Ftp-WG: status of rfc 2228

Jeffrey Altman <[email protected]> Tue, 4 Nov 2003 08:39:27 -0500
Newsgroups gmane.ietf.ftpext
Organization Columbia University in the City of New York
Message-ID <[email protected]>
[email protected] wrote:

>hello all,
>
>i'm new to the list.
>
>very recently, i've taken an interest in the status of rfc 2228 as i wish to implement some means of user authentication, integrity protection, and optional data encryptiong to an existing ftpd implementation.
>
>i was wondering if anyone knew which ftp implementations currently support the proposed security extensions.
>  
>
There are many implementations supporting

  GSSAPI-Kerberos 5
  Kerberos 4
  Secure Remote Password
  Transport Layer Security v1

Kermit <http://www.kermit-project.org/> is a FTP client which supports 
all of the above.
We have a partial list of servers at 
<http://www.kermit-project.org/ftpd.html>

>and finally, are there any thoughts on combining the control connection and data connection?  in my eyes, this would eliminate the bounce attack and make ftp less of a problem for nat'd connections and firewalls.
>  
>
If you want a secure file transfer solution which requires only a single 
channel, then
you want RFC 2839, Internet Kermit Service.  
<ftp://ftp.isi.edu/in-notes/rfc2839.txt>
and <http://www.kermit-project.org/iksd.html>

>thanks for any feedback
>
>
>abe
>  
>
smime.p7s (application/x-pkcs7-signature, 3.3 KB) - not displayed