Firewall Wizards mailing list archives
Re: Next Generation Firewall
From: Ted Doty <ted () iss net>
Date: Wed, 03 Dec 1997 16:07:54 -0500
At 09:41 AM 12/2/97 -0400, James Slupsky wrote:
1. If the system of encryption and authentication for the RPCs is a good
one (such >as Kerberos or DCE version 1.1), then don't some of these concerns go away? >(specifically, the authorized user concerns) This assumes that you will only exchange data with known (and presumably trusted) parties. This mailing list is an example of a good reason to communicate with people that you don't know, and have no reason to trust. As long as there are anonymous services (like the web) and quasi-anonymous services (like email mailing lists), crypto authentication is a limited solution. - Ted -------------------------------------------------------------- Ted Doty, Internet Security Systems | Phone: +1 770 395 0150 41 Perimeter Center East | Fax: +1 770 395 1972 Atlanta, GA 30346 USA | Web: http://www.iss.net -------------------------------------------------------------- PGP key fingerprint: 362A EAC7 9E08 1689 FD0F E625 D525 E1BE
Current thread:
- Re: Next Generation Firewall James Slupsky (Dec 03)
- Re: Next Generation Firewall Ted Doty (Dec 03)
- Firewall rulebase analysis and regression testing Rob Quinn (Dec 19)