GraphOn Support Forums
Welcome, Guest
Please Login or Register.    Lost Password?
Go to bottom Post Reply Favoured: 0
TOPIC: Re: SSL
#75
troym (Admin)
Admin
Posts: 202
graphgraph
User Online Now Click here to see the profile of this user
Gender: Male Birthdate: 1973-01-14
Re: SSL 5 Years, 2 Months ago Karma: 1  
QUOTE:
How does GoGlobal use ssl? Specifically, I refer to
http://www.cert.org/advisories/CA-2003-26.html.


GO-Global for UNIX uses a version of OpenSSL that is affected by the advisory you have linked to. You can disable the SSL port, and thus not be vulnerable by passing an "-sslport 0" argument to the "gold" daemon, or by specifying "GOLD_SSL_PORT=0" in the ${GOGLOBAL_ROOT}/etc/gold.conf file.

This set of vulnerabilities is scheduled to be addressed in the next point release of GO-Global for UNIX (v2.1.1). The estimated timeframe is a bit fluid as we are adding and removing requirements that will be included, but it should be in the first quarter of 2004, if not sooner. (This is not a guarantee and should only be considered a possibility, however.)

While GO-Global for UNIX is technically vulnerable to exploits as listed in the advisory, most users of our product use it on an isolated LAN environment (or over a VPN where access is controlled). As such, the server is not subject to attack from unknown intruders (such as a web server would be). In additionl, the vulnerabilities are related to client certificate verification, which the GO-Global product does not currently do, so exposure is limited by this as well. Obviously none of this is intended as an excuse, let alone a good one, for not having addressed this vulnerability, but only a rationale as to why this has not been addressed to date.

Hope this helps,
Troy
 
Report to moderator   Logged Logged  
 
Troy Morrison
troy @ graphon.com
GraphOn Corporation
  The administrator has disabled public write access.
      Topics Author Date
    thread link
SSL
gkkitag 2003/11/04 20:15
    thread link
thread linkthread link Re: SSL
troym 2003/11/04 21:15
Go to top Post Reply
Powered by FireBoardget the latest posts directly to your desktop