In message <[EMAIL PROTECTED]>, Ken Hornstein write s: >>mpb>Encryption? There are many ways to do that already. >>ken>Okay, give me one way of encrypting my network AFS traffic today. >> >>I can't comment on _your_ network AFS traffic since I know nothing >>of your network/servers/clients etc. > >But you said, "Encryption? There are many ways to do that already.". The tunneling solution is one example, AND i haven't read the AFS code for a long time, but it used to be the case that when the client created the connection to the server, it would specifiy the 'flavor' of connection. The choices of flavor would dictate the kind of security connection. If i remeber right, the kind of ticket you had helped the client code select between different flavors. I also seem to remember that the security code which manages the connections had code available for encrypting every byte in the connection, but in the RT days that code wasn't turned on. It could be that over time since the code wasn't used much, its falled into disrepair, and may have even been reaped, but it was considered in the past. I'm assuming that such a client would have to be physically secure, and that it would have to flush its cache frequently to purge any traces of the (decrypted) files on the local machine... at the very least when the user loses tokens. Maybe the mods to correctly support encryption are more significant than just mods at the protocol layer, or are you primarily concerned about sniffers like NFR? mts.
Re: encryption of AFS file service traffic?
Michael T. Stolarchuk Mon, 6 Apr 1998 16:37:24 +0200 (MET DST)
- encryption of AFS file service traffic? RL Bob Morgan
- Re: encryption of AFS file service traffic? Bjoern Groenvall
- Re: encryption of AFS file service traffic? John Hawkinson
- Re: encryption of AFS file service traffic? Derrick J Brashear
- Re: encryption of AFS file service traffic? Greg Hudson
- Re: encryption of AFS file service traffic? Per-Ola Mard
- Re: encryption of AFS file service traf... Paul Blackburn
- Re: encryption of AFS file service ... Ken Hornstein
- Re: encryption of AFS file ser... Paul Blackburn
- Re: encryption of AFS file... Ken Hornstein
- Re: encryption of AFS ... Michael T. Stolarchuk
- Re: encryption of AFS file service ... Chris Cowan
- Re: encryption of AFS file service traf... Per-Ola Mard
- Re: encryption of AFS file service traffic? Rich Sudlow
- Re: encryption of AFS file service traffic? Paul Blackburn
- Re: encryption of AFS file service traffic? Ken Hornstein
- Re: encryption of AFS file service traffic? Nathan J Williams
- Re: encryption of AFS file service traffic? Chris Cowan
