Amanda-Users

RE: Encrypted network traffic

2003-12-30 10:58:55
Subject: RE: Encrypted network traffic
From: Andrew Hall <halla3 AT corp.earthlink DOT net>
To: Gregor Ibic <gregor.ibic AT intelicom DOT si>
Date: Tue, 30 Dec 2003 10:55:54 -0500
Maybe getting a little OT, but you could use racoon, on *BSD at least,
and have a different key pair for each side of the data transfer, that
automatically re-keys at a specified time period.  So you would end up
having to compromise 3 key pairs total to get at your data (1 for IKE
phase 1, and 1 pair each for each side of the security association).

You could then use gpg to encrypt the data on tape. :)

Drew

On Tue, 2003-12-30 at 10:38, Gregor Ibic wrote:
> I would say, encrypt it on a lower layer like IPSEC.
>  
> regards,
> gregor
>  
> 
> 
> Intelicom d.o.o.
> Security software company
> http://www.intelicom.si
> email: info AT intelicom DOT si
> 
> 
>          


<Prev in Thread] Current Thread [Next in Thread>