Security Considerations in Insecure Networks

Version 1 (Hiroya Kubo, 2010-01-04 17:02)

1 1 Hiroya Kubo
h1. Security Considerations in Insecure Networks
2 1 Hiroya Kubo
3 1 Hiroya Kubo
h2. Warning! 
4 1 Hiroya Kubo
5 1 Hiroya Kubo
* You SHOULD use SQS applications in your LAN, inside your network wirewalls.
6 1 Hiroya Kubo
* You MUST NOT use SQS applications in insecure networks. 
7 1 Hiroya Kubo
8 1 Hiroya Kubo
h2. Network Services and Features
9 1 Hiroya Kubo
10 1 Hiroya Kubo
An SQS application process create several IP sockets:
11 1 Hiroya Kubo
12 1 Hiroya Kubo
* HTTP server socket
13 1 Hiroya Kubo
* RMI server socket
14 1 Hiroya Kubo
* Administratively Scoped IP Multicast socket
15 1 Hiroya Kubo
16 1 Hiroya Kubo
(SQSには、LAN内で用いることを前提にしたHTTPサーバ機能, RMIサーバ機能, Administratively Scoped IP Multicastによる通信機能があります。)
17 1 Hiroya Kubo
18 1 Hiroya Kubo
19 1 Hiroya Kubo
h2. SQS applications in Disconnected Environment
20 1 Hiroya Kubo
21 1 Hiroya Kubo
Once you have installed SQS applications,  they do not require internet connection in runtime.
22 1 Hiroya Kubo
23 1 Hiroya Kubo
(SQSは、いったんインストールをしてしまえば、運用中にインターネットに接続する必要はありません。)
24 1 Hiroya Kubo
25 1 Hiroya Kubo
In case you consider security risk, you should launch SQS applications on hosts with private IP addresses only, inside firewall. Otherwise, you should disconnect your network cable and disable wifi interface before use.
26 1 Hiroya Kubo
27 1 Hiroya Kubo
(セキュリティを気にされるのであれば、ファイヤウォールの内側で、プライベートアドレスのみを付与されたマシンで運用されるか、いっそのこと、ネットワークケーブルを抜く・無線LANをオフにしてから動かすべきです。)
28 1 Hiroya Kubo
29 1 Hiroya Kubo
h2. TODO: Access Control
30 1 Hiroya Kubo
31 1 Hiroya Kubo
Network address and user/group password authentication features are partially implemented(patches and contributions are welcome).