Re: NNTPS pointers
Grant Taylor <[email protected]>
| Newsgroups | gmane.network.inn |
|---|---|
| Organization | TNet Consulting |
| Message-ID | <[email protected]> |
On 10/19/21 3:36 PM, Julien ÉLIE wrote: > Hi Grant, Hi Julien, > Yep! ;-) > Usually, either IPsec or stunnel with TCP wrappers is used for innd. ACK Would you please elaborate on what you mean by "stunnel with TCP wrappers"? As in what is TCP wrappers doing to modify stunnel? Is it just allowing / blocking access? If so, I'd think that a firewall could do the same thing. > Note that STARTTLS is now discouraged because of possible > man-in-the-middle attacks. Implementations SHOULD use implicit TLS on > port 563 (see RFC 8143). Sure. Implicit TLS would be nice for NNTP (server-to-server). But, I think that STARTTLS is the lesser of the evils (sub-optimal security vs no security). > It is tricky to implement in innd, with its channels... > Same thing for COMPRESS, which would be useful to have in transit mode. *nod* > Patch welcome of course :-) I'm not personally qualified to do write a patch. -- Grant. . . . unix || die
smime.p7s
(application/pkcs7-signature, 3.9 KB) - not displayed