[4987] in WWW Security List Archive
RE: SSL encryption.
daemon@ATHENA.MIT.EDU (John Lehmann (SSASyd))
Mon Apr 7 00:15:01 1997
From: "John Lehmann (SSASyd)" <LEHMANNJ@saatchi.com.au>
To: "'www-security@ns2.rutgers.edu'" <www-security@ns2.rutgers.edu>
Date: Mon, 07 Apr 97 12:09:00 S
Errors-To: owner-www-security@ns2.rutgers.edu
>I know about SSL, but the application is for use outside USA, so as I
>understand it SSL will only be 40 bit encryption. This is not considered
>suitable.
If you have control over the clients accessing the server, ensure that
they are using SafePassage [http://www.ukweb.com/] or some other secure
proxy to access the web server - which could be running Apache with the
SSL patches or whatever (Whatever being Stronghold - same URL:).
--
John J "Just Say No to precompiled security"
Lehmann--lehmannj@saatchi.com.au