FreeS/WAN graphical configurator (was: Making FreeS/WAN harder to use)
"John A. Sullivan III" <[email protected]> 03 Mar 2003 05:49:24 -0500
| Newsgroups | gmane.network.freeswan.devel |
|---|---|
| Message-ID | <[email protected]> |
I am imagining that you envision a GUI tool to administer individual hosts. Thus, our project may not be what you are looking for. But, in case it may be of assistance, we have just launched iscs.sourceforge.net (http://iscs.sourceforge.net and http://www.sourceforge.net/projects/iscs). There is not much on the site yet. We were about six weeks away from beta but funding has been reduced to two days per week :-( . This tool is intended to initially configure many FSW/iptables gateways from a single, central security policy manager. The idea is to create high level policies that translate themselves into the enforcement rules needed by tools like FSW and iptables and then automatically distribute themselves to those enforcement points. We then plan to extend it to include both other security tools and individual clients. We had not planned to address OE. Most documentation is actually in the CVS rather than the documentation section. Let me know if it may be of use - John On Sun, 2003-03-02 at 06:05, [email protected] wrote: > Date: Sun, 02 Mar 2003 05:01:53 -0500 > From: "John S. Denker" <[email protected]> > To: [email protected] > CC: [email protected], [email protected] > Subject: [Design] Re: [Users] Making FreeS/WAN harder to use, INTENTIONALLY. > > D) This raises some questions about where the boundary > of the FreeS/WAN project should be. It is one thing > to provide bare-bones functionality. It is another > thing to provide an easy-to-use admin interface. So > far it appears that most of the work has gone into > functionality. But there will come -- or has come -- > a point where usability issues start cutting into > security and/or start cutting into customer acceptance. > > One could imagine having a "configurator" script that > asks a few _high level_ questions, allowing the customer > to select from a smallish number of standard solutions > to common problems. The configurator then implements > the chosen high-level policy in terms of low-level > router, netfilter, IPsec, and DNSSEC functions. > > If the project goal is to have IPsec be widely used, > such a configurator might significantly advance that > goal. The advantages (from the customer's point of > view) of a configurator over an intricate multi-step > error-prone manual process should be obvious. > > The downside (from the project management point of > view) is that the complexity of such a configurator > is comparable to a small compiler. It will take a some > leadership and some commitment to make this happen. > > > > --__--__-- > > _______________________________________________ > Design mailing list > [email protected] > http://lists.freeswan.org/mailman/listinfo/design > > > End of Design Digest -- John A. Sullivan III Chief Technology Officer Nexus Management +1 207-985-7880 [email protected]