you believe you are connected to. In our example, we can be confident that we are communicating with Murdoch University and not some site masquerading as Murdoch University, and that www.murdoch.edu.au is their real web address.
- The expiry date of the certificate.
- The fingerprint (usually MD5 hash number) of the certificate - read the lectures notes on digest authentication.
Compare the information supplied by Navigator and Internet Explorer. How does each present their information? Is everything given in one browser displayed in the other as well? If not, what is missing on the different browsers?
Getting a list of trusted Certifying Authorities (CAs)
- Each browser comes with a list of trusted certifying authorities by default, to view this list:
In Netscape Navigator, click on the Security tool on the tool bar, or the padlock icon. Then click on Certificates>Signers. This gives a list of "self-signed" certificates from each of the individual trusted CAs. You can view the CA's information by selecting it and clicking the Edit button. The browser will also verify that the certificate on this page hasn't been tampered with (using the fingerprint) when you click the Verify button.
In IE, select the menu item Tools>Internet Options..., click on the Content tab item, and click on the Authorities buttons. IE has different set of selected authorities for different types of certificates.- The reason for the Delete or Remove option in the list of CAs is because when the browsers encounter a site certificate which is NOT on the list of trusted CAs, the browser will ask you if you want to accept the certificate and included the untrusted CA as a trusted one. If you do choose to accept the certificate just for that session, you can delete the suspect CA from the list after the session is finished. You should NOT remove any of the existing ones that came with the software.
Getting a Personal Certificate
- You can even get a personal certificate for a modest price of US$10 to $20 (based on the level of security). For example, see the personal certificate product on the eSign web site. This will be useful in securing your own email messages, and in cases where you are required to authenticate yourself. Keep in mind a few things:
- Authentication is a two-way street. Only get a personal certificate when communicating with a party which requires/supports authentication.
- Certificates are usually tied to certain programs (eg. e-mail clients on certain machine IP addresses). This is because when you apply, receive, install and use the certificate, they are almost always on the same machine. DON'T APPLY FOR A PERSONAL CERTIFICATE IN A LAB MACHINE!
- Simple certificates (eg. VeriSign Class 1) only takes a few seconds. More secure ones (eg. VeriSign Class 2) takes a few days, at least.
Security Configurations
- All security configurations in the current version of Navigator is found by clicking the Security tool in the tool bar. Look especially at the item Navigator, which controls a lot of the displayed messages when encountering secured pages (in SSL).
- For Internet Explorer, the configuration information can be found by selecting the menu item Tools>Internet Options..., then clicking on the Advanced tab. Look at the items under Security. A few points:
- PCT (Private Communications Technology) was a competing standard Miscrosoft offered to SSL before they adopted full support for SSL. It is still being supported in IE. Look at the lecture notes for descriptions of SSL.
- TLS (Transport Layer Protocol) is a complementary protocol to SSL, developed by IETF (the Internet Engineering task force).
- There is an item for looking up certificatse revocations. Sometimes when the private keys for the certificates gets compromised, the certificates are revoked. Certifying authorities publishes such lists electronically. The browsers have the option of consulting this list before accepting any certificate.
Control of active content
- Netscape Navigator allows certain control over downloading of active contents (eg. JavaScript and cookies). It is found in the menu item Edit>Preferences..., in the Advanced item - have a look.
- The active content settings for IE is in the Tools>Internet Options...>Security item. Select the different categories (Internet,Local intranet, etc) and click on Custom Levels. You can also define lists of trusted and restricted sites by selecting the categories and clicking on the Sites button.
Remember to read the week's development on the Internet by scanning through relevant articles in the IT section of Tuesday's the Australian newspaper - use the online version or the physical copy in the University library. Get into the habit of keeping up with current developments. Test your knowledge of major developments by going through the Good News Week self-tests.
H.L. Hiew
Unit Coordinator
Document author: H.L.
Hiew, Unit Coordinator
Last Modified: Monday, 29-Oct-2001 06:08:48 MST
Disclaimer & Copyright Notice © 2001 Murdoch
University