Security Considerations in Insecure Networks
Version 1 (Hiroya Kubo, 2010-01-04 17:02)
| 1 | 1 | Hiroya Kubo | h1. Security Considerations in Insecure Networks |
|---|---|---|---|
| 2 | 1 | Hiroya Kubo | |
| 3 | 1 | Hiroya Kubo | h2. Warning! |
| 4 | 1 | Hiroya Kubo | |
| 5 | 1 | Hiroya Kubo | * You SHOULD use SQS applications in your LAN, inside your network wirewalls. |
| 6 | 1 | Hiroya Kubo | * You MUST NOT use SQS applications in insecure networks. |
| 7 | 1 | Hiroya Kubo | |
| 8 | 1 | Hiroya Kubo | h2. Network Services and Features |
| 9 | 1 | Hiroya Kubo | |
| 10 | 1 | Hiroya Kubo | An SQS application process create several IP sockets: |
| 11 | 1 | Hiroya Kubo | |
| 12 | 1 | Hiroya Kubo | * HTTP server socket |
| 13 | 1 | Hiroya Kubo | * RMI server socket |
| 14 | 1 | Hiroya Kubo | * Administratively Scoped IP Multicast socket |
| 15 | 1 | Hiroya Kubo | |
| 16 | 1 | Hiroya Kubo | (SQSには、LAN内で用いることを前提にしたHTTPサーバ機能, RMIサーバ機能, Administratively Scoped IP Multicastによる通信機能があります。) |
| 17 | 1 | Hiroya Kubo | |
| 18 | 1 | Hiroya Kubo | |
| 19 | 1 | Hiroya Kubo | h2. SQS applications in Disconnected Environment |
| 20 | 1 | Hiroya Kubo | |
| 21 | 1 | Hiroya Kubo | Once you have installed SQS applications, they do not require internet connection in runtime. |
| 22 | 1 | Hiroya Kubo | |
| 23 | 1 | Hiroya Kubo | (SQSは、いったんインストールをしてしまえば、運用中にインターネットに接続する必要はありません。) |
| 24 | 1 | Hiroya Kubo | |
| 25 | 1 | Hiroya Kubo | In case you consider security risk, you should launch SQS applications on hosts with private IP addresses only, inside firewall. Otherwise, you should disconnect your network cable and disable wifi interface before use. |
| 26 | 1 | Hiroya Kubo | |
| 27 | 1 | Hiroya Kubo | (セキュリティを気にされるのであれば、ファイヤウォールの内側で、プライベートアドレスのみを付与されたマシンで運用されるか、いっそのこと、ネットワークケーブルを抜く・無線LANをオフにしてから動かすべきです。) |
| 28 | 1 | Hiroya Kubo | |
| 29 | 1 | Hiroya Kubo | h2. TODO: Access Control |
| 30 | 1 | Hiroya Kubo | |
| 31 | 1 | Hiroya Kubo | Network address and user/group password authentication features are partially implemented(patches and contributions are welcome). |
