Security Basics mailing list archives

Re: 5 security questions


From: "Dr. S. A. Vetha Manickam" <avmanickam () yahoo com>
Date: Wed, 5 Mar 2003 00:21:58 -0800 (PST)


--- Çaðýl Þeker <cagils () biznet com tr> wrote:
I have a couple of questions related to security and smartcards:

1. An applet that has been transfered through the SSL tunnel can be forced to
communicate with the server (RMI) using the same SSL connection, using the
same certificate stored?

No.

2. Is there a standard that is obeyed by all smartcard hardware for
revocation?
Is it a revocation of Certificate. I don't think so.


3. When a smartcard is used to logon to Windows. When the card pulled out,
 the system can initiate an auto-logout. Is it a standard or depends on the
 software?
Depend on the software that one develops for login by replacing the gina.dll.




4. How can an applet can access the data inside a smartcard? Is there a
standard API / System to do it?

First of all, the applet has to be a signed applet. Then it has to interact with Smart
card API.

 
5. Does squid have LDAP support?

Yes, it supports LDAP. In addition, it supports PAM, KErberos, OpenLDAP, Window Domain
authentication.
 
Thanks.



ATTACHMENT part 2 application/pgp-signature name=signature.dat



=====


__________________________________________________
Do you Yahoo!?
Yahoo! Tax Center - forms, calculators, tips, more
http://taxes.yahoo.com/


Current thread: