RE: [Full-Disclosure] SSH vs. TLS

full-disclosure_at_nym.hush.com
Date: 06/29/04

  • Next message: James Patterson Wicks: "RE: [Full-Disclosure] PIX vs CheckPoint"
    To: full-disclosure@lists.netsys.com
    Date: Tue, 29 Jun 2004 11:29:25 -0700
    
    

    >So, what do you all think? Is SSH really that bad or are these
    >requirements unreasonable? Is it really worth implementing TLS Telnet?

    The requirements are perfect if you want to describe TLS and PKI.

    >- SSH is not an IETF standard.
    Why is this even an issue? It's an open protocol, and has been proven.
     Furthermore, the commercial and open source ssh clients/servers have
    likely been under more scrutiny than Telnet over TLS software.

    >- SSH allows tunneling other protocols, circumventing firewall
    > policies.
    SSH tunneling is a problem because the data is encrypted. TLS encrypts
    data, and other things can be tunneled over TLS, using the port for Telnet
    over TLS. Using TLS doesn't prevent circumvention of firewall policies
    through tunneling.

    >- There must be a mechanism to integrate both client and server keys
    > into LDAP.
    Well, that's convenient, isn't it?

    As for the other requirements, like you, I believe that Kerberos will
    address those issues. However, I've never implemented it and can't be
    certain.

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: James Patterson Wicks: "RE: [Full-Disclosure] PIX vs CheckPoint"

    Relevant Pages

    • Re: TLS negotiation
      ... There are several problems which would need to be addressed in order to negotiate TLS using the TELNET client program. ... "Negotiate TLS" means to do the initial TLS handshake and then subsequently all client/server interactions are encrypted. ... By the time that you solve all of this, you have writen a new program rather than any of the existing TELNET client programs. ...
      (comp.mail.misc)
    • Re: telnet mydomain.ild 465 : connection closed
      ... telnet localhost 25: the OutPut obtained as described as in the tutorial in the above link ... To test wrappermode TLS, use the "openssl s_client" command, which you ...
      (freebsd-questions)
    • Re: telnet mydomain.tld 465 ERROR : connection closed
      ... telnet localhost 25: the OutPut obtained as described as in the tutorial in the above link ... To test wrappermode TLS, use the "openssl s_client" command, which you ...
      (freebsd-questions)
    • TLS not required
      ... When I telnet in to my server it shows 250 - TLS and StartTLS, ... TLS enabled on smtp virrtual server. ...
      (microsoft.public.exchange.admin)
    • Re: sFTP from/to z/OS
      ... You have two main paths to take: SSH or TLS (transport ... TLS is a superset/replacement of SSL. ... ZFS/HFS files, which tends to constrain to a single LPAR. ... come with z/os, but is 'openware' downloadable from IBM. ...
      (bit.listserv.ibm-main)