Re: NNTPS pointers

Grant Taylor <[email protected]>
Newsgroups gmane.network.inn
Organization TNet Consulting
Message-ID <[email protected]>
On 10/19/21 3:36 PM, Julien ÉLIE wrote:
> Hi Grant,

Hi Julien,

> Yep!

;-)

> Usually, either IPsec or stunnel with TCP wrappers is used for innd.

ACK

Would you please elaborate on what you mean by "stunnel with TCP 
wrappers"?  As in what is TCP wrappers doing to modify stunnel?  Is it 
just allowing / blocking access?  If so, I'd think that a firewall could 
do the same thing.

> Note that STARTTLS is now discouraged because of possible 
> man-in-the-middle attacks.  Implementations SHOULD use implicit TLS on 
> port 563 (see RFC 8143).

Sure.  Implicit TLS would be nice for NNTP (server-to-server).  But, I 
think that STARTTLS is the lesser of the evils (sub-optimal security vs 
no security).

> It is tricky to implement in innd, with its channels...
> Same thing for COMPRESS, which would be useful to have in transit mode.

*nod*

> Patch welcome of course :-)

I'm not personally qualified to do write a patch.



-- 
Grant. . . .
unix || die
smime.p7s (application/pkcs7-signature, 3.9 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.