nv-l

Re: Communications used by Web Client

2001-04-11 14:13:15
Subject: Re: Communications used by Web Client
From: "Les Dickert" <lesdickert AT hotmail DOT com>
To: nv-l AT lists.tivoli DOT com
Date: Wed, 11 Apr 2001 14:13:15
Just did a quick Sniffer test from my laptop
with the Web Client and our NetView server
(6.0.1 under AIX 4.3.3).  Revealed:

1.  The login and password is encrypted
    (BASIC) from the Web Client to the
    NetView server.

2.  NetView server to Web Client output
    is in clear text, at least the things
    that are text, like events.


Les Dickert
Verisign Consulting








>From: "Bill Evans" <wvevans AT prodigy DOT net>
>Reply-To: IBM NetView Discussion <nv-l AT tkg DOT com>
>To: "NV-L ListServ" <nv-l AT tkg DOT com>
>Subject: Re: [NV-L] Communications used by Web Client
>Date: Wed, 11 Apr 2001 09:49:25 -0400
>
>Who cares if the Web Client is secure?  Good question, I should have 
>explained.
>
>You can probably figure out its a bureaucrat in a Government Agency.  "ALL 
>communications must be secure.  Is the Web Client's communications secure?" 
>  Doesn't matter that the sensitive data the agency processes will NEVER be 
>visible from the Web Client.  If it's not secure we have to seek the agency 
>equivalent of a "zoning variance".
>
>Bill

_________________________________________________________________


<Prev in Thread] Current Thread [Next in Thread>