On Aug 14, 2007, at 12:26 PM, Alan Altmark wrote:
On Tuesday, 08/14/2007 at 11:26 EDT, "Mrohs, Ray"
<[EMAIL PROTECTED]>
wrote:
I just did the same with stunnel provided with SLES10. It seems to
work
fine. Now what are the disadvantages compared to SSLSERV?
It's the same as the pre-z/VM 5.3 support, requiring the client to
establish the SSL session before it starts sending protocol data.
- you'll need clients that support that model (not defined by RFC)
- it works for inbound connections only
Not so much disadvantages as they are restrictions.
There's another one.
You may well have exceptionally boneheaded security auditors, who
insist that unencrypted communications are always BAD and WRONG and
EVIL, and no amount of explaining to them that the cleartext network
path is actually *entirely inside* the z/VM image will get them to
see the light.
Adam