Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Firewall Wizards: Re: IPsec and firewalls

Re: IPsec and firewalls

From: <carson_at_tla.org>
Date: Mon, 9 Feb 1998 12:56:28 -0500 (EST)

>>>>> "Adam" == Adam Shostack <adam_at_homeport.org> writes:

Adam> Regarding Carson's points about making your firewall a CA, I
Adam> think that for any company which has more than a few servers
Adam> internally, making the FW a Certification Authority is a mistake. A
...
Adam> I suspect that Carson knew this, and misspoke, hitting one of
Adam> my pet peeves. :)

Nope. I said make it _a_ CA, not _the_ CA. A big difference. The only certs
it would be signing are the bogus ones required to spoof SSL. Your browser
has to trust it as a CA, so you should make sure it's hard to get at its
signing key, but nobody _outside_ your organization should trust it, and you
don't have to trust it for signing keys (if your client software is smart
enough).

"I see...you want to go to https:/www.blackhat.com/nukeme.exe...<fumble
fumble fumble> _I'm_ www.blackhat.com. _Really_ I am. You trust me, don't
you? <bat, bat, bat> Now let's see if that file passes my toxic waste
filters..."

-- 
Carson Gaspar -- carson_at_cs.columbia.edu carson_at_tla.org carson_at_cugc.org
http://www.cs.columbia.edu/~carson/home.html
Queen Trapped in a Butch Body
Received on Feb 09 1998
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos