Security Basics mailing list archives

RE: sftp vs ftp with ssl


From: "Nauwelaerts, Nick" <nick.nauwelaerts () compu-mark com>
Date: Mon, 18 Aug 2003 17:34:45 +0200

-----Original Message-----
From: subscribe [mailto:subscribe () kringstad net] 
Sent: Wednesday, August 06, 2003 07:54 PM
To: security-basics () securityfocus com
Subject: sftp vs ftp with ssl


Hi list,
I've been trying to get up an secure ftp server on linux platform, pureftpd.
This utillity support both sftp and ftp tls/ssl. Is there anyone who has any
experiance with secure ftp servers on any platforms? any suggestions? or
pointers? Im not sure how firewalls will react on these two types, regarding
ports etc?



Heya,
Last time I looked I did not find any FTP server that encrypted it's data
channel with SSL, only the control channel. This would lead to encrypted
passwords, but the actual data transferred would still be in the clear.
sftp however encrypts both control & data, it's a very different protocal as
ftp is. Also, sftp is much easier to firewall as ftp/ssl, since only port
22/tcp is used.

// nick

---------------------------------------------------------------------------
----------------------------------------------------------------------------


Current thread: