Re: How is Passive FTP with TLS and NAT supposed to work?

2020-06-15 Thread Kirk Wolf
On Fri, Jun 12, 2020 at 3:56 PM Paul Gilmartin < 000433f07816-dmarc-requ...@listserv.ua.edu> wrote: > On Fri, 12 Jun 2020 20:46:49 +, Jackson, Rob wrote: > > >Before I found out about Co:Z I used shell scripts and REXX in OMVS to > copy the files back and forth from MVS datasets to OMVS

Re: How is Passive FTP with TLS and NAT supposed to work?

2020-06-13 Thread Jackson, Rob
A yeah, my bad, that looks right. Details do count. I was going from faulty memory. :) Thanks! First Horizon Bank Mainframe Technical Support -Original Message- From: IBM Mainframe Discussion List On Behalf Of Charles Mills Sent: Saturday, June 13, 2020 12:28 PM To:

Re: How is Passive FTP with TLS and NAT supposed to work?

2020-06-13 Thread Charles Mills
THANK YOU. Yes, PASSIVEIGNOREADDR is the key (and BTW you can then eliminate CCC with its security exposure). Shows what a kludge FTP is. The client says "Let's go into passive mode. Tell me what IP address to use, and I will ignore it. Thank you. Because after all, I already know your IP

Re: How is Passive FTP with TLS and NAT supposed to work?

2020-06-13 Thread Jackson, Rob
My cruddy email application (Outlook) doesn't do the >-style quoting (or at least I don't know how to make it), so let me try below with tabs; it will probably be ugly. First Horizon Bank Mainframe Technical Support -Original Message- From: IBM Mainframe Discussion List On Behalf Of

Re: How is Passive FTP with TLS and NAT supposed to work?

2020-06-12 Thread Gibney, Dave
In my case, it was and is long stable FTPS jobs using standard files and no knowledgeable staff with time to refit to stfp. About a decade ago, I experimented with the idea of wrapping a PROC around the whole process. Ran out of available time to solve all issues. > -Original Message-

Re: How is Passive FTP with TLS and NAT supposed to work?

2020-06-12 Thread Charles Mills
I am gathering from reading the RFC that that 227 Entering Passive Mode (10,200,40,20,8,106) is a verbatim message from the server, and for the question "what *does* the server send?" the answer is "that 227 message." Is that correct? Charles -Original Message- From: IBM Mainframe

Re: How is Passive FTP with TLS and NAT supposed to work?

2020-06-12 Thread Charles Mills
Thanks all! Thanks much! Let me try to do one reply here to hold down the noise. > active mode is the one using PORT; passive mode uses PASV Thank you! It's a detail but I want to have the details right. Details are of the essence here. What *exactly* does the server send? On the client end I

Re: How is Passive FTP with TLS and NAT supposed to work?

2020-06-12 Thread Paul Gilmartin
On Fri, 12 Jun 2020 20:46:49 +, Jackson, Rob wrote: >Before I found out about Co:Z I used shell scripts and REXX in OMVS to copy >the files back and forth from MVS datasets to OMVS file systems (if sending to >the mainframe, they would follow up the copy with a SSH and execute a script

Re: How is Passive FTP with TLS and NAT supposed to work?

2020-06-12 Thread Jackson, Rob
Before I found out about Co:Z I used shell scripts and REXX in OMVS to copy the files back and forth from MVS datasets to OMVS file systems (if sending to the mainframe, they would follow up the copy with a SSH and execute a script with a table of DSNs with DCBs to copy to a MVS dataset . . .

Re: How is Passive FTP with TLS and NAT supposed to work?

2020-06-12 Thread Paul Gilmartin
On Fri, 12 Jun 2020 18:21:47 +, Gibney, Dave wrote: >Aside from, I think this is still true, absent Dovetail extensions, the >requirement that SFTP only works with ZFS/HFS files >> What's the intended recipient? If desktop or Open Systems, zFS/HFS should be acceptable. If z/OS,

Re: How is Passive FTP with TLS and NAT supposed to work?

2020-06-12 Thread Seymour J Metz
I've never understood why RFC 4960 Stream Control Transmission Protocol (SCTP) didn't catch on and get exploited by a new FTP protocol. -- Shmuel (Seymour J.) Metz http://mason.gmu.edu/~smetz3 From: IBM Mainframe Discussion List

Re: How is Passive FTP with TLS and NAT supposed to work?

2020-06-12 Thread Gibney, Dave
We live behind an f5 Load Balancer. It knows our certificates and can decrypt/recrypt to determine the PORT. We flat don't do active FTPS > -Original Message- > From: IBM Mainframe Discussion List On > Behalf Of Charles Mills > Sent: Friday, June 12, 2020 11:01 AM > To:

Re: How is Passive FTP with TLS and NAT supposed to work?

2020-06-12 Thread Gibney, Dave
Aside from, I think this is still true, absent Dovetail extensions, the requirement that SFTP only works with ZFS/HFS files > > There are other things, I'm sure I'm forgetting. Switch to SFTP, and life > gets > much easier--most of the time. > > First Horizon Bank > Mainframe Technical

Re: How is Passive FTP with TLS and NAT supposed to work?

2020-06-12 Thread Kirk Wolf
How about after throwing firewalls in to the mix? FTP's dual port architecture is simply a nightmare. Kirk Wolf Dovetailed Technologies http://dovetail.com On Fri, Jun 12, 2020 at 1:01 PM Charles Mills wrote: > X-Posted IBMMAIN and IBMTCP. Apologies. This is a question that is both > urgent

Re: How is Passive FTP with TLS and NAT supposed to work?

2020-06-12 Thread Jackson, Rob
Well, your point is made und understood, but active mode is the one using PORT; passive mode uses PASV. They both have their FW/load balancer issues. We tend to use a variety of "fixes" for the various issues, given our convoluted (typical?) environment. EPSV can help. Some clients have the