大家好
最近在公司內網使用了Rapid7 InsightVM 6.5掃描AD和Exchange Server,都有Untrusted TLS/SSL server X.509 certificate問題…
請問要如何找出有問題的自簽憑證?或者有別的方式可測試是否為誤判?
不對啊, Rapid7 掃完, 應該在報表上就會告訴你:
Untrusted X.509 是從哪一台機器上面掃到的...
為何你會不知道憑證在哪台機器裡?
依照官網說明看來
只要是「自簽憑證」就會跳出這個警告
參考以下說明
The server's TLS/SSL certificate is signed by a Certification Authority (CA) that is not well-known or trusted. This could happen if: the chain/intermediate certificate is missing, expired or has been revoked; the server hostname does not match that configured in the certificate; the time/date is incorrect; or a self-signed certificate is being used. The use of a self-signed certificate is not recommended since it could indicate that a TLS/SSL man-in-the-middle attack is taking place
沒有「誤判」(因為實際上就是自簽憑證)
Rapid 只是告知「Untrusted TLS/SSL server X.509 certificate」這個 issue
至於要採行「改善措施」或者「不當一回事」
則是你的選擇