Re: [fw-wiz] Why are developers choosing to...



>
> Why are developers choosing to write "web-based" code that runs some
> sort of encryption, typically SSL, across a non-standard port (say
> 10443) and then having those URLs blow up when they try to traverse the
> prudent company's perimeter security...You know..."deny all that is not
> explicitly allowed."
>
> I am seeing more and more "websites" that use a URL such as
> http://register.at.my.site:10443. Why not just use the standard secure
> port 443 from the get go? Is there something that makes SSL across
> 10443 innately more secure, or is this just the "security by obscurity"
> smoke-and-mirrors trick?

Well, you don't have to run the web server software as root, if it is
running on Unix system, to use port 10443.

Darren
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxx
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • Re: Installing ISA Server for first time
    ... Please note that though correct for HTTP SSL on non standard ports I'm not ... the ISA 2004 can only allow SSL 443 port go through it. ... Microsoft is providing this information as aconvenience to you. ...
    (microsoft.public.windows.server.sbs)
  • Re: Self Signed Certificates
    ... RWW works fine using SSL port 443. ... My config for the site is using port 444, windows authentication, SSL is ...
    (microsoft.public.windows.server.sbs)
  • Re: Installing ISA Server for first time
    ... the ISA 2004 can only allow SSL 443 port go through it. ... Microsoft is providing this information as aconvenience to you. ...
    (microsoft.public.windows.server.sbs)
  • Re: running an ssl webserver
    ... >> My machine is only listening for port 80 connections This is through ... >> How do i open an ssl port on this internal webserver. ... SSLRandomSeed startup builtin ...
    (comp.os.linux.security)
  • Re: OE6 problem: SMTP port 465 /w SSL
    ... port, too, but when I send a mail, it always return something like this: ... Your server has unexpectedly terminated the connection. ... SSL in server and don't set SSL on clients, ... authentication requiring TLS is checked, NT authentication is disabled as it ...
    (microsoft.public.exchange.clients)