Newbie requests clarification

From: Mark (mark@artwarren.co.ukNOSPAM)
Date: 02/25/02


From: mark@artwarren.co.ukNOSPAM (Mark)
Date: Mon, 25 Feb 2002 16:30:47 GMT

Hi,

I am trying to gain an overview of the suitability of SSH for a
project I am involved in, but having little knowledge of server side
technologies, I need some clarification of my understanding of SSH.

The project is an online database accessible by users at home, in
Internet cafes, libraries, etc. We wish to protect passwords and
usernames only, no critical financial information currently passes
between client and server.

Our problem is whether to use SSH or SSL. I would be grateful for
clarification on the following points.

Do I understand correctly that SSH must be explicitly installed on the
users machine, unlike SSL that is automatically supported by most web
browsers? Can this installation be done via a downloadable,
idiot-proof .exe file?

Given that users will only be reading and sending data (via online
forms) of a low-level security nature is using SSH overkill?

Any other pearls of wisdom you may wish to cast in my direction would
be gratefully received.

Thanks for your troubles.

Mark



Relevant Pages

  • Re: Apache Software Foundation Server compromised, resecured. (fwd)
    ... this was one "result" of the comromised ssh binary at sourceforge. ... a public server of the Apache Software Foundation ... > (ASF) was illegally accessed by unknown crackers. ... > exhaustive audit of all Apache source code and binary distributions ...
    (FreeBSD-Security)
  • Re: FreeBSD Crash without Errors, Warnings, or Panics
    ... I suppose I could run on stable until the driver is fixed in a release branch, but I need this box up and online, and I've always read that the stable branch is not the place for production servers. ... I'm running 6.0-RELEASE-p5 on a Toshiba built server: dual Xeon Intel motherboard with a LSILogic MegaRAID controller. ... Also, some network ports still respond, like a telnet to port 22 to test SSH will yield an SSH banner, but trying to connect with SSH just hangs. ... The box runs a web-based app and connects to a local Postgres DB which seemed to be unable to start new connections being requested by the PHP scripts. ...
    (freebsd-hackers)
  • Re: restrict ssh access
    ... > We have one ssh server which receives about 6000 failed attempts to ... > unsuccessful login attempts per client IP address? ... the remote server is also running OpenSSH. ...
    (comp.security.ssh)
  • Re: SSH as root
    ... Subject: SSH as root ... but it doesn't require having a key on the server that could be ... If they compromise a server, and the passphrase, etc. is there, they only ... private key to anyone. ...
    (SSH)
  • Re: Explanation of SSH
    ... I am still unclear on how SSH works exactly. ... Client issues SSH command and names server ... "Shopper" says "server sends back its public host and server keys ... Surely there is only one public key it sends ...
    (comp.security.ssh)