Security Basics mailing list archives

Re: secure transfers and authentication


From: James Grace <e1photon () gmail com>
Date: Tue, 01 Apr 2008 19:19:46 -0400

I second the scp and maybe add the sftp protocol as well.

-- James

On Tue, 2008-04-01 at 16:57 -0500, Francisco Neira Basso wrote:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

mgk.mailing wrote:
Hi List

I was wondering if anyone had run across anything that would help with
my current project.   I am looking to automate transfers over an
insecure network where both the client and server are authenticated to
each other.  My current line of thinking is using ssl signed
certificates from our Certificate authority to do the authentication and
then https to transfer the data.  Putting aside that http may not be the
best transfer mechanism for data can anyone make any suggestions or
point out any potential pitfalls that maybe there?  It is vital that the
transfer is protected and that the client and server is authenticated.
Thanks

mgk


Hello,

What about scp?


- --
Francisco Neira B.
Seguridad de la Informacion
Defensoria del Pueblo
Lima, Peru  -05:00 UTC
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (GNU/Linux)
Comment: Using GnuPG with CentOS - http://enigmail.mozdev.org

iD8DBQFH8q+wFYZ03N+YDpMRAq/2AJ9gwQ7zP1mFAy5gWNV0R3pd4/OcsACfbgyp
/jkZH0HoRVPSaI0aR/2hsro=
=9Ouj
-----END PGP SIGNATURE-----


Current thread: