Discussions
Categories
Groups
Community Home
Categories
INTERNAL ENABLEMENT
POPULAR
PUBLIC CLOUD
PRIVATE CLOUD
Quick Links
MY LINKS
HELPFUL TIPS
Back to website
Home
Web CMS (TeamSite)
OD over the Internet
Ottawa_IWOV
Question for the group -
We have a situation where we may need to OD over the Internet. It would be a Solaris to Solaris deployment.
Can we use SSH to asccomplish this with Open Deploy? What are the port implications?
I know this is not a lot of information. Any insight into this based on experience would be highly valuable.
Regards,
Find more posts tagged with
Comments
jed
OD has built in encryption--why do you need to go through SSH? In theory, if that is what you are forced to do, it should work using port forwarding with the listener "bindPort", however, stunnel may be a better fit.
--
Jed Michnowicz
jedm@sun.com
Content Management Engineering
Sun Microsystems
Bill Klish
We deploy over the Internet to some third party hosting vendors using the built in SSL encryption. Would that work for you?
Ottawa_IWOV
Yeah, that is exactly the boat we are in. I know it's asking a lot, but might you be able to provide some examples?
Thanks,
jed
The SSL setup is pretty well documented in the OD manual. You generate the various certs, modify config files, and deploy the certs to the various base/target hosts. (Make sure the firewall on the target is opened up to access connections from the base server.)
Note: By default, the cert is good for one year. Make sure you set a reminder to regen the cert each year (or extend the cert lifetime).
--
Jed Michnowicz
jedm@sun.com
Content Management Engineering
Sun Microsystems
skip11
Hi,
I totally concur. Why ssh when OD encryption is used ? If you have to use ssh, set up a DMZ system on the
receiver end and push the files to it via rsync and an ssh tunnel with a dedicated user and tight file permissions.
The DMZ internet facing ip/port should be firewalled from allowing connections to your inside network. If you then need to
deploy inside from the DMZ, use OD with a firewall rule for uni-directional traffic. Based on your security requirements,
OD could pass the traffic from the DMZ to the inside either encrypted or not. If ssh is not required, encrypt OD - it's quite simple,
and if you use openssl with your own CA (IMO, do not use snakeoil), the certificates could be valid for more than a year. my $0.02.
regards,
R.Barger
Credit Suisse Group
Zurich, Switzerland