With c$socket and 'ags-create-server' I have now created a simple server for receiving web server messages. However, they expected from us to work with ssl. c$socket was a simple way that made a web server unnecessary on our side. Does anyone have experience with a simple similar ssl server solution, without running a 'real' web server.
With c$socket and 'ags-create-server' I have now created a simple server for receiving web server messages. However, they expected from us to work with ssl. c$socket was a simple way that made a web server unnecessary on our side. Does anyone have experience with a simple similar ssl server solution, without running a 'real' web server.
There are TLS servers that are a lot of work and require specialized knowledge; TLS servers that are broken; and TLS servers that someone else administers for you.
A properly-implemented and -administered HTTPS server will have a certificate (or certificates, if it supports both RSA and ECDSA suites) issued by an organizational or public CA, signed using an intermediate certificate, with a reasonably short expiration period. The CA will follow the CABF Baseline Requirements, so there are CRLs and OCSP and probably transparency logs to worry about. The server may have to implement OCSP stapling for performance reasons. The server's administrator will practice good private-key hygiene to prevent the key from being stolen. The server may enforce HTTP Strict Transport Security. The administrator will curate the set of supported TLS versions and cipher suites to include only those necessary for compatibility with authorized clients, and ensure that the available suites meet the organization's requirements for security. Someone will have to monitor updates to the server software, particularly the TLS implementation, so that security vulnerabilities are patched quickly.
Any "simple" TLS-enabled server will fail to do many of these things, and consequently be only marginally more secure than communicating in plaintext.
And so most applications take one of the other two choices.
With c$socket and 'ags-create-server' I have now created a simple server for receiving web server messages. However, they expected from us to work with ssl. c$socket was a simple way that made a web server unnecessary on our side. Does anyone have experience with a simple similar ssl server solution, without running a 'real' web server.
With c$socket and 'ags-create-server' I have now created a simple server for receiving web server messages. However, they expected from us to work with ssl. c$socket was a simple way that made a web server unnecessary on our side. Does anyone have experience with a simple similar ssl server solution, without running a 'real' web server.
I'm guessing this is more than an in-house service behind a firewall or you wouldn't be considering using TLS at all.
Sign up
Already have an account? Login
Welcome to the Rocket Forum!
Please log in or register:
Employee Login | Registration Member Login | RegistrationEnter your E-mail address. We'll send you an e-mail with instructions to reset your password.