Re: Securely getting a password from a custom app into Oracle

From: Brian Hatch (secprogat_private)
Date: Mon Aug 05 2002 - 15:51:32 PDT

  • Next message: Nicholas Janzen: "Re: Securely getting a password from a custom app into Oracle"

    > I use stunnel (http://www.stunnel.org/) to set up SSL links between
    > workstations and Postgres database servers, I dont see why this would
    > not work with Oracle.
    > 
    > 
    >  /usr/local/sbin/stunnel -p /usr/local/ssl/certs/stunnel.pem -c
    >     -I <MYIPADDR> -d localhost:postgres -r mydbserver:spostgres
    
    I've heard both success and failure with Oracle.  See 
    
    Linkname: (failing to) use Stunnel with Oracle
         URL: http://www.stunnel.org/examples/oracle.html
    
    
    If anyone can support or refute those results, lemme know and I'll
    add it to the page.  Indications are that Oracle uses out of band
    data, which doesn't play nicely with Stunnel.  (Stunnel can drop
    it or put it inline, and Oracle may not like that.)
    
    I don't have an Oracle database to test on.  If anyone has one
    to spare, for god's sake don't send it to me.  ;-)
    
    
    --
    Brian Hatch                  A good bug is
       Systems and                hard to find.
       Security Engineer
    www.buildinglinuxvpns.net
    
    Every message PGP signed
    
    
    



    This archive was generated by hypermail 2b30 : Mon Aug 05 2002 - 16:29:24 PDT