How can I manage my SSL certificates!? Look no further!

KendallWorks
28 Dec 201609:44

Summary

TLDRIn this video, Kendall introduces 'Key Manager Plus' by Managed Engine, a powerful yet affordable SSL certificate management tool designed for large organizations. The tool offers an intuitive dashboard to monitor expiring certificates, detailed certificate information, and the ability to export them directly. It also integrates with Active Directory, supports multiple domains, and can send email alerts for expiring certificates. Kendall emphasizes its cost-effectiveness and highlights features like CSR creation and password storage, making it an excellent solution for streamlined certificate management.

Takeaways

  • 🛠️ The video introduces 'Key Manager Plus', a tool for managing SSL/SSH certificates in large organizations.
  • 📊 Key Manager Plus offers a highly refined dashboard for SSL certificate management, which is considered one of the best by the speaker.
  • 📅 It provides an overview of certificates expiring within specific timeframes, such as 0-30 days, 30-60 days, and those already expired.
  • 🔍 Users can drill down into certificate details, including expiration, issuer, and encryption algorithm.
  • 💾 The tool allows for exporting and downloading certificates directly from the interface.
  • 📈 It includes a feature to view all keys and certificates within the organization, along with a graphical representation of the data.
  • 🔒 Key Manager Plus integrates with Active Directory, supporting multiple domains and user authentication.
  • 📧 It has an automated email feature to notify users about expiring certificates, ensuring they stay on top of certificate management.
  • 💰 The tool is described as being very affordable, especially for organizations needing to manage a large number of certificates.
  • 🔑 It enables the creation and storage of CSRs (Certificate Signing Requests) and passwords in a centralized location.
  • 📝 The video mentions a streamlined process for certificate requests, from generation to signing, and the ability to attach and distribute certificates securely.

Q & A

  • What is the main purpose of Key Manager Plus?

    -Key Manager Plus is a tool designed for managing SSL and SSH certificates, particularly useful for large organizations to streamline the process of certificate management.

  • Who is the speaker in the video and what is their focus?

    -The speaker is Kendall, who focuses on discussing the features and benefits of Key Manager Plus, a certificate management tool.

  • What does Key Manager Plus offer in terms of a dashboard?

    -Key Manager Plus provides an impressive dashboard that displays information about expiring certificates, including counts and details, which is considered one of the best in SSL certificate management tools.

  • How does Key Manager Plus help in identifying certificates that are about to expire?

    -It categorizes certificates based on their expiration dates, showing counts for certificates expiring within 0 to 30 days, 30 to 60 days, and those that have already expired.

  • Can users drill down into the certificate details in Key Manager Plus?

    -Yes, users can click on the certificate counts to view detailed information about each certificate, including its expiration status, issuer, and other relevant data.

  • What is the feature that allows users to export certificates from Key Manager Plus?

    -Users can click on a specific certificate and use the export feature to download the certificate to their computer.

  • How does Key Manager Plus integrate with Active Directory?

    -Key Manager Plus can be integrated with Active Directory, allowing users to log in with their AD credentials and manage permissions through groups, similar to other tools.

  • What is the cost of Key Manager Plus for managing a thousand SSL certificates?

    -The annual contract for managing a thousand SSL certificates with Key Manager Plus is two thousand dollars, which is considered very affordable compared to other tools.

  • What additional features does Key Manager Plus offer for certificate management?

    -Key Manager Plus also allows users to create CSRs (Certificate Signing Requests), store passwords centrally, and generate reports, among other features.

  • How does Key Manager Plus handle the process of certificate requests and management?

    -It provides a centralized location for creating CSRs, managing signed certificates, and associating them with specific requests or tickets, which can then be closed and communicated internally.

  • What is the speaker's opinion on the value of Key Manager Plus compared to other tools?

    -The speaker finds Key Manager Plus to be an extremely helpful and cost-effective tool, offering more features and better management capabilities than other tools they have used.

Outlines

00:00

🛠️ SSL Certificate Management with Key Manager Plus

The video introduces Key Manager Plus, a tool by Managed Engine, designed for SSL certificate management in large organizations. The tool offers an exceptional dashboard that provides insights into expiring certificates within various timeframes and allows users to drill down for detailed information on each certificate. It also enables the export of certificates directly to a user's computer. The speaker emphasizes the tool's ability to streamline certificate management, especially for organizations using global sign or other providers, and highlights its integration with Active Directory and its cost-effectiveness.

05:01

💰 Affordable SSL Certificate Management and Automation

This paragraph delves into the cost-effectiveness and automation features of Key Manager Plus. The speaker discusses the affordability of the tool, mentioning its low annual contract cost for a thousand licenses. The tool's ability to automate tasks such as creating CSRs (Certificate Signing Requests) and storing passwords is highlighted. The video also covers the process of generating, signing, and managing CSRs centrally, which is particularly useful for organizations with internal certificate servers. The speaker shares a use case scenario involving the management of certificate requests and the secure distribution of certificates within an organization, emphasizing the tool's role in maintaining security and efficiency.

Mindmap

Keywords

💡SSL Certificates

SSL Certificates, or Secure Sockets Layer Certificates, are digital certificates that provide a secure link between a web server and a browser, ensuring that all data passed between them remains private and integral. In the video, the speaker discusses the importance of managing SSL certificates in large organizations, highlighting the tool 'Key Manager Plus' for managing these certificates efficiently.

💡Key Manager Plus

Key Manager Plus is an application mentioned in the video that is designed for managing SSL and SSH certificates. It is developed by Managed Engine and is praised for its user-friendly dashboard and detailed certificate management features. The tool allows users to monitor the expiration of certificates and take necessary actions to prevent security lapses.

💡Dashboard

In the context of the video, a dashboard refers to a user interface that provides a comprehensive overview of the key metrics and information related to SSL certificate management. The speaker describes the dashboard of Key Manager Plus as one of the best they've encountered, emphasizing its role in making certificate management more accessible and efficient.

💡Certificate Expiration

Certificate Expiration is a critical aspect of SSL certificate management. The video emphasizes the importance of tracking when certificates are due to expire, as expired certificates can compromise the security of a website. Key Manager Plus provides features to monitor and alert users about certificates that are expiring within specific timeframes.

💡GlobalSign

GlobalSign is a Certificate Authority (CA) mentioned in the video as an example of a provider that offers SSL certificates and tools for their management. The speaker uses GlobalSign to illustrate the comparison between the standard tools provided by certificate authorities and the more advanced features of Key Manager Plus.

💡Drill Down

Drill Down refers to the ability to navigate through layers of data to access more detailed information. In the video, the speaker describes how Key Manager Plus allows users to drill down into certificate data to view detailed information about individual certificates, such as their expiration dates and issuers.

💡Export Certificate

The ability to export a certificate is highlighted in the video as a feature of Key Manager Plus. It allows users to download a certificate from the tool to their local computer, which can be useful for backup purposes or for transferring the certificate to another system.

💡Active Directory Integration

Active Directory is a directory service used by Microsoft for authentication and authorization. The video mentions that Key Manager Plus integrates with Active Directory, allowing users to log in using their AD credentials and manage permissions and access to the certificate management tool more effectively.

💡CSRs (Certificate Signing Requests)

CSRs are used in the process of obtaining an SSL certificate from a Certificate Authority. The video explains how Key Manager Plus can store and manage CSRs, making it easier for organizations to handle the process of certificate generation and signing.

💡Centralized Management

Centralized Management is a key theme in the video, where the speaker discusses the benefits of having all certificate-related activities managed from a single location using Key Manager Plus. This includes creating CSRs, storing certificates, and managing keys, which streamlines the certificate management process.

💡Ticket Generation Process

In the context of the video, the ticket generation process refers to the workflow of creating and managing requests for SSL certificates within an organization. Key Manager Plus can be integrated into this process, allowing for the tracking and management of certificate requests from creation to deployment.

Highlights

Introduction to Key Manager Plus, a tool for managing SSL and SSH certificates in large organizations.

Key Manager Plus offers an exceptional dashboard for SSL certificate management.

The tool provides an overview of certificate expiration dates, including counts for those expiring within 0-30, 30-60 days, and those already expired.

Users can drill down into specific certificate details, including expiration and issuance information.

Certificates can be exported and downloaded directly from the tool.

Key Manager Plus integrates with Active Directory and supports multiple domains.

The tool can automatically send email notifications for expiring certificates.

Affordable pricing for a thousand licenses, significantly cheaper than other tools with fewer features.

Key Manager Plus allows for the creation and storage of CSRs and passwords in a central location.

The tool streamlines the certificate management process, from request to signing and deployment.

Demonstration of how to attach a signed certificate to a ticket within the tool.

Key Manager Plus enhances security by centralizing certificate and passphrase management.

The tool supports the generation of various reports for certificate management.

Key Manager Plus is a new and valuable tool for organizations managing a large number of SSL certificates.

The presenter emphasizes the tool's cost-effectiveness and ease of use compared to other solutions.

A call to action for viewers to explore the tool further and potentially improve their certificate management processes.

Transcripts

play00:00

[Music]

play00:06

hey everyone Kendall here again so today

play00:10

I wanted to do a short video on a tool

play00:15

that if you're in a big organization

play00:16

this should be very very helpful to you

play00:19

guys talking to a bunch of my other IT

play00:23

based friends they don't really know

play00:26

about this tool a lot of people didn't

play00:28

even know it existed a lot of people

play00:30

know about this company though but they

play00:33

just did not know that there was such a

play00:34

tool for SSL based certificates this

play00:37

tool does do SSH base certificates as

play00:41

well but I'm just going to cover SSL

play00:44

because it's just very very useful so as

play00:46

you can tell here this is a demo and the

play00:49

application is called key manager plus

play00:51

it's made by managed engine which is up

play00:54

here in the top left hand corner of the

play00:55

screen this key manager plus gives you

play00:59

just an awesome dashboard probably one

play01:01

of the best dashboards I've ever come

play01:03

across on any ssl certificate management

play01:06

tool and a lot of you guys who are doing

play01:09

this in a big organization you know that

play01:11

hey if you're going through let's just

play01:14

use global sign as an example you get a

play01:16

tool that way or any big-name provider

play01:19

that you have out there they give you

play01:20

some type of tool of them but it's

play01:22

nothing to this degree of I guess

play01:27

refinement would be the best way I could

play01:28

describe it so the nice thing is it

play01:30

gives you how many certificates are

play01:31

going to expire within you know then 0

play01:34

to 30 days 30 to 60 days and then it can

play01:37

give you obviously what's already

play01:38

expired and it gives you the counts on

play01:40

them well that's nice and enough self

play01:42

but what it doesn't give you that you

play01:44

would think is hey can I just click on

play01:46

this and drill down on it well yes you

play01:48

can you can click down on the 10 try and

play01:50

which ones are expired and it'll

play01:52

actually tell you all the information

play01:54

about the certificate okay so that's

play01:57

pretty sweet right now if that isn't

play01:59

sweet enough you can drill down on cloud

play02:01

front which was the first certificate

play02:03

there as an example you can click on

play02:05

this button you can actually export it

play02:07

and download that certificate to your

play02:09

computer so how sweet is that I mean

play02:11

that's ridiculous right

play02:13

alright you can go back to the homepage

play02:15

and let's say next is 0 to 30 days what

play02:20

certificates are expiring in my

play02:22

organization Oh facebook as an example

play02:25

you know these are all demo sites has

play02:27

one day left all right it gives you all

play02:30

the information about it like the key

play02:31

size who issued it who you need to go

play02:34

through to renew it right that type of

play02:37

information and through this window of

play02:40

course if you wanted no more about it

play02:42

like hey I don't really know what this

play02:44

ssl certificate here is for cloud let's

play02:48

click on that huh okay here's all the

play02:52

information about it gives me a founded

play02:54

on port 443 it's valid from this date

play02:57

and it goes to this date here's the

play02:59

alternative names that also the

play03:01

certificate uses right so there's a

play03:03

couple other sites that the certificate

play03:05

does and it's also a gosh I'm just going

play03:11

to say asterix but it's basically a you

play03:13

know it's for this whole HDFC Bank com

play03:17

sorry I can't think of the stupid word

play03:18

that you want to use there but anyways

play03:20

um so you know that information it's a

play03:23

sha-1 using RSA right for the encryption

play03:26

for the key algorithm I mean there's

play03:28

just so much and again you can export it

play03:30

right out through this window come back

play03:33

to home here same thing for 30 to 60

play03:35

days okay the other cool thing is is

play03:37

this gives you the how many certificates

play03:40

it actually finds in your organization

play03:43

so you can view your certificates it

play03:45

tells you like an orange here this is

play03:47

how many certificates i have in the key

play03:49

store which is a function basically

play03:51

where you can use the store keys within

play03:54

the application and that does eat up

play03:57

licenses and there is a way I guess I'm

play04:00

not necessarily going to say around that

play04:01

but there's a better use of the tool

play04:03

that I found to use and if you guys want

play04:05

more information about that I can go

play04:07

into details on it and then tells you

play04:09

obviously how much how many ssh-keys you

play04:12

have and then here you can click view

play04:13

all and it'll view all the keys the

play04:15

licenses that you have in your

play04:16

environment over here obviously it gives

play04:19

you all the different certificates who

play04:21

they're issued by right and a nice

play04:23

graphical pie chart I mean this is great

play04:25

for management

play04:26

but also as like if you have a

play04:29

monitoring team or a management team

play04:31

that manages all these certificates and

play04:33

they need to know when their upcoming me

play04:35

this is just a great great tool it also

play04:39

integrates with active directory let's

play04:42

see if this is yeah so through their

play04:43

demo on their site you can use your

play04:45

active directory it works with multiple

play04:47

domains i have tested this i know at

play04:49

least six domains it works with and

play04:51

users can log on with that's the most

play04:54

amount of domains I've tested it with

play04:56

you can assign groups just like you

play04:58

would to any type of tool it works

play05:00

really really well has a mail server

play05:03

setting it can automatically mail let's

play05:07

say 0 to 30 days you want to know when

play05:09

that window of certificates are going to

play05:11

expire it can email you a generated list

play05:14

of all those certificates so every month

play05:16

you're on top of your certificates this

play05:19

may sound like I'm getting paid by them

play05:20

I'm not getting paid by them I just find

play05:23

this an extremely helpful tool and the

play05:26

crazy thing about this is this tool is

play05:27

dirt dirt dirt cheap okay I mean dirt

play05:30

cheap for a thousand licenses on the

play05:33

certificate you're going to pay two

play05:35

thousand dollars as an annual contract

play05:37

that is ridiculously cheap I'm not going

play05:40

to tell you guys who I work for but we

play05:43

spend a lot more on tools that do a lot

play05:46

less let's just put it that way this

play05:48

tool is amazing and especially for two

play05:51

thousand dollars right if you have your

play05:54

ssl certificates over here the other

play05:57

cool thing about it is you can create

play05:59

your CSRs and you can create your CSRs

play06:02

and stores all your passwords here all

play06:05

right so like this one's managed engine

play06:06

they might all be that nope they're

play06:08

different but it stores all your

play06:11

passwords here so okay now you have your

play06:12

private key inside a store that's

play06:16

centrally managed right you can create

play06:18

your csr and now you can send it off to

play06:21

whoever needs to be signed by and after

play06:23

you've gotten that signed right publicly

play06:26

you basically can take that certificate

play06:29

and use it wherever you want on your

play06:31

devices which is super super slick but

play06:34

the nice thing about this is it keeps

play06:36

all this in one central location every

play06:38

single time you create a csr

play06:40

which is just amazing to me you know

play06:41

unless your business is a hundred

play06:43

percent through what's a global sign as

play06:45

an example it's a nightmare if you have

play06:50

internal certificate servers that you're

play06:53

using to issue certificates and you're

play06:55

creating CSR is that way you don't have

play06:57

a management tool it's just a nightmare

play06:59

and I know this firsthand so on this

play07:01

tool is just well worth the money and a

play07:03

lot of you people out there in

play07:05

organization probably aren't going to

play07:07

have a thousand certificates that you

play07:09

need to manage if I'm gonna have

play07:10

somewhere around 200 right and it's very

play07:13

reasonable I think it starts off at like

play07:14

a hundred dollars for this tool if you

play07:16

have you know 100 or 200 certificates

play07:19

and you can obviously get a quote up on

play07:20

the top here you can call them you can

play07:23

go to their site which is managed engine

play07:26

com and they have tons and tons of

play07:30

different tools there but I really

play07:32

wanted to make people aware about this

play07:35

tool because it is fairly new on the

play07:37

market and it is a very good tool for

play07:40

what it does you could streamline your

play07:42

whole process if you wanted using a

play07:44

certificate request basically let's say

play07:46

this would be your ticket generation

play07:48

process let's say you have a team that's

play07:52

generating these requests you have

play07:54

another team that's managing those

play07:56

certificates that could then come to the

play07:57

CSRs that create the CSRs once the CSRs

play08:01

are created they then get them signed

play08:02

either internally or externally and once

play08:05

they're done they can come back to this

play08:07

request let's say this is ticket right

play08:09

for demo they're all closed so let's

play08:12

just add one and we'll just call it a

play08:13

testing testing testing com number of

play08:21

days let's say watch 704 days and it's

play08:24

for XYZ calm all right ok so it's

play08:30

disabled for the demo but I know

play08:32

firsthand because i have used this tool

play08:35

you can after its that if you haven't

play08:38

closed the ticket yet and it's open you

play08:40

can click on the ticket and then when

play08:41

you go to close the ticket you can

play08:43

actually attach the certificate that you

play08:45

got from global sign or your internal

play08:48

certificate authority whoever you got

play08:50

that

play08:50

publicly signed by you can attach that

play08:52

into this certificate request area which

play08:55

basically closes changes the status the

play08:57

closed and then it will email that

play08:59

certificate internally without the

play09:01

passwords right to whoever needs that

play09:04

certificate and then the nice thing is

play09:06

if they have active directory

play09:07

credentials they can come here under

play09:10

certificates or sorry under CSRs and

play09:13

then they can view the passphrase

play09:14

further certificate so then it's all

play09:17

centering centrally managed it's not

play09:19

emailed out anywhere and it's just kept

play09:21

really really safe I'm sorry I'm not

play09:24

trying to rank here but I just wanted to

play09:26

touch all the topics on this just for

play09:29

SSL and what it does because it is a

play09:31

very very valid tool and you can

play09:34

generate reports with it there's so much

play09:36

more you can do with this tool and I'll

play09:38

let you guys check it out I appreciate

play09:40

you guys for watching and hopefully you

play09:42

guys learned something

Rate This

5.0 / 5 (0 votes)

الوسوم ذات الصلة
SSL ManagementIT ToolCertificate ExpirySecurityAutomationOrganizationalDashboardActive DirectoryCSR CreationKey StoreManaged Engine
هل تحتاج إلى تلخيص باللغة الإنجليزية؟