<?xml version="1.0" encoding="ISO-8859-1"?><article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
<front>
<journal-meta>
<journal-id>1390-6542</journal-id>
<journal-title><![CDATA[Enfoque UTE]]></journal-title>
<abbrev-journal-title><![CDATA[Enfoque UTE]]></abbrev-journal-title>
<issn>1390-6542</issn>
<publisher>
<publisher-name><![CDATA[Universidad UTE]]></publisher-name>
</publisher>
</journal-meta>
<article-meta>
<article-id>S1390-65422017000100273</article-id>
<article-id pub-id-type="doi">10.29019/enfoqueute.v8n1.128</article-id>
<title-group>
<article-title xml:lang="es"><![CDATA[Análisis de Certificados SSL/TLS gratuitos y su implementación como Mecanismo de seguridad en Servidores de Aplicación.]]></article-title>
<article-title xml:lang="en"><![CDATA[Analysis of free SSL/TLS Certificates and their implementation as Security Mechanism in Application Servers.]]></article-title>
</title-group>
<contrib-group>
<contrib contrib-type="author">
<name>
<surname><![CDATA[Hurtado]]></surname>
<given-names><![CDATA[Mario E. Cueva]]></given-names>
</name>
<xref ref-type="aff" rid="Aff"/>
</contrib>
<contrib contrib-type="author">
<name>
<surname><![CDATA[Sarango]]></surname>
<given-names><![CDATA[Diego Javier Alvarado]]></given-names>
</name>
<xref ref-type="aff" rid="Aff"/>
</contrib>
</contrib-group>
<aff id="Af1">
<institution><![CDATA[,Universidad Nacional de Loja  ]]></institution>
<addr-line><![CDATA[Loja ]]></addr-line>
<country>Ecuador</country>
</aff>
<aff id="Af2">
<institution><![CDATA[,Universidad Nacional de Loja  ]]></institution>
<addr-line><![CDATA[Loja ]]></addr-line>
<country>Ecuador</country>
</aff>
<pub-date pub-type="pub">
<day>00</day>
<month>02</month>
<year>2017</year>
</pub-date>
<pub-date pub-type="epub">
<day>00</day>
<month>02</month>
<year>2017</year>
</pub-date>
<volume>8</volume>
<fpage>273</fpage>
<lpage>286</lpage>
<copyright-statement/>
<copyright-year/>
<self-uri xlink:href="http://scielo.senescyt.gob.ec/scielo.php?script=sci_arttext&amp;pid=S1390-65422017000100273&amp;lng=en&amp;nrm=iso"></self-uri><self-uri xlink:href="http://scielo.senescyt.gob.ec/scielo.php?script=sci_abstract&amp;pid=S1390-65422017000100273&amp;lng=en&amp;nrm=iso"></self-uri><self-uri xlink:href="http://scielo.senescyt.gob.ec/scielo.php?script=sci_pdf&amp;pid=S1390-65422017000100273&amp;lng=en&amp;nrm=iso"></self-uri><abstract abstract-type="short" xml:lang="es"><p><![CDATA[Resumen: La seguridad en la capa de aplicación (SSL), proporciona la confidencialidad, integridad y autenticidad de los datos, entre dos aplicaciones que se comunican entre sí. El presente artículo es el resultado de haber implementado certificados SSL / TLS gratuitos en servidores de aplicación, determinando las características relevantes que debe tener un certificado SSL/TLS, la Autoridad certificadora que lo emita. Se realiza un análisis de las vulnerabilidades en los servidores web y se establece un canal cifrado de comunicaciones con el fin de proteger de ataques como hombre en el medio, phising y mantener la integridad de la información que es trasmitida entre el cliente y servidor.]]></p></abstract>
<abstract abstract-type="short" xml:lang="en"><p><![CDATA[Abstract: Security in the application layer (SSL), provides the confidentiality, integrity, and authenticity of the data, between two applications that communicate with each other. This article is the result of having implemented Free SSL / TLS Certificates in application servers, determining the relevant characteristics that must have a SSL/TLS certificate, the Certifying Authority generate it. A vulnerability analysis is developed in application servers and encrypted communications channel is established to protect against attacks such as man in the middle, phishing and maintaining the integrity of information that is transmitted between the client and server.]]></p></abstract>
<kwd-group>
<kwd lng="es"><![CDATA[Seguridad]]></kwd>
<kwd lng="es"><![CDATA[Certificados SSL/TLS]]></kwd>
<kwd lng="es"><![CDATA[Autoridad Certificadora]]></kwd>
<kwd lng="es"><![CDATA[Vulnerabilidades]]></kwd>
<kwd lng="es"><![CDATA[X.509]]></kwd>
<kwd lng="es"><![CDATA[Kali Linux.]]></kwd>
<kwd lng="en"><![CDATA[Security]]></kwd>
<kwd lng="en"><![CDATA[Certificates SSL/TLS]]></kwd>
<kwd lng="en"><![CDATA[Certifying Authority]]></kwd>
<kwd lng="en"><![CDATA[Vulnerabilities]]></kwd>
<kwd lng="en"><![CDATA[X.509]]></kwd>
<kwd lng="en"><![CDATA[Kali Linux.]]></kwd>
</kwd-group>
</article-meta>
</front><back>
<ref-list>
<ref id="B1">
<nlm-citation citation-type="confpro">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Clark]]></surname>
<given-names><![CDATA[J.]]></given-names>
</name>
<name>
<surname><![CDATA[Van Oorschot]]></surname>
<given-names><![CDATA[P. C.]]></given-names>
</name>
</person-group>
<source><![CDATA[SoK: SSL and HTTPS: Revisiting past challenges and evaluating certificate trust model enhancements]]></source>
<year>2013</year>
<conf-name><![CDATA[ Proceedings - IEEE Symposium on Security and Privacy]]></conf-name>
<conf-loc> </conf-loc>
<page-range>511-25</page-range></nlm-citation>
</ref>
<ref id="B2">
<nlm-citation citation-type="confpro">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Durumeric]]></surname>
<given-names><![CDATA[Z.]]></given-names>
</name>
<name>
<surname><![CDATA[Kasten]]></surname>
<given-names><![CDATA[J.]]></given-names>
</name>
</person-group>
<source><![CDATA[Analysis of the HTTPS certificate ecosystem]]></source>
<year>2013</year>
<conf-name><![CDATA[ Proceedings of the 2013 on Internet]]></conf-name>
<conf-loc> </conf-loc>
<page-range>291-304</page-range></nlm-citation>
</ref>
<ref id="B3">
<nlm-citation citation-type="">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Enrique]]></surname>
<given-names><![CDATA[M.]]></given-names>
</name>
<name>
<surname><![CDATA[Hurtado]]></surname>
<given-names><![CDATA[C.]]></given-names>
</name>
<name>
<surname><![CDATA[Javier]]></surname>
<given-names><![CDATA[D.]]></given-names>
</name>
<name>
<surname><![CDATA[Sarango]]></surname>
<given-names><![CDATA[A.]]></given-names>
</name>
<name>
<surname><![CDATA[Gustavo]]></surname>
<given-names><![CDATA[R.]]></given-names>
</name>
<name>
<surname><![CDATA[Díaz]]></surname>
<given-names><![CDATA[F.]]></given-names>
</name>
<name>
<surname><![CDATA[Torres]]></surname>
<given-names><![CDATA[H.]]></given-names>
</name>
</person-group>
<source><![CDATA[Revisión Sistemática de Certificados SSL / TLS como Mecanismo de Seguridad en Servidores de Aplicación]]></source>
<year>2017</year>
</nlm-citation>
</ref>
<ref id="B4">
<nlm-citation citation-type="journal">
<article-title xml:lang=""><![CDATA[Procedures for performing systematic reviews]]></article-title>
<person-group person-group-type="author">
<name>
<surname><![CDATA[Kitchenham]]></surname>
<given-names><![CDATA[B.]]></given-names>
</name>
</person-group>
<source><![CDATA[Keele]]></source>
<year>2004</year>
<volume>33</volume>
<page-range>28</page-range><publisher-loc><![CDATA[UK ]]></publisher-loc>
<publisher-name><![CDATA[Keele University]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B5">
<nlm-citation citation-type="confpro">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Markovi]]></surname>
<given-names><![CDATA[M.]]></given-names>
</name>
</person-group>
<source><![CDATA[Data protection techniques, cryptographic protocols and PKI systems in modern computer networks]]></source>
<year>2007</year>
<conf-name><![CDATA[ 2007 IWSSIP and EC-SIPMCS - Proc. 2007 14th Int. Workshop on Systems, Signals and Image Processing, and 6th EURASIP Conf. Focused on Speech and Image Processing, Multimedia Communications and Services]]></conf-name>
<conf-loc> </conf-loc>
<page-range>13-24</page-range></nlm-citation>
</ref>
<ref id="B6">
<nlm-citation citation-type="">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Mu]]></surname>
<given-names><![CDATA[F.]]></given-names>
</name>
<name>
<surname><![CDATA[Zhang]]></surname>
<given-names><![CDATA[J.]]></given-names>
</name>
<name>
<surname><![CDATA[Du]]></surname>
<given-names><![CDATA[J.]]></given-names>
</name>
<name>
<surname><![CDATA[Lin]]></surname>
<given-names><![CDATA[J.]]></given-names>
</name>
</person-group>
<source><![CDATA[Application of the Secure Transport SSL Protocol in Network Communication]]></source>
<year>2011</year>
</nlm-citation>
</ref>
<ref id="B7">
<nlm-citation citation-type="confpro">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Ordean]]></surname>
<given-names><![CDATA[M.]]></given-names>
</name>
<name>
<surname><![CDATA[Giurgiu]]></surname>
<given-names><![CDATA[M.]]></given-names>
</name>
</person-group>
<source><![CDATA[Implementation of a security layer for the SSL/TLS protocol]]></source>
<year>2010</year>
<conf-name><![CDATA[ 9International Symposium on Electronics and Telecommunications, ISETC&#8217;10 - Conference Proceedings]]></conf-name>
<conf-date>2010</conf-date>
<conf-loc> </conf-loc>
<page-range>209-12</page-range></nlm-citation>
</ref>
<ref id="B8">
<nlm-citation citation-type="journal">
<article-title xml:lang=""><![CDATA[Vulnerabilidades de las Redes TCP/IP y Principales Mecanismos de Seguridad]]></article-title>
<person-group person-group-type="author">
<name>
<surname><![CDATA[Riffo]]></surname>
<given-names><![CDATA[M. A.]]></given-names>
</name>
</person-group>
<source><![CDATA[In Vitro]]></source>
<year>2008</year>
<volume>3</volume>
<numero>2</numero>
<issue>2</issue>
<page-range>1-23</page-range></nlm-citation>
</ref>
<ref id="B9">
<nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Subías]]></surname>
<given-names><![CDATA[M. P.]]></given-names>
</name>
</person-group>
<source><![CDATA[Desfalcos]]></source>
<year>2007</year>
<page-range>25-6</page-range><publisher-name><![CDATA[Phishing]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B10">
<nlm-citation citation-type="confpro">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Wagner]]></surname>
<given-names><![CDATA[D.]]></given-names>
</name>
<name>
<surname><![CDATA[Schneier]]></surname>
<given-names><![CDATA[B.]]></given-names>
</name>
</person-group>
<source><![CDATA[Analysis of the SSL 3.0 protocol]]></source>
<year>1996</year>
<conf-name><![CDATA[ Proceedings of the 2nd Conference on Proceedings of the Second USENIX Workshop on Electronic Commerce - Volume 2, 4]]></conf-name>
<conf-loc> </conf-loc>
</nlm-citation>
</ref>
</ref-list>
</back>
</article>
