[4987] in WWW Security List Archive

home help back first fref pref prev next nref lref last post

RE: SSL encryption.

daemon@ATHENA.MIT.EDU (John Lehmann (SSASyd))
Mon Apr 7 00:15:01 1997

From: "John Lehmann (SSASyd)" <LEHMANNJ@saatchi.com.au>
To: "'www-security@ns2.rutgers.edu'" <www-security@ns2.rutgers.edu>
Date: Mon, 07 Apr 97 12:09:00 S
Errors-To: owner-www-security@ns2.rutgers.edu


>I know about SSL, but the application is for use outside USA, so as I
>understand it SSL will only be 40 bit encryption. This is not considered
>suitable.

If you have control over the clients accessing the server, ensure that   
they are using SafePassage [http://www.ukweb.com/] or some other secure   
proxy to access the web server - which could be running Apache with the   
SSL patches or whatever (Whatever being Stronghold - same URL:).

 --
John J "Just Say No to precompiled security"   
Lehmann--lehmannj@saatchi.com.au


home help back first fref pref prev next nref lref last post