rejetto forum

ssl nearer? i need help

rejetto · 13 · 9643

0 Members and 1 Guest are viewing this topic.

Offline rejetto

  • Administrator
  • Tireless poster
  • *****
    • Posts: 13523
    • View Profile
hello, this topic is for delphi programmers. (hi mars)
finally, the socket library used by HFS has released the ssl support freely. i noticed it in the last hour. :)
http://www.overbyte.be/frame_index.html
i'm studying it. it seems that the code to be changed in hfs is not much, but we need to understand all the rest: certificates, and the like. because i don't think we'll go far without these.
so, if anyone wants to help understand what we need to do pratically to integrate ssl into hfs, it's welcome. step-by-step :D
lemme know.


Offline Mars

  • Operator
  • Tireless poster
  • *****
    • Posts: 2068
    • View Profile
j'en reviens à un de mes posts sur le sujet : comment créer un deuxième port d'écoute pour HFS, soit donc un deuxième canal capable de supporter un deuxième type de tpl nommé par exemple HFS.SSL.TPL, afin de gérer avec différence, un canal sécurisé et non sécurisé. et pourquoi pas un protocole de communication entre deux serveurs hfs pour synchroniser des répertoires par exemple.


Offline FRENCH CAN CAN

  • Tireless poster
  • ****
    • Posts: 681
    • View Profile
Si può rispondere in lingua Italiana in questo topic? ho visto che mars ha risposto in francese.  ???


Offline Mars

  • Operator
  • Tireless poster
  • *****
    • Posts: 2068
    • View Profile
parqué le messago s'adresso onlito to rejetto

I shall also have been able to write my message in delphi code ;D



Offline rejetto

  • Administrator
  • Tireless poster
  • *****
    • Posts: 13523
    • View Profile
haha :D

ok, i didn't study it enough to say, but i see it will probably need 2 listening sockets instead of one. But this is just guessing, let me know if you find more.

about different templates, i don't think it's worthing having a system based on the socket. I imagine one day we'll have something like an event [choose tpl] and you'll return with macros the name of the template to be used. So you'll choose based on port, or user, or time of day. Any thing.


Offline MarkV

  • Tireless poster
  • ****
    • Posts: 764
    • View Profile
Normal HTTP listens on port 80, and HTTPS on port 443 afaik.
http://worldipv6launch.org - The world is different now.



Offline r][m

  • Tireless poster
  • ****
    • Posts: 347
    • View Profile

Offline Mars

  • Operator
  • Tireless poster
  • *****
    • Posts: 2068
    • View Profile
No more current event, at the moment stunnel is enough for this spot and I believe that the other priorities are in progress, but be reassured it is in the TO DO LIST of  rejetto.
It is as for a ship blocked alongside the quayby the storm, we wait for an calm for pursuit the road towards the destination SSL ;)


Offline rejetto

  • Administrator
  • Tireless poster
  • *****
    • Posts: 13523
    • View Profile
stunnel has the big limit of hiding IP addresses, making every IP based feature not working.


Offline maverick

  • Tireless poster
  • ****
    • Posts: 1052
  • Computer Solutions
    • View Profile
stunnel has the big limit of hiding IP addresses, making every IP based feature not working.

I don't understand.  Please explain.
maverick


Offline Mars

  • Operator
  • Tireless poster
  • *****
    • Posts: 2068
    • View Profile
When you use hfs directly in contact with the internet you can use the ban because hfs can identify the distant user by his IP, but by way of stunnel, this one passes on in hfs only the address ip 127.0.0.1, that's right which rejetto wants to say >:(

However by using a particular option of stunnel, it is possible to define the address of the network connection of the card to mark the difference

[https]
;accept = [address:]port  of stunnel
accept  = 0.0.0.0:443
;connect = [address:]port of HFS
connect = 127.0.0.1:80       
;local =Ip of your computer on the network viewed by the hfs server
local = 192.168.1.xxx
TIMEOUTclose = 0
« Last Edit: November 20, 2008, 06:49:59 PM by mars »


Offline maverick

  • Tireless poster
  • ****
    • Posts: 1052
  • Computer Solutions
    • View Profile
When you use hfs directly in contact with the internet you can use the ban because hfs can identify the distant user by his IP, but by way of stunnel, this one passes on in hfs only the address ip 127.0.0.1, that's right which rejetto wants to say >:(

ok.  He's referring to the HFS gui.  Yes that's right. 
maverick