jails, ipfilter & stunnel

From: V. Jones (vjones62_at_earthlink.net)
Date: 07/13/03

  • Next message: Uwe Doering: "Re: jails, ipfilter & stunnel"
    Date: Sat, 12 Jul 2003 18:43:26 -0700 (PDT)
    To: freebsd-security@freebsd.org
    
    

    I'm setting up a server where I plan to use Jails to improve security
    I also have installed and am configuring ipfilter. Here are my
    questions:

    Because I'm using Jails, I will have to have multiple ip aliases on the
    network interface. I will use ipfilter to specify what can go to each
    of the addresses. (e.g., allow only incoming to port 80 on the jail
    running apache).

    Another jailed server will run mail services (pop, smtp, imap). If
    I want to allow users to use web based email(over ssl of course), the
    web server will have to communicate with the mail server. Is there
    a chance of "information leakage" in this type of setup?

    Finally, I'd like to use SSL to offer secure web connections & secure email
    without having to buy two certificates. Am I getting too cute if I accept
    ssl connections on one ip address and use stunnel to route them to the
    appropriate jailed server?
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"


  • Next message: Uwe Doering: "Re: jails, ipfilter & stunnel"

    Relevant Pages

    • Re: No libc shared lib number bump ?
      ... versioned symbol libraries with the same version number since ... When things like large Xorg or GNOME or KDE changes hit the Ports ... I have 11 of my 12 jails on ... IMAP server, one as a nntp server, one as a samba server, ...). ...
      (freebsd-current)
    • Re: jails, ipfilter & stunnel
      ... > I'm setting up a server where I plan to use Jails to improve security ... > I also have installed and am configuring ipfilter. ... > Because I'm using Jails, I will have to have multiple ip aliases on the ... > ssl connections on one ip address and use stunnel to route them to the ...
      (FreeBSD-Security)
    • Re: UFS Crash and directories now missing
      ... the one with the jails mounted but every jail ... so I'm guessing it's a logical error in the directory structure or ... Right before the server crashed I noticed MySQL at 100% o several CPUs ...
      (freebsd-questions)
    • Re: ZFS, Jails, network, routing, domains and IP addresses
      ... My question concerns jails and the set-up I thought about. ... the future server has 48 GB of RAM and 2 2TB HDDs. ... On every host there'll be a Postfix and Apache installation. ... The idea is the jails' host does something like this: Connection to ...
      (freebsd-questions)
    • Re: 6.8 became very slow
      ... It was running twe driver with RAID 5. ... just copied jails from the prev installation. ... the kernel must be for something else, ... It is a web hosting server ...
      (freebsd-questions)