FreeS/WAN graphical configurator (was: Making FreeS/WAN harder to use)

"John A. Sullivan III" <[email protected]> 03 Mar 2003 05:49:24 -0500
Newsgroups gmane.network.freeswan.devel
Message-ID <[email protected]>
	I am imagining that you envision a GUI tool to administer individual
hosts.  Thus, our project may not be what you are looking for.  But, in
case it may be of assistance, we have just launched iscs.sourceforge.net
(http://iscs.sourceforge.net and
http://www.sourceforge.net/projects/iscs).  There is not much on the
site yet.  We were about six weeks away from beta but funding has been
reduced to two days per week :-(  .  This tool is intended to initially
configure many FSW/iptables gateways from a single, central security
policy manager.  The idea is to create high level policies that
translate themselves into the enforcement rules needed by tools like FSW
and iptables and then automatically distribute themselves to those
enforcement points.  We then plan to extend it to include both other
security tools and individual clients.  We had not planned to address
OE.  Most documentation is actually in the CVS rather than the
documentation section.  Let me know if it may be of use - John

On Sun, 2003-03-02 at 06:05, [email protected] wrote:
> Date: Sun, 02 Mar 2003 05:01:53 -0500
> From: "John S. Denker" <[email protected]>
> To: [email protected]
> CC: [email protected], [email protected]
> Subject: [Design] Re: [Users] Making FreeS/WAN harder to use, INTENTIONALLY.
> 

> D) This raises some questions about where the boundary
> of the FreeS/WAN project should be.  It is one thing
> to provide bare-bones functionality.  It is another
> thing to provide an easy-to-use admin interface.  So
> far it appears that most of the work has gone into
> functionality.  But there will come -- or has come --
> a point where usability issues start cutting into
> security and/or start cutting into customer acceptance.
> 
> One could imagine having a "configurator" script that
> asks a few _high level_ questions, allowing the customer
> to select from a smallish number of standard solutions
> to common problems.  The configurator then implements
> the chosen high-level policy in terms of low-level
> router, netfilter, IPsec, and DNSSEC functions.
> 
> If the project goal is to have IPsec be widely used,
> such a configurator might significantly advance that
> goal.  The advantages (from the customer's point of
> view) of a configurator over an intricate multi-step
> error-prone manual process should be obvious.
> 
> The downside (from the project management point of
> view) is that the complexity of such a configurator
> is comparable to a small compiler.  It will take a some
> leadership and some commitment to make this happen.
> 
> 
> 
> --__--__--
> 
> _______________________________________________
> Design mailing list
> [email protected]
> http://lists.freeswan.org/mailman/listinfo/design
> 
> 
> End of Design Digest
-- 
John A. Sullivan III
Chief Technology Officer
Nexus Management
+1 207-985-7880
[email protected]