Re: [fw-wiz] Integrating firewall into crypto infrastructure?

From: Andras Kis-Szabo (kisza@securityaudit.hu)
Date: 08/17/02


From: Andras Kis-Szabo <kisza@securityaudit.hu>
To: ark@eltex.ru
Date: Sat Aug 17 06:25:01 2002

Hi,

> (SSL this time. dealing with IPSEC is obvious, doing kerberos is damn
> tricky and i have no time for it)

Try to connect with people on zorp@lists.balabit.hu
The related product is: http://www.balabit.hu/en/products/ZorpPro/
(As far as I know this is openssl based, too, but it is well tested and
designed; and solves some of Your problems.)

Regards,

        kisza

-- 
    Andras Kis-Szabo       Security Development, Design and Audit
-------------------------/        Zorp, NetFilter and IPv6
 kisza@SecurityAudit.hu /-----Member of the BUTE-MIS-SEARCHlab------>


Relevant Pages

  • RE: Passwords with Lan Manager (LM) under Windows
    ... First "You can't precompile that data into a rainbow, ... As I said earlier "Kerberos support with IPsec" And by this yes ... Passwords with Lan Manager under Windows ...
    (Pen-Test)
  • Re: IPSec without encryption between intranet and standalone
    ... I've also unassinged the IPSec polcy and instantly the 'lag' disappears ... I was not aware I could enter a nonsense string as a shared ... security associations (Kerberos and talk of shared key). ... If I used a sharedkey how ...
    (microsoft.public.win2000.security)
  • Re: Microsoft IPSec via group policy
    ... IPsec could accomplish this. ... packets containing Kerberos hashes that are sent over the network between ... However you could build a CUSTOM Policy (without ... Requiring ipsec between a client and a DC via GPO is problematic. ...
    (Security-Basics)
  • Re: Kerberos Question
    ... However if you use ipsec negotiation within the domain by ... default kerberos computer authentication will be used and required. ... >> Security Policy and Domain Controller Security Policy and disable storage ...
    (microsoft.public.windows.server.security)
  • Re: ACL login security access
    ... I am already using IPSec with Kerberos authentification on my Domain network ... Kerberos even from a Workgroup machine, just by opening a Windows Explorer ... > traffic that involves authentication and Active Directory with domain ...
    (microsoft.public.windows.server.security)