From bounce-fwtk-users-303@listserv.nai.com Mon Jun  3 10:27 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id KAA23271
	Mon, 3 Jun 2002 10:27:34 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id KAA00240; Mon, 3 Jun 2002 10:40:04 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma000213; Mon, 3 Jun 02 10:39:35 -0400
Message-ID: <LISTMANAGER-303-647-2002.06.03-09.29.56--fwtk-archive#lists.tislabs.com@listserv.nai.com>
From: Michel.Marcon@equipement.gouv.fr
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] How to get all patches ??
Date: Mon, 3 Jun 2002 16:39:06 +0200 
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2653.19)
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 500
Status: RO

Hi.

1-Well all the patches and contribs are on the Web, but is there any way to
download *all* of them. I men to get a usable c source, not like the HTML
web page ??

2-How to submit a patch so everyone could use it ??

mm
--------------------------
Michel Marcon
SysAdmin Unix & Windows NT
Ministere Equipement, CETU
Tel (33) 04 7214-3408

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Tue Jun 11 15:31 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id PAA08122
	Tue, 11 Jun 2002 15:31:03 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id PAA18150; Tue, 11 Jun 2002 15:43:46 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma018088; Tue, 11 Jun 02 15:43:23 -0400
Message-ID: <LISTMANAGER-303-694-2002.06.11-14.33.38--fwtk-archive#lists.tislabs.com@listserv.nai.com>
From: "Don" <don@lclcan.com>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Using my site for secure transactions
Date: Tue, 11 Jun 2002 15:44:20 -0400
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.50.4807.1700
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4807.1700
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 1120
Status: RO

Hi,

I'v got the fwtk 2.1 withatches installed.  I've installed a test certificate so that I can access my site via https://.

How do I open 443 on the firewall and set 443 on the firewall to SSL port?

My current config. is:

inetd.conf
=======
ssl             stream  tcp     nowait  root    /usr/local/etc/netacl ssl

services
=====
https           443/tcp                         # MCom
https           443/udp                        # MCom
ssl             443/tcp

netperm-table
=========
# outbound ssl                                        
netacl-ssl: permit-hosts * -exec /usr/local/etc/ssl-gw

# secure http                                           
ssl-gw:         denial-msg /usr/local/etc/http-deny.html
ssl-gw:         timeout 36000                           
ssl-gw:         permit-hosts 205.205.137.*              
ssl-gw:         permit-hosts *                          
ssl-gw:         deny-hosts *                            

Thanks,
Don


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Fri Jun 14 15:20 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id PAA17188
	Fri, 14 Jun 2002 15:20:19 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id PAA20508; Fri, 14 Jun 2002 15:33:06 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma020503; Fri, 14 Jun 02 15:32:20 -0400
Message-ID: <LISTMANAGER-303-721-2002.06.14-14.22.02--fwtk-archive#lists.tislabs.com@listserv.nai.com>
From: "Don" <don@lclcan.com>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] This list
Date: Fri, 14 Jun 2002 15:32:56 -0400
MIME-Version: 1.0
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.50.4807.1700
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4807.1700
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: multipart/alternative;
	boundary="----=_NextPart_000_024D_01C213B8.C17E8640"
Content-Length: 1067
Status: RO

This is a multi-part message in MIME format.

------=_NextPart_000_024D_01C213B8.C17E8640
Content-Type: text/plain;
	charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable

Is it still active?

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

------=_NextPart_000_024D_01C213B8.C17E8640
Content-Type: text/html;
	charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=3DContent-Type content=3D"text/html; =
charset=3Dwindows-1252">
<META content=3D"MSHTML 5.50.4916.2300" name=3DGENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=3D#ffffff>
<DIV><FONT face=3DArial size=3D2>Is it still =
active?</FONT></DIV>
---<BR>
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com<BR>
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com
</BODY></HTML>


------=_NextPart_000_024D_01C213B8.C17E8640--




From bounce-fwtk-users-303@listserv.nai.com Fri Jun 14 15:33 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id PAA17241
	Fri, 14 Jun 2002 15:33:25 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id PAA20924; Fri, 14 Jun 2002 15:46:12 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma020907; Fri, 14 Jun 02 15:45:24 -0400
X-Authentication-Warning: guardian.hartwellcorp.com: mail set sender to <mikes@hartwellcorp.com> using -f
Message-ID: <LISTMANAGER-303-722-2002.06.14-14.35.08--fwtk-archive#lists.tislabs.com@listserv.nai.com>
From: "Michael St. Laurent" <mikes@hartwellcorp.com>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] RE: This list
Date: Fri, 14 Jun 2002 12:46:55 -0700
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: multipart/alternative;
	boundary="----_=_NextPart_001_01C213DC.3CB2BDB8"
Content-Length: 2585
Status: RO

This message is in MIME format. Since your mail reader does not understand
this format, some or all of this message may not be legible.

------_=_NextPart_001_01C213DC.3CB2BDB8
Content-Type: text/plain

Well, traffic has fallen off dramatically over the last year or so (I wonder
why that is).  There are occasional bursts of activity however.  Do you have
a question or problem?
 
 

--
Michael St. Laurent
Hartwell Corporation 

-----Original Message-----
From: Don [mailto:don@lclcan.com] 
Sent: Friday, June 14, 2002 12:33 PM
To: fwtk-users
Subject: [fwtk-users] This list


Is it still active?
---
You are currently subscribed to fwtk-users as: mikes@hartwellcorp.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com 



---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

------_=_NextPart_001_01C213DC.3CB2BDB8
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=us-ascii">
<TITLE>Message</TITLE>

<META content="MSHTML 6.00.2716.2200" name=GENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=#ffffff>
<DIV><SPAN class=416454419-14062002><FONT face=Arial color=#0000ff size=2>Well, 
traffic has fallen off dramatically over the last year or so (I wonder why that 
is).&nbsp; There are occasional bursts of activity however.&nbsp; Do you have a 
question or problem?</FONT></SPAN></DIV>
<DIV>&nbsp;</DIV>
<DIV>&nbsp;</DIV><!-- Converted from text/plain format -->
<P><FONT size=2>--<BR>Michael St. Laurent<BR>Hartwell Corporation</FONT> </P>
<BLOCKQUOTE 
style="PADDING-LEFT: 5px; MARGIN-LEFT: 5px; BORDER-LEFT: #0000ff 2px solid; MARGIN-RIGHT: 0px">
  <DIV></DIV>
  <DIV class=OutlookMessageHeader lang=en-us dir=ltr align=left><FONT 
  face=Tahoma size=2>-----Original Message-----<BR><B>From:</B> Don 
  [mailto:don@lclcan.com] <BR><B>Sent:</B> Friday, June 14, 2002 12:33 
  PM<BR><B>To:</B> fwtk-users<BR><B>Subject:</B> [fwtk-users] This 
  list<BR><BR></FONT></DIV>
  <DIV><FONT face=Arial size=2>Is it still active?</FONT></DIV>---<BR>You are 
  currently subscribed to fwtk-users as: mikes@hartwellcorp.com<BR>To 
  unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com 
</BLOCKQUOTE>
---<BR>
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com<BR>
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com
</BODY></HTML>


------_=_NextPart_001_01C213DC.3CB2BDB8--


From bounce-fwtk-users-303@listserv.nai.com Fri Jun 14 15:57 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id PAA17282
	Fri, 14 Jun 2002 15:57:28 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id QAA21307; Fri, 14 Jun 2002 16:10:15 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma021294; Fri, 14 Jun 02 16:09:40 -0400
Message-ID: <LISTMANAGER-303-723-2002.06.14-14.59.37--fwtk-archive#lists.tislabs.com@listserv.nai.com>
From: "Don" <don@lclcan.com>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] problem with ssl and fwtk
Date: Fri, 14 Jun 2002 16:10:31 -0400
MIME-Version: 1.0
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.50.4807.1700
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4807.1700
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: multipart/alternative;
	boundary="----=_NextPart_000_02CD_01C213BE.02052200"
Content-Length: 4031
Status: RO

This is a multi-part message in MIME format.

------=_NextPart_000_02CD_01C213BE.02052200
Content-Type: text/plain;
	charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable

Well, I've d/l and installed a test certificate from Thawte. I had =
already set up apache to work with ssl by installing OpenSSL and ModSSL. =
 When I try to connect to my site via https://, I get the I.E. "The page =
cannot be displayed" message.

Looking at my logs show no apparent error.  All I see are the following =
lines (xxx =3D IP):

permit host=3Dme.lclcan.com/xxx.xxx.xxx.xxx service=3Dssl =
execute=3D/usr/local/etc/ssl-gw
permit host=3Dlclcan.com/216.94.98.2 service=3Dssl  =
execute=3D/usr/local/etc/ssl-gw

The engineer at Thawte is convinced it's my firewall causing the =
problem.  I'm stumped. Anyone have an idea?

Don

=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D

Well, traffic has fallen off dramatically over the last year or so (I =
wonder
why that is).  There are occasional bursts of activity however.  Do you =
have
a question or problem?
=20
=20

--
Michael St. Laurent
Hartwell Corporation=20

-----Original Message-----
From: Don [mailto:don@lclcan.com]=20
Sent: Friday, June 14, 2002 12:33 PM
To: fwtk-users
Subject: [fwtk-users] This list


Is it still active?


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

------=_NextPart_000_02CD_01C213BE.02052200
Content-Type: text/html;
	charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=3DContent-Type content=3D"text/html; =
charset=3Dwindows-1252">
<META content=3D"MSHTML 5.50.4916.2300" name=3DGENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=3D#ffffff>
<DIV><FONT face=3DArial size=3D2>Well, I've d/l and installed a test =
certificate=20
from Thawte. I had already set up apache to work with ssl by installing =
OpenSSL=20
and ModSSL.&nbsp; When I try to connect to my site via https://, I get =
the I.E.=20
"The page cannot be displayed" message.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2>Looking at my logs show no apparent =
error.&nbsp;=20
All I see are the following lines (xxx =3D IP):</FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2>permit =
host=3Dme.lclcan.com/xxx.xxx.xxx.xxx=20
service=3Dssl execute=3D/usr/local/etc/ssl-gw</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>permit host=3Dlclcan.com/216.94.98.2 =
service=3Dssl =20
execute=3D/usr/local/etc/ssl-gw</FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2>The engineer at Thawte is convinced =
it's my=20
firewall causing the problem.&nbsp; I'm stumped. Anyone have an=20
idea?</FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2>Don</FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial =
size=3D2>=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D</FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV>Well, traffic has fallen off dramatically over the last year or so =
(I=20
wonder<BR>why that is).&nbsp; There are occasional bursts of activity=20
however.&nbsp; Do you have<BR>a question or problem?<BR> <BR>=20
<BR><BR>--<BR>Michael St. Laurent<BR>Hartwell Corporation =
<BR><BR>-----Original=20
Message-----<BR>From: Don [mailto:don@lclcan.com] <BR>Sent: Friday, June =
14,=20
2002 12:33 PM<BR>To: fwtk-users<BR>Subject: [fwtk-users] This =
list<BR><BR><BR>Is=20
it still active?<BR></DIV>
---<BR>
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com<BR>
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com
</BODY></HTML>


------=_NextPart_000_02CD_01C213BE.02052200--




From bounce-fwtk-users-303@listserv.nai.com Fri Jun 14 16:00 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA17289
	Fri, 14 Jun 2002 16:00:26 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id QAA21369; Fri, 14 Jun 2002 16:13:14 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma021358; Fri, 14 Jun 02 16:12:45 -0400
Message-ID: <LISTMANAGER-303-724-2002.06.14-15.02.43--fwtk-archive#lists.tislabs.com@listserv.nai.com>
From: "Don" <don@lclcan.com>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] not getting any e-mail
Date: Fri, 14 Jun 2002 16:13:46 -0400
MIME-Version: 1.0
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.50.4807.1700
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4807.1700
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: multipart/alternative;
	boundary="----=_NextPart_000_02DC_01C213BE.75F994C0"
Content-Length: 1351
Status: RO

This is a multi-part message in MIME format.

------=_NextPart_000_02DC_01C213BE.75F994C0
Content-Type: text/plain;
	charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable

Strange,  I can post to the list but I never get any e-mail from the =
list including my posts.  A check of the web archive shows my posts as =
appearing.

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

------=_NextPart_000_02DC_01C213BE.75F994C0
Content-Type: text/html;
	charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=3DContent-Type content=3D"text/html; =
charset=3Dwindows-1252">
<META content=3D"MSHTML 5.50.4916.2300" name=3DGENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=3D#ffffff>
<DIV><FONT face=3DArial size=3D2>Strange,&nbsp; I can post to the list =
but I never=20
get any e-mail from the list including my posts.&nbsp; A check of the =
web=20
archive shows my posts as appearing.</FONT></DIV>
---<BR>
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com<BR>
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com
</BODY></HTML>


------=_NextPart_000_02DC_01C213BE.75F994C0--




From bounce-fwtk-users-303@listserv.nai.com Fri Jun 14 16:04 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA17296
	Fri, 14 Jun 2002 16:04:28 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id QAA21467; Fri, 14 Jun 2002 16:17:16 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma021454; Fri, 14 Jun 02 16:16:24 -0400
X-Authentication-Warning: guardian.hartwellcorp.com: mail set sender to <mikes@hartwellcorp.com> using -f
Message-ID: <LISTMANAGER-303-725-2002.06.14-15.04.09--fwtk-archive#lists.tislabs.com@listserv.nai.com>
From: "Michael St. Laurent" <mikes@hartwellcorp.com>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] RE: problem with ssl and fwtk
Date: Fri, 14 Jun 2002 13:15:38 -0700
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: multipart/alternative;
	boundary="----_=_NextPart_001_01C213E0.40306C34"
Content-Length: 5274
Status: RO

This message is in MIME format. Since your mail reader does not understand
this format, some or all of this message may not be legible.

------_=_NextPart_001_01C213E0.40306C34
Content-Type: text/plain

Hmmm, I connect to SSL sites all the time through our firewall.  You are
using FWTK version 2.1?  What patches have you applied if any?
 
 

--
Michael St. Laurent
Hartwell Corporation 

-----Original Message-----
From: Don [mailto:don@lclcan.com] 
Sent: Friday, June 14, 2002 1:11 PM
To: fwtk-users
Subject: [fwtk-users] problem with ssl and fwtk


Well, I've d/l and installed a test certificate from Thawte. I had already
set up apache to work with ssl by installing OpenSSL and ModSSL.  When I try
to connect to my site via https://, I get the I.E. "The page cannot be
displayed" message.
 
Looking at my logs show no apparent error.  All I see are the following
lines (xxx = IP):
 
permit host=me.lclcan.com/xxx.xxx.xxx.xxx service=ssl
execute=/usr/local/etc/ssl-gw
permit host=lclcan.com/216.94.98.2 service=ssl execute=/usr/local/etc/ssl-gw
 
The engineer at Thawte is convinced it's my firewall causing the problem.
I'm stumped. Anyone have an idea?
 
Don
 
==============================
 
Well, traffic has fallen off dramatically over the last year or so (I wonder
why that is).  There are occasional bursts of activity however.  Do you have
a question or problem?



--
Michael St. Laurent
Hartwell Corporation 

-----Original Message-----
From: Don [mailto:don@lclcan.com] 
Sent: Friday, June 14, 2002 12:33 PM
To: fwtk-users
Subject: [fwtk-users] This list


Is it still active?

---
You are currently subscribed to fwtk-users as: mikes@hartwellcorp.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com 



---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

------_=_NextPart_001_01C213E0.40306C34
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=us-ascii">
<TITLE>Message</TITLE>

<META content="MSHTML 6.00.2716.2200" name=GENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=#ffffff>
<DIV><SPAN class=318111320-14062002><FONT face=Arial color=#0000ff size=2>Hmmm, 
I connect to SSL sites all the time through our firewall.&nbsp; You are using 
FWTK version 2.1?&nbsp; What patches have you applied if 
any?</FONT></SPAN></DIV>
<DIV>&nbsp;</DIV>
<DIV>&nbsp;</DIV><!-- Converted from text/plain format -->
<P><FONT size=2>--<BR>Michael St. Laurent<BR>Hartwell Corporation</FONT> </P>
<BLOCKQUOTE 
style="PADDING-LEFT: 5px; MARGIN-LEFT: 5px; BORDER-LEFT: #0000ff 2px solid; MARGIN-RIGHT: 0px">
  <DIV></DIV>
  <DIV class=OutlookMessageHeader lang=en-us dir=ltr align=left><FONT 
  face=Tahoma size=2>-----Original Message-----<BR><B>From:</B> Don 
  [mailto:don@lclcan.com] <BR><B>Sent:</B> Friday, June 14, 2002 1:11 
  PM<BR><B>To:</B> fwtk-users<BR><B>Subject:</B> [fwtk-users] problem with ssl 
  and fwtk<BR><BR></FONT></DIV>
  <DIV><FONT face=Arial size=2>Well, I've d/l and installed a test certificate 
  from Thawte. I had already set up apache to work with ssl by installing 
  OpenSSL and ModSSL.&nbsp; When I try to connect to my site via https://, I get 
  the I.E. "The page cannot be displayed" message.</FONT></DIV>
  <DIV><FONT face=Arial size=2></FONT>&nbsp;</DIV>
  <DIV><FONT face=Arial size=2>Looking at my logs show no apparent error.&nbsp; 
  All I see are the following lines (xxx = IP):</FONT></DIV>
  <DIV><FONT face=Arial size=2></FONT>&nbsp;</DIV>
  <DIV><FONT face=Arial size=2>permit host=me.lclcan.com/xxx.xxx.xxx.xxx 
  service=ssl execute=/usr/local/etc/ssl-gw</FONT></DIV>
  <DIV><FONT face=Arial size=2>permit host=lclcan.com/216.94.98.2 service=ssl 
  execute=/usr/local/etc/ssl-gw</FONT></DIV>
  <DIV><FONT face=Arial size=2></FONT>&nbsp;</DIV>
  <DIV><FONT face=Arial size=2>The engineer at Thawte is convinced it's my 
  firewall causing the problem.&nbsp; I'm stumped. Anyone have an 
  idea?</FONT></DIV>
  <DIV><FONT face=Arial size=2></FONT>&nbsp;</DIV>
  <DIV><FONT face=Arial size=2>Don</FONT></DIV>
  <DIV><FONT face=Arial size=2></FONT>&nbsp;</DIV>
  <DIV><FONT face=Arial size=2>==============================</FONT></DIV>
  <DIV><FONT face=Arial size=2></FONT>&nbsp;</DIV>
  <DIV>Well, traffic has fallen off dramatically over the last year or so (I 
  wonder<BR>why that is).&nbsp; There are occasional bursts of activity 
  however.&nbsp; Do you have<BR>a question or 
  problem?<BR><BR><BR><BR>--<BR>Michael St. Laurent<BR>Hartwell Corporation 
  <BR><BR>-----Original Message-----<BR>From: Don [mailto:don@lclcan.com] 
  <BR>Sent: Friday, June 14, 2002 12:33 PM<BR>To: fwtk-users<BR>Subject: 
  [fwtk-users] This list<BR><BR><BR>Is it still active?<BR></DIV>---<BR>You are 
  currently subscribed to fwtk-users as: mikes@hartwellcorp.com<BR>To 
  unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com 
</BLOCKQUOTE>
---<BR>
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com<BR>
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com
</BODY></HTML>


------_=_NextPart_001_01C213E0.40306C34--


From bounce-fwtk-users-303@listserv.nai.com Fri Jun 14 16:08 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA17300
	Fri, 14 Jun 2002 16:08:28 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id QAA21547; Fri, 14 Jun 2002 16:21:16 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma021540; Fri, 14 Jun 02 16:20:31 -0400
Message-ID: <LISTMANAGER-303-726-2002.06.14-15.06.27--fwtk-archive#lists.tislabs.com@listserv.nai.com>
Date: Fri, 14 Jun 2002 16:14:04 -0400
From: Keith Young <kyoung@v-one.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Organization: V-ONE
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.0.0) Gecko/20020530
X-Accept-Language: en-us, en
MIME-Version: 1.0
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Re: problem with ssl and fwtk
Content-Transfer-Encoding: 7bit
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Content-Type: text/plain; charset=windows-1252; format=flowed
Content-Length: 1018
Status: RO

Don wrote:
> Well, I've d/l and installed a test certificate from Thawte. I had 
> already set up apache to work with ssl by installing OpenSSL and 
> ModSSL.  When I try to connect to my site via https://, I get the I.E. 
> "The page cannot be displayed" message.
>  
> Looking at my logs show no apparent error.  All I see are the following 
> lines (xxx = IP):
>  
> permit host=me.lclcan.com/xxx.xxx.xxx.xxx service=ssl 
> execute=/usr/local/etc/ssl-gw
> permit host=lclcan.com/216.94.98.2 service=ssl execute=/usr/local/etc/ssl-gw
>  
> The engineer at Thawte is convinced it's my firewall causing the 
> problem.  I'm stumped. Anyone have an idea?
>  

Don,

Are you using the FWTK? Unless someone renamed the plug-gw proxy, or you 
are running Gauntlet, I don't know where you got the "ssl-gw" proxy from...

-- 

-- 
--Keith Young
-kyoung@v-one.com



---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Fri Jun 14 16:09 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA17304
	Fri, 14 Jun 2002 16:09:28 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id QAB21562; Fri, 14 Jun 2002 16:22:16 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma021551; Fri, 14 Jun 02 16:21:34 -0400
X-Authentication-Warning: guardian.hartwellcorp.com: mail set sender to <mikes@hartwellcorp.com> using -f
Message-ID: <LISTMANAGER-303-727-2002.06.14-15.08.51--fwtk-archive#lists.tislabs.com@listserv.nai.com>
From: "Michael St. Laurent" <mikes@hartwellcorp.com>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Cc: "'don@lclcan.com'" <don@lclcan.com>
Subject: [fwtk-users] RE: not getting any e-mail
Date: Fri, 14 Jun 2002 13:19:57 -0700
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2650.21)
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: multipart/alternative;
	boundary="----_=_NextPart_001_01C213E0.DA93120E"
Content-Length: 2781
Status: RO

This message is in MIME format. Since your mail reader does not understand
this format, some or all of this message may not be legible.

------_=_NextPart_001_01C213E0.DA93120E
Content-Type: text/plain

Wait for a little bit and see if you get two copies of this or just one.  I
sent it to both your address and the list address.
 
 

--
Michael St. Laurent
Hartwell Corporation 

-----Original Message-----
From: Don [mailto:don@lclcan.com] 
Sent: Friday, June 14, 2002 1:14 PM
To: fwtk-users
Subject: [fwtk-users] not getting any e-mail


Strange,  I can post to the list but I never get any e-mail from the list
including my posts.  A check of the web archive shows my posts as appearing.
---
You are currently subscribed to fwtk-users as: mikes@hartwellcorp.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com 



---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

------_=_NextPart_001_01C213E0.DA93120E
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=us-ascii">
<TITLE>Message</TITLE>

<META content="MSHTML 6.00.2716.2200" name=GENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=#ffffff>
<DIV><SPAN class=673451720-14062002><FONT face=Arial color=#0000ff size=2>Wait 
for a little bit and see if you get two copies of this or just one.&nbsp; I sent 
it to both your address and the list address.</FONT></SPAN></DIV>
<DIV>&nbsp;</DIV>
<DIV>&nbsp;</DIV><!-- Converted from text/plain format -->
<P><FONT size=2>--<BR>Michael St. Laurent<BR>Hartwell Corporation</FONT> </P>
<BLOCKQUOTE 
style="PADDING-LEFT: 5px; MARGIN-LEFT: 5px; BORDER-LEFT: #0000ff 2px solid; MARGIN-RIGHT: 0px">
  <DIV></DIV>
  <DIV class=OutlookMessageHeader lang=en-us dir=ltr align=left><FONT 
  face=Tahoma size=2>-----Original Message-----<BR><B>From:</B> Don 
  [mailto:don@lclcan.com] <BR><B>Sent:</B> Friday, June 14, 2002 1:14 
  PM<BR><B>To:</B> fwtk-users<BR><B>Subject:</B> [fwtk-users] not getting any 
  e-mail<BR><BR></FONT></DIV>
  <DIV><FONT face=Arial size=2>Strange,&nbsp; I can post to the list but I never 
  get any e-mail from the list including my posts.&nbsp; A check of the web 
  archive shows my posts as appearing.</FONT></DIV>---<BR>You are currently 
  subscribed to fwtk-users as: mikes@hartwellcorp.com<BR>To unsubscribe send a 
  blank email to leave-fwtk-users-303A@listserv.nai.com 
</BLOCKQUOTE>
---<BR>
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com<BR>
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com
</BODY></HTML>


------_=_NextPart_001_01C213E0.DA93120E--


From bounce-fwtk-users-303@listserv.nai.com Fri Jun 14 16:19 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA17354
	Fri, 14 Jun 2002 16:19:30 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id QAA21824; Fri, 14 Jun 2002 16:32:18 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma021811; Fri, 14 Jun 02 16:31:54 -0400
Message-ID: <LISTMANAGER-303-728-2002.06.14-15.20.07--fwtk-archive#lists.tislabs.com@listserv.nai.com>
From: "Don" <don@lclcan.com>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Test
Date: Fri, 14 Jun 2002 16:31:03 -0400
MIME-Version: 1.0
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.50.4807.1700
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4807.1700
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: multipart/alternative;
	boundary="----=_NextPart_000_031E_01C213C0.DFE87FC0"
Content-Length: 1057
Status: RO

This is a multi-part message in MIME format.

------=_NextPart_000_031E_01C213C0.DFE87FC0
Content-Type: text/plain;
	charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable

Please ignore.

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

------=_NextPart_000_031E_01C213C0.DFE87FC0
Content-Type: text/html;
	charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=3DContent-Type content=3D"text/html; =
charset=3Dwindows-1252">
<META content=3D"MSHTML 5.50.4916.2300" name=3DGENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=3D#ffffff>
<DIV><FONT face=3DArial size=3D2>Please =
ignore.</FONT></DIV>
---<BR>
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com<BR>
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com
</BODY></HTML>


------=_NextPart_000_031E_01C213C0.DFE87FC0--




From bounce-fwtk-users-303@listserv.nai.com Fri Jun 14 16:42 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA17364
	Fri, 14 Jun 2002 16:42:30 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id QAA22127; Fri, 14 Jun 2002 16:55:19 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma022123; Fri, 14 Jun 02 16:54:41 -0400
Message-ID: <LISTMANAGER-303-729-2002.06.14-15.42.50--fwtk-archive#lists.tislabs.com@listserv.nai.com>
From: "Don" <don@lclcan.com>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Cc: "Keith Young" <kyoung@v-one.com>
Subject: [fwtk-users] Re: problem with ssl and fwtk
Date: Fri, 14 Jun 2002 16:53:22 -0400
MIME-Version: 1.0
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.50.4807.1700
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4807.1700
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: multipart/alternative;
	boundary="----=_NextPart_000_037C_01C213C3.FE2233C0"
Content-Length: 5851
Status: RO

This is a multi-part message in MIME format.

------=_NextPart_000_037C_01C213C3.FE2233C0
Content-Type: text/plain;
	charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable

Don wrote:
> Well, I've d/l and installed a test certificate from Thawte. I had=20
> already set up apache to work with ssl by installing OpenSSL and=20
> ModSSL.  When I try to connect to my site via https://, I get the I.E. =

> "The page cannot be displayed" message.
> =20
> Looking at my logs show no apparent error.  All I see are the =
following=20
> lines (xxx =3D IP):
> =20
> permit host=3Dme.lclcan.com/xxx.xxx.xxx.xxx service=3Dssl=20
> execute=3D/usr/local/etc/ssl-gw
> permit host=3Dlclcan.com/216.94.98.2 service=3Dssl =
execute=3D/usr/local/etc/ssl-gw
> =20
> The engineer at Thawte is convinced it's my firewall causing the=20
> problem.  I'm stumped. Anyone have an idea?
> =20

Don,

Are you using the FWTK? Unless someone renamed the plug-gw proxy, or you =

are running Gauntlet, I don't know where you got the "ssl-gw" proxy =
from...

=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D

Yes I'm using the FWTK.  I'm thinking there's a config problem.

The line in my netperm-table file reads:
  netacl-ssl: permit-hosts * -exec /usr/local/etc/ssl-gw
But this is only for outbound ssl so users from the outside should be =
able to load my site secure, no?

Further down in netperm-table, I see:
  ssl-gw:         denial-msg /usr/local/etc/http-deny.html
  ssl-gw:         timeout 36000
  ssl-gw:         permit-hosts *

The line in my /etc/inetd.conf file reads:
   ssl             stream  tcp     nowait  root    /usr/local/etc/netacl =
ssl

/etc/services is set up as such:
  https           443/tcp
  https           443/udp
  ssl              443/tcp

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

------=_NextPart_000_037C_01C213C3.FE2233C0
Content-Type: text/html;
	charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=3DContent-Type content=3D"text/html; =
charset=3Dwindows-1252">
<META content=3D"MSHTML 5.50.4916.2300" name=3DGENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=3D#ffffff>
<DIV><FONT face=3DArial>Don wrote:<BR>&gt; Well, I've d/l and installed =
a test=20
certificate from Thawte. I had <BR>&gt; already set up apache to work =
with ssl=20
by installing OpenSSL and <BR>&gt; ModSSL.&nbsp; When I try to connect =
to my=20
site via https://, I get the I.E. <BR>&gt; "The page cannot be =
displayed"=20
message.<BR>&gt;&nbsp; <BR>&gt; Looking at my logs show no apparent =
error.&nbsp;=20
All I see are the following <BR>&gt; lines (xxx =3D IP):<BR>&gt;&nbsp; =
<BR>&gt;=20
permit host=3Dme.lclcan.com/xxx.xxx.xxx.xxx service=3Dssl <BR>&gt;=20
execute=3D/usr/local/etc/ssl-gw<BR>&gt; permit =
host=3Dlclcan.com/216.94.98.2=20
service=3Dssl execute=3D/usr/local/etc/ssl-gw<BR>&gt;&nbsp; <BR>&gt; The =
engineer at=20
Thawte is convinced it's my firewall causing the <BR>&gt; problem.&nbsp; =
I'm=20
stumped. Anyone have an idea?<BR>&gt;&nbsp; <BR><BR>Don,<BR><BR>Are you =
using=20
the FWTK? Unless someone renamed the plug-gw proxy, or you <BR>are =
running=20
Gauntlet, I don't know where you got the "ssl-gw" proxy =
from...<BR></FONT></DIV>
<DIV><FONT face=3DArial><FONT=20
size=3D2>=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D</FONT></FONT></DIV>
<DIV><FONT face=3DArial><FONT size=3D2></FONT></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial><FONT size=3D2>Yes I'm using the FWTK.&nbsp; I'm =
thinking=20
there's a config problem.</FONT></FONT></DIV>
<DIV><FONT face=3DArial><FONT size=3D2></FONT></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial><FONT size=3D2>The line in my netperm-table file =

reads:</FONT></FONT></DIV>
<DIV><FONT face=3DArial><FONT size=3D2>&nbsp; netacl-ssl: permit-hosts * =
-exec=20
/usr/local/etc/ssl-gw</FONT></FONT></DIV>
<DIV><FONT face=3DArial size=3D2>But this is only for outbound ssl so =
users from the=20
outside should be able to load my site secure, no?</FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2>Further down in netperm-table, I =
see:</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>&nbsp;=20
ssl-gw:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; denial-msg=20
/usr/local/etc/http-deny.html<BR>&nbsp;=20
ssl-gw:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; timeout =
36000<BR>&nbsp;=20
ssl-gw:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; permit-hosts=20
*</FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2>The line in my /etc/inetd.conf file=20
reads:</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>&nbsp;&nbsp;=20
ssl&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;=20
stream&nbsp; tcp&nbsp;&nbsp;&nbsp;&nbsp; nowait&nbsp; =
root&nbsp;&nbsp;&nbsp;=20
/usr/local/etc/netacl ssl</FONT></DIV>
<DIV><FONT face=3DArial><FONT size=3D2></FONT></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial><FONT size=3D2>/etc/services is set up as=20
such:</FONT></FONT></DIV>
<DIV><FONT face=3DArial><FONT size=3D2>&nbsp;=20
https&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=20
443/tcp<BR>&nbsp;=20
https&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=20
443/udp<BR>&nbsp;=20
ssl&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;=20
443/tcp</FONT></DIV></FONT>
---<BR>
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com<BR>
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com
</BODY></HTML>


------=_NextPart_000_037C_01C213C3.FE2233C0--




From bounce-fwtk-users-303@listserv.nai.com Fri Jun 14 17:12 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA17405
	Fri, 14 Jun 2002 17:12:37 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id RAA22670; Fri, 14 Jun 2002 17:25:25 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma022653; Fri, 14 Jun 02 17:24:40 -0400
Message-ID: <LISTMANAGER-303-730-2002.06.14-16.14.48--fwtk-archive#lists.tislabs.com@listserv.nai.com>
Date: Fri, 14 Jun 2002 17:25:11 -0400
From: Joseph S D Yao <jsdy@center.osis.gov>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Re: This list
Mail-Followup-To: fwtk-users <fwtk-users@listserv.nai.com>
Mime-Version: 1.0
Content-Disposition: inline
User-Agent: Mutt/1.2.5i
In-Reply-To: <LISTMANAGER-765-721-2002.06.14-14.22.02--jsdy#center.osis.gov@listserv.nai.com>; from don@lclcan.com on Fri, Jun 14, 2002 at 03:32:56PM -0400
X-Virus-Scanned: at The OSIS Center by AMaViS-perl11-milter (http://amavis.org/)
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain; charset=us-ascii
Content-Length: 506
Status: RO

On Fri, Jun 14, 2002 at 03:32:56PM -0400, Don wrote:
> Is it still active?

yes, just no longer constantly so.

-- 
Joe Yao				jsdy@center.osis.gov - Joseph S. D. Yao
OSIS Center Systems Support					EMT-B
-----------------------------------------------------------------------
   This message is not an official statement of OSIS Center policies.

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Fri Jun 14 17:16 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id RAA17414
	Fri, 14 Jun 2002 17:16:40 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id RAA22735; Fri, 14 Jun 2002 17:29:26 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma022731; Fri, 14 Jun 02 17:29:19 -0400
Message-ID: <LISTMANAGER-303-731-2002.06.14-16.19.32--fwtk-archive#lists.tislabs.com@listserv.nai.com>
Date: Fri, 14 Jun 2002 17:29:55 -0400
From: Joseph S D Yao <jsdy@center.osis.gov>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Re: not getting any e-mail
Mail-Followup-To: fwtk-users <fwtk-users@listserv.nai.com>
Mime-Version: 1.0
Content-Disposition: inline
User-Agent: Mutt/1.2.5i
In-Reply-To: <LISTMANAGER-765-724-2002.06.14-15.02.43--jsdy#center.osis.gov@listserv.nai.com>; from don@lclcan.com on Fri, Jun 14, 2002 at 04:13:46PM -0400
X-Virus-Scanned: at The OSIS Center by AMaViS-perl11-milter (http://amavis.org/)
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain; charset=us-ascii
Content-Length: 786
Status: RO

On Fri, Jun 14, 2002 at 04:13:46PM -0400, Don wrote:
> Strange,  I can post to the list but I never get any e-mail from the list including my posts.  A check of the web archive shows my posts as appearing.
> 
> ---
> You are currently subscribed to fwtk-users as: jsdy@center.osis.gov
> To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

Obviously, I got this one.

-- 
Joe Yao				jsdy@center.osis.gov - Joseph S. D. Yao
OSIS Center Systems Support					EMT-B
-----------------------------------------------------------------------
   This message is not an official statement of OSIS Center policies.

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Fri Jun 14 21:22 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id VAA17797
	Fri, 14 Jun 2002 21:22:25 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id VAA26967; Fri, 14 Jun 2002 21:35:12 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma026962; Fri, 14 Jun 02 21:34:48 -0400
Message-Id: <LISTMANAGER-303-734-2002.06.14-20.24.36--fwtk-archive#lists.tislabs.com@listserv.nai.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.1.1
Date: Fri, 14 Jun 2002 16:47:24 -0400
To: "fwtk-users" <fwtk-users@listserv.nai.com>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: [fwtk-users] Re: problem with ssl and fwtk
In-Reply-To: <LISTMANAGER-602-723-2002.06.14-14.59.37--rmurphy#itm-inst.
 com@listserv.nai.com>
Mime-Version: 1.0
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 1285
Status: RO

At 04:10 PM 6/14/02 -0400, Don wrote:
>Well, I've d/l and installed a test certificate from Thawte. I had already 
>set up apache to work with ssl by installing OpenSSL and ModSSL.  When I 
>try to connect to my site via https://, I get the I.E. "The page cannot be 
>displayed" message.
>
>Looking at my logs show no apparent error.  All I see are the following 
>lines (xxx = IP):
>
>permit host=me.lclcan.com/xxx.xxx.xxx.xxx service=ssl 
>execute=/usr/local/etc/ssl-gw
>permit host=lclcan.com/216.94.98.2 service=ssl execute=/usr/local/etc/ssl-gw

I think you're running things backwards - VERY backwards.
The ssl-gw, if I remember right, is a SSL proxy. You can't front-end a web 
server with a SSL proxy. Just use plug-gw to forward the incoming traffic 
to your web server.

Running ssl-gw inbound this way is opening you to a huge security hole - 
anyone can telnet to your firewall on port 443, then use a "connect" verb 
to bypass your firewall.

>The engineer at Thawte is convinced it's my firewall causing the 
>problem.  I'm stumped. Anyone have an idea?

Of course - it's always the firewall :-)
         -Rick


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Fri Jun 14 21:24 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id VAA17801
	Fri, 14 Jun 2002 21:24:26 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id VAA26989; Fri, 14 Jun 2002 21:37:13 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma026980; Fri, 14 Jun 02 21:36:22 -0400
Message-Id: <LISTMANAGER-303-735-2002.06.14-20.24.38--fwtk-archive#lists.tislabs.com@listserv.nai.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.1.1
Date: Fri, 14 Jun 2002 16:50:47 -0400
To: "fwtk-users" <fwtk-users@listserv.nai.com>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: [fwtk-users] Re: problem with ssl and fwtk
In-Reply-To: <LISTMANAGER-602-726-2002.06.14-15.06.27--rmurphy#itm-inst.
 com@listserv.nai.com>
Mime-Version: 1.0
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 421
Status: RO

At 04:14 PM 6/14/02 -0400, Keith Young wrote:
>Don,
>
>Are you using the FWTK? Unless someone renamed the plug-gw proxy, or you 
>are running Gauntlet, I don't know where you got the "ssl-gw" proxy from...

That's one of the contributed proxies.
         -Rick


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Mon Jun 17 08:50 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id IAA21783
	Mon, 17 Jun 2002 08:50:06 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id JAA08858; Mon, 17 Jun 2002 09:02:58 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma008845; Mon, 17 Jun 02 09:02:35 -0400
Message-ID: <LISTMANAGER-303-737-2002.06.17-07.52.41--fwtk-archive#lists.tislabs.com@listserv.nai.com>
From: "Don" <don@lclcan.com>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
References: <5.1.1.6.0.20020614164154.00ab72e0@mail.itm-inst.com>
Subject: [fwtk-users] Re: problem with ssl and fwtk
Date: Mon, 17 Jun 2002 09:03:26 -0400
MIME-Version: 1.0
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.50.4807.1700
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4807.1700
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: multipart/alternative;
	boundary="----=_NextPart_000_000F_01C215DD.D7701DC0"
Content-Length: 4239
Status: RO

This is a multi-part message in MIME format.

------=_NextPart_000_000F_01C215DD.D7701DC0
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

Well, if I am front-ending it, it's not on purpose.  The begets the =
question.  How do I configure it so that the proxy is only for outgoing =
while all incoming requests just use regular apache?
  At 04:10 PM 6/14/02 -0400, Don wrote:
  >Well, I've d/l and installed a test certificate from Thawte. I had =
already=20
  >set up apache to work with ssl by installing OpenSSL and ModSSL.  =
When I=20
  >try to connect to my site via https://, I get the I.E. "The page =
cannot be=20
  >displayed" message.
  >
  >Looking at my logs show no apparent error.  All I see are the =
following=20
  >lines (xxx =3D IP):
  >
  >permit host=3Dme.lclcan.com/xxx.xxx.xxx.xxx service=3Dssl=20
  >execute=3D/usr/local/etc/ssl-gw
  >permit host=3Dlclcan.com/216.94.98.2 service=3Dssl =
execute=3D/usr/local/etc/ssl-gw

  I think you're running things backwards - VERY backwards.
  The ssl-gw, if I remember right, is a SSL proxy. You can't front-end a =
web=20
  server with a SSL proxy. Just use plug-gw to forward the incoming =
traffic=20
  to your web server.

  Running ssl-gw inbound this way is opening you to a huge security hole =
-=20
  anyone can telnet to your firewall on port 443, then use a "connect" =
verb=20
  to bypass your firewall.

  >The engineer at Thawte is convinced it's my firewall causing the=20
  >problem.  I'm stumped. Anyone have an idea?

  Of course - it's always the firewall :-)
           -Rick


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

------=_NextPart_000_000F_01C215DD.D7701DC0
Content-Type: text/html;
	charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=3DContent-Type content=3D"text/html; =
charset=3Diso-8859-1">
<META content=3D"MSHTML 5.50.4916.2300" name=3DGENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=3D#ffffff>
<DIV><FONT face=3DArial size=3D2>Well, if I am front-ending it, it's not =
on=20
purpose.&nbsp; The begets the question.&nbsp; How do I configure it so =
that the=20
proxy is only for outgoing while all incoming requests just use regular=20
apache?</FONT></DIV>
<BLOCKQUOTE=20
style=3D"PADDING-RIGHT: 0px; PADDING-LEFT: 5px; MARGIN-LEFT: 5px; =
BORDER-LEFT: #000000 2px solid; MARGIN-RIGHT: 0px">At=20
  04:10 PM 6/14/02 -0400, Don wrote:<BR>&gt;Well, I've d/l and installed =
a test=20
  certificate from Thawte. I had already <BR>&gt;set up apache to work =
with ssl=20
  by installing OpenSSL and ModSSL.&nbsp; When I <BR>&gt;try to connect =
to my=20
  site via https://, I get the I.E. "The page cannot be =
<BR>&gt;displayed"=20
  message.<BR>&gt;<BR>&gt;Looking at my logs show no apparent =
error.&nbsp; All I=20
  see are the following <BR>&gt;lines (xxx =3D =
IP):<BR>&gt;<BR>&gt;permit=20
  host=3Dme.lclcan.com/xxx.xxx.xxx.xxx service=3Dssl=20
  <BR>&gt;execute=3D/usr/local/etc/ssl-gw<BR>&gt;permit=20
  host=3Dlclcan.com/216.94.98.2 service=3Dssl =
execute=3D/usr/local/etc/ssl-gw<BR><BR>I=20
  think you're running things backwards - VERY backwards.<BR>The ssl-gw, =
if I=20
  remember right, is a SSL proxy. You can't front-end a web <BR>server =
with a=20
  SSL proxy. Just use plug-gw to forward the incoming traffic <BR>to =
your web=20
  server.<BR><BR>Running ssl-gw inbound this way is opening you to a =
huge=20
  security hole - <BR>anyone can telnet to your firewall on port 443, =
then use a=20
  "connect" verb <BR>to bypass your firewall.<BR><BR>&gt;The engineer at =
Thawte=20
  is convinced it's my firewall causing the <BR>&gt;problem.&nbsp; I'm =
stumped.=20
  Anyone have an idea?<BR><BR>Of course - it's always the firewall=20
  :-)<BR>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=20
-Rick<BR></BLOCKQUOTE>
---<BR>
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com<BR>
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com
</BODY></HTML>


------=_NextPart_000_000F_01C215DD.D7701DC0--




From bounce-fwtk-users-303@listserv.nai.com Mon Jun 17 14:33 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id OAA22400
	Mon, 17 Jun 2002 14:33:54 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id OAA18490; Mon, 17 Jun 2002 14:46:45 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma018472; Mon, 17 Jun 02 14:46:10 -0400
Date: Mon, 17 Jun 2002 12:46:48 -0600
From: dreamwvr <dreamwvr@dreamwvr.com>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] This list
Message-ID: <LISTMANAGER-303-740-2002.06.17-13.36.18--fwtk-archive#lists.tislabs.com@listserv.nai.com>
Mime-Version: 1.0
Content-Disposition: inline
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain; charset=us-ascii
Content-Length: 682
Status: RO

helo,
    Yes the list is still parsed although perhaps not as 
often as back in the day. Well glad to see that those from
back_then are still well. 

cu

Best Regards,
dreamwvr@dreamwvr.com

-- 
/*  Security is a work in progress - dreamwvr                 */
#                                                             
# Note: To begin Journey type man afterboot,man help,man hier[.]      
#                                                             
// "Who's Afraid of Schrodinger's Cat?" /var/(.)?mail/me \?  ;-]

---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Mon Jun 17 16:58 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA22590
	Mon, 17 Jun 2002 16:58:18 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id RAA22692; Mon, 17 Jun 2002 17:11:10 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma022675; Mon, 17 Jun 02 17:10:23 -0400
Message-Id: <LISTMANAGER-303-742-2002.06.17-16.00.32--fwtk-archive#lists.tislabs.com@listserv.nai.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.1.1
Date: Mon, 17 Jun 2002 16:59:16 -0400
To: "fwtk-users" <fwtk-users@listserv.nai.com>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: [fwtk-users] Re: problem with ssl and fwtk
In-Reply-To: <LISTMANAGER-602-737-2002.06.17-07.52.41--rmurphy#itm-inst.
 com@listserv.nai.com>
References: <5.1.1.6.0.20020614164154.00ab72e0@mail.itm-inst.com>
Mime-Version: 1.0
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 1432
Status: RO

At 09:03 AM 6/17/02 -0400, Don wrote:
Please post in plain text - that makes it easier for us with text-mode mail 
readers to follow. HTML also looks bad in the archives.

>Well, if I am front-ending it, it's not on purpose.  The begets the 
>question.  How do I configure it so that the proxy is only for outgoing 
>while all incoming requests just use regular apache?

OK, I guess I'm not sure I understand what you're doing.
If you're running Apache on your firewall, don't. A basic tenet of firewall 
design is to minimize what's installed so that you're less likely to be 
exploited due to a bug. Apache is far too large and complex to run on a 
firewall.

Assuming you're running it all on one box, set up Apache to only listen on 
your external IP address. Then, anyone from the inside will get the proxy 
and outside people will get the web server.

If you're running Apache on a separate internal system, then what you want 
to do is to get the bind-address patch for plug-gw. Use that plug-gw on the 
firewall, bound to the outside IP address only. Plug from that address on 
port 443 to the web server on port 443.

If you don't use the bind-address patch, you could use netacl. Have 
internal hosts exec  ssl-gw and external hosts exec plug-gw.
         -Rick


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Tue Jun 18 09:03 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA24230
	Tue, 18 Jun 2002 09:03:36 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id JAA06721; Tue, 18 Jun 2002 09:16:28 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma006702; Tue, 18 Jun 02 09:16:10 -0400
Message-ID: <LISTMANAGER-303-746-2002.06.18-08.06.01--fwtk-archive#lists.tislabs.com@listserv.nai.com>
From: "Don" <don@lclcan.com>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Re: problem with ssl and fwtk
Date: Tue, 18 Jun 2002 09:17:21 -0400
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.50.4807.1700
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4807.1700
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 3108
Status: RO

Sorry for the HTML post.  Yes, I am running my web server and firewall on the same machine.  At this time,this is my only option.

If I understand, I should assign different ports to https and ssl in /etc/services and then have Apache listening on port 444?  I
already have apache listening on my external I.P.

e.g.
==
https           443/tcp
https           443/udp
ssl               444/tcp

Note: It's possible that my problem is related to something else.  I ran the following script on the server:  openssl
s_client -connect 216.94.98.2:443 -debug -state

and received the following error:

SSL_connect:before/connect initialization
write to 08146430 [08146A78] (130 bytes => 130 (0x82))
0000 - 80 80 01 03 01 00 57 00-00 00 20 00 00 16 00 00   ......W... .....
0010 - 13 00 00 0a 07 00 c0 00-00 66 00 00 07 00 00 05   .........f......
0020 - 00 00 04 05 00 80 03 00-80 01 00 80 08 00 80 00   ................
0030 - 00 65 00 00 64 00 00 63-00 00 62 00 00 61 00 00   .e..d..c..b..a..
0040 - 60 00 00 15 00 00 12 00-00 09 06 00 40 00 00 14   `...........@...
0050 - 00 00 11 00 00 08 00 00-06 00 00 03 04 00 80 02   ................
0060 - 00 80 55 b6 1e 51 9a a0-cf 3f cb de da f6 28 29   ..U..Q...?....()
0070 - 9b 8d 74 62 80 67 d3 d7-f8 c8 bf ed 84 d3 fc 6c   ..tb.g.........l
0080 - 8a 42                                             .B
SSL_connect:SSLv2/v3 write client hello A
read from 08146430 [0814BFD8] (7 bytes => -1 (0xFFFFFFFF))
SSL_connect:error in SSLv2/v3 read server hello A
write:errno=104

===========================

At 09:03 AM 6/17/02 -0400, Don wrote:
Please post in plain text - that makes it easier for us with text-mode mail
readers to follow. HTML also looks bad in the archives.

>Well, if I am front-ending it, it's not on purpose.  The begets the
>question.  How do I configure it so that the proxy is only for outgoing
>while all incoming requests just use regular apache?

OK, I guess I'm not sure I understand what you're doing.
If you're running Apache on your firewall, don't. A basic tenet of firewall
design is to minimize what's installed so that you're less likely to be
exploited due to a bug. Apache is far too large and complex to run on a
firewall.

Assuming you're running it all on one box, set up Apache to only listen on
your external IP address. Then, anyone from the inside will get the proxy
and outside people will get the web server.

If you're running Apache on a separate internal system, then what you want
to do is to get the bind-address patch for plug-gw. Use that plug-gw on the
firewall, bound to the outside IP address only. Plug from that address on
port 443 to the web server on port 443.

If you don't use the bind-address patch, you could use netacl. Have
internal hosts exec  ssl-gw and external hosts exec plug-gw.
         -Rick


---
You are currently subscribed to fwtk-users as: don@lclcan.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com



---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Wed Jun 19 09:33 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id JAA27279
	Wed, 19 Jun 2002 09:33:28 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id JAA10575; Wed, 19 Jun 2002 09:46:24 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma010565; Wed, 19 Jun 02 09:46:14 -0400
Message-ID: <LISTMANAGER-303-747-2002.06.19-08.36.00--fwtk-archive#lists.tislabs.com@listserv.nai.com>
From: "Don" <don@lclcan.com>
To: "fwtk-users" <fwtk-users@listserv.nai.com>
Subject: [fwtk-users] Re: problem with ssl and fwtk
Date: Wed, 19 Jun 2002 09:47:24 -0400
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.50.4807.1700
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4807.1700
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Length: 1706
Status: RO

Ok.  I think I have a better idea.  In my /etc/inetd.conf file, ther'sa line that says:

ssl     stream  tcp     nowait  root    /usr/local/etc/netacl ssl

I think the above is the reason that ssl requests inbound are being intercepted.  So...., how do I make the above outbound only?

==============

>Well, if I am front-ending it, it's not on purpose.  The begets the 
>question.  How do I configure it so that the proxy is only for outgoing 
>while all incoming requests just use regular apache?

OK, I guess I'm not sure I understand what you're doing.
If you're running Apache on your firewall, don't. A basic tenet of firewall 
design is to minimize what's installed so that you're less likely to be 
exploited due to a bug. Apache is far too large and complex to run on a 
firewall.

Assuming you're running it all on one box, set up Apache to only listen on 
your external IP address. Then, anyone from the inside will get the proxy 
and outside people will get the web server.

If you're running Apache on a separate internal system, then what you want 
to do is to get the bind-address patch for plug-gw. Use that plug-gw on the 
firewall, bound to the outside IP address only. Plug from that address on 
port 443 to the web server on port 443.

If you don't use the bind-address patch, you could use netacl. Have 
internal hosts exec  ssl-gw and external hosts exec plug-gw.
         -Rick


---
You are currently subscribed to fwtk-users as: don@lclcan.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

From bounce-fwtk-users-303@listserv.nai.com Wed Jun 19 16:38 EDT 2002
Received: from sentry.gw.tislabs.com (firewall-user@sentry.gw.tislabs.com [192.94.214.100])
	by lists.tislabs.com (8.9.1/8.9.1) with ESMTP id QAA28161
	Wed, 19 Jun 2002 16:38:17 -0400 (EDT)
Received: by sentry.gw.tislabs.com; id QAA22949; Wed, 19 Jun 2002 16:51:12 -0400 (EDT)
Received: from listserv.nai.com(161.69.213.6) by sentry.gw.tislabs.com via smap (V5.5)
	id xma022933; Wed, 19 Jun 02 16:50:54 -0400
Message-Id: <LISTMANAGER-303-750-2002.06.19-15.40.32--fwtk-archive#lists.tislabs.com@listserv.nai.com>
X-Sender: rmurphy@mail.itm-inst.com
X-Mailer: QUALCOMM Windows Eudora Version 5.1.1
Date: Wed, 19 Jun 2002 16:49:29 -0400
To: "fwtk-users" <fwtk-users@listserv.nai.com>
From: Rick Murphy <rmurphy@itm-inst.com>
Subject: [fwtk-users] Re: problem with ssl and fwtk
In-Reply-To: <LISTMANAGER-602-747-2002.06.19-08.36.00--rmurphy#itm-inst.
 com@listserv.nai.com>
Mime-Version: 1.0
List-Unsubscribe: <mailto:leave-fwtk-users-303A@listserv.nai.com>
Reply-To: "fwtk-users" <fwtk-users@listserv.nai.com>
Content-Type: text/plain; charset="us-ascii"; format=flowed
Content-Length: 1307
Status: RO

At 09:47 AM 6/19/02 -0400, Don wrote:
>Ok.  I think I have a better idea.  In my /etc/inetd.conf file, ther'sa 
>line that says:
>
>ssl     stream  tcp     nowait  root    /usr/local/etc/netacl ssl
>
>I think the above is the reason that ssl requests inbound are being 
>intercepted.  So...., how do I make the above outbound only?

Yes, that's true - that will cause inetd to capture all traffic to port 443.
Remove that from inetd, then kill and restart inetd. That should allow you 
to connect to your web server using SSL. If that's not working, it's not 
the firewall and you should investigate further.

Then, set up a copy of ssl-gw listening to some other port. Don't use 
netacl to front end it - that's an unnecessary complication. Tell your 
internal users to use that port as their SSL proxy.

To reiterate, I don't recommend running your web server and your firewall 
on the same machine. In the configuration you're using, if your web server 
is compromised it can be used as a stepping stone to bypass the firewall 
and access your internal network. You really should find a separate machine 
to use as a web server.
         -Rick


---
You are currently subscribed to fwtk-users as: fwtk-archive@lists.tislabs.com
To unsubscribe send a blank email to leave-fwtk-users-303A@listserv.nai.com

