Network Security with OpenSSL | John Viega, Matt Messier, ... | SSL made Clear
books:
Network Security w...
Network Security with OpenSSL
John Viega
,
Matt Messier
, ...
O'Reilly Media, Inc.
, 2002 - 384 pages
average customer review:
based on 8 reviews
view larger image
for more information click here
highly recommended
Most applications these days are at least somewhat
network
aware, but how do you protect those applications against common network
security
threats? Many developers are turning to
OpenSSL
, an open source version of SSL/TLS, which is the most widely used protocol for secure network communications. The OpenSSL library is seeing widespread adoption for web sites that require cryptographic functions to protect a broad range of sensitive information, such as credit card numbers and other financial transactions. The library is the only free, full-featured SSL implementation for C and C++, and it can be used programmatically or from the command line to secure most TCP-based network protocols. Network Security with OpenSSL enables developers to use this protocol much more effectively. Traditionally, getting something simple done in OpenSSL could easily take weeks. This concise book gives you the guidance you need to avoid pitfalls, while allowing you to take advantage of the library?s advanced features. And, instead of bogging you down in the technical details of how SSL works under the hood, this book provides only the information that is necessary to use OpenSSL safely and effectively. In step-by-step fashion, the book details the challenges in securing network communications, and shows you how to use OpenSSL tools to best meet those challenges. As a system or network administrator, you will benefit from the thorough treatment of the OpenSSL command-line interface, as well as from step-by-step directions for obtaining certificates and setting up your own certification authority. As a developer, you will further benefit from the in-depth discussions and examples of how to use OpenSSL in your own programs. Although OpenSSL is written in C, information on how to use OpenSSL with Perl, Python and PHP is also included. OpenSSL may well answer your need to protect sensitive data. If that?s the case, Network Security with OpenSSL is the only guide available on the subject.
for more information click here
openssl programming cleanly explained
The book starts with a general introduction of encryption in general, then SSL protocol in general. Then
openssl
command line interface is introduced with some easy to follow examples. Later openssl programming is explained in detail.
As the only free SSL programming library with source code available, openssl is notorious for its undocumented/underdocumented/misdocumented manuals. Starting a software project using openssl without prior experience is often a painful experience if you simply rely on the manuals coming with the source code. Given thousands of interfaces/data structures, it is an overwhelming job to understand openssl in depth. Your best bet is usually reading the sample source code that comes with package, but often it leaves lots of questions - what does this api do? Why use this one? Under what circumstances should I use this one? You may rely on openssl mailing list, but answer is not guaranteed and you have to do your own home work first.
So come this book finally. It explains (using many examples) most interfaces a typical openssl programmer would use in reality. It is a really easy to read from chapter to chapter since the authors apparently try to explain most api using a short and clear example.
I wish when the next version comes out, it can do:
1. fix typos. Yeah, it does contain some typos. Good proofreading is needed.
2. Include topics in openssl 0.9.7. Like CRL.
3. What's going on under hood. How openssl code is organized, how interface control of flow goes. This helps understand the openssl library and debugging as well.
for more information click here
SSL made Clear
I worked on a LAMP project with 'C' switching application behind it. This book clearly described what I needed and how to do it. Very good resource.
Great Book to Use When Writing an SSL app.
If you have little or no experience with SSL, or
OpenSSL
, get this book. It explains the principles behind SSL, and then goes on to cover OpenSSL. The companion website opensslbook.com contains the latest examples.
The only drawbacks to the book are the way that the authors cover random number generators for windows, (totally excludes the MS crypto function cryptgenrand(), in favor of the Author's own entropy collection system), and the creation of certificates could have been covered a little better. I also kept having to consult the Openssl API documentation for clarification on certain things, but overall this is a great book.
for more information click here
SSL programming
This book was a valuable resource in implementing Secure Sockets, it would have been difficult to finish my product without it.
good for programmers
Contents: intro,
openssl
command line, PKI, then programming: support infrastructure, ssl, symmetric keys, hashes, public keys, and openSSL for Perl, Python, and PHP.
As others have noted, this is a great book for programming. It's not as detailed if you are looking to set up your own PKI. Basically it is about 30 pages of the openssl command (using symmetric keys, generating private keys, making certificates, signing them) and ~270 pages or so of programming.
for more information click here
reviews
:
page 1
,
2
products you might be interested in
recommendations
Linux Security and Administration
Hacking and Security - General
My Favorite Security Books
My Non-fiction Bookshelf
security
Fooling Some of the People All of the Time: A Long Short Story
America Alone: The End of the World As We Know It
Fooled by Randomness: The Hidden Role of Chance in Life and in the ...
War and Decision: Inside the Pentagon at the Dawn of the War on ...
The Intelligent Investor: The Definitive Book on Value Investing. A ...
network
The New Age of Innovation: Driving Cocreated Value Through Global ...
The Food You Crave: Luscious Recipes for a Healthy Life
Barefoot Contessa at Home: Everyday Recipes You'll Make Over and Over ...
Groundswell: Winning in a World Transformed by Social Technologies
Never Eat Alone: And Other Secrets to Success, One Relationship at a ...
search for books
network security
,
network
,
openssl
,
security
randomly chosen
tools & hardware:
LATEX-ITE "PLI-STIX" Permanent crack filler