Download My Document
Transcript
Hansoft employs the industry standard AES-256 encryption algorithm for all communication between the client and the server. Additionally, from version 7.0, both client and server utilize X.509 certificate-based authentication and key exchange provided by the OpenSSL library. This is done to protect clients from hacked servers, and to protect servers from clients running on unauthorized machines, minimizing security risks such as identity theft, eavesdropping and unauthorized access to sensitive information. This product includes software developed by the OpenSSL Project for use in the OpenSSL Toolkit. (http://www.openssl.org/) Certificates In order to facilitate secure communication, the Hansoft server can be configured with a certificate issued from a Certificate Authority -- an entity in a chain of trust stemming from a number of established root authorities. By accepting the certificate, the user indicates that they trust the Certificate Authority, and therefore the server they are connecting to, and that the connection is allowed to continue. In addition, servers can be self-signed, in which case a Certificate Authority is not involved. Upon connecting for the first time, the user will be notified of this.