[THIN] Re: SSL Relay

  • From: Eric Foote <EricF@xxxxxxxxx>
  • To: "'thin@xxxxxxxxxxxxx'" <thin@xxxxxxxxxxxxx>
  • Date: Sat, 28 Sep 2002 07:58:10 -0400

SSL - Secure Socket Layer - a negotiated key system between two systems that
encrypts the stream of information passed between them.

To make this work you need:
A Certificate for the SSL Server (Verisign - about $300 per year)
An External Fully qualified domain name that matches the FQDN on the cert
A Root CA for the client machines (Verisigns Root CA comes with Windows)

If you want to try it - you can go to www.thawte.com and get a 21 day test
cert - keep in mind that since it is not a live cert you will need to
install the Thawte Test Root CA on any machine that will be testing with
your server. (From http://www.thawte.com/html/SUPPORT/index.html#)

I just finished a CSG setup yesterday - it was a bit of a pain - but it
seemed pretty slick once it was setup.  So now we only need to open (2) SSL
ports to our CSG servers rather than 85 port 1494's to our Citrix boxes.

Eric Foote
*************************************************
Business Computer Systems of Mi, Inc.           
49 Macomb Place Suite 20                        
Mt. Clemens, MI 48043                          
(586) 783-6046 x202 Voice                            
(586) 783-6048 Fax                              
EricF@xxxxxxxxx                                 
www.bcsmi.com                                   
Your source for Thin Client Computing Solutions!
*************************************************


-----Original Message-----
From: Robert Walk [mailto:rwalk@xxxxxxxxxxx]
Sent: Friday, September 27, 2002 8:43 AM
To: thin@xxxxxxxxxxxxx
Subject: [THIN] Re: SSL Relay



Yep, I have FR2.  From what I have read it appears that SSL Relay is a
better solution for our situation.  Of course I could be wrong!

Rob

On Thu, 2002-09-26 at 21:26, Chris Lynch wrote:
> 
>  
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
> 
> If you want a test cert, I would use a Thawte cert.  They last 21
> days, and are just the same as Verisign.  If cannot get a "free" one,
> the Thawte 1 year is $199.  Cheaper that Verisign.
> 
> Also, why are you using SSL Relay?  Do you have FR2?
> 
> CHRIS LYNCH -  MCSE, CCNA, CCA
> NETWORK ENGINEER - INFORMATION TECHNOLOGY
> NRT Incorporated, 27271 Las Ramblas, Mission Viejo, CA 92691
> Chris.lynch@xxxxxxxxxx  Tel 949.367.3406
> 
> 
> - -----Original Message-----
> From: thin-bounce@xxxxxxxxxxxxx [mailto:thin-bounce@xxxxxxxxxxxxx] On
> Behalf Of Eugene Herman
> Sent: Thursday, September 26, 2002 11:57 AM
> To: thin@xxxxxxxxxxxxx
> Subject: [THIN] Re: SSL Relay
> 
> 
> 
> You can get a free certificate from Verisign - good for 14 days - you
> muet = also load a file called getacert.cer on the WS - also
> available free from = Verisign - and yes you can download another one
> on day 15
> 
> >>> rwalk@xxxxxxxxxxx 09/26/02 01:48PM >>>
> 
> Hello,
> 
> I am trying to configure SSL relay for Metaframe XP on Windows 2000
> Server.  Right now I am just trying to test it and possibly deploy it
> to a few users.  The problem I am having is with the "Server
> Certificate", is there a way to use one with having to pay for it?  I
> have read some of the docs and haven't been able to come a signed
> certificate that works.  Any pointers would be greatly appreciated.
> 
> Thanks,
> 
> Rob
> 
> 
> 
> **********************************************
> This weeks sponsor Kevsoft Corporation=20
> TScale by Kevsoft Corporation=20
> Support 30% to 40% more users on your server farm
> without buying new hardware! =20
> http://www.kevsoft.com/=20
> ***********************************************
> 
> For Archives, to Unsubscribe, Subscribe or=20
> set Digest or Vacation mode use the below link.
> 
> http://thethin.net/citrixlist.cfm
> 
> 
> 
> **********************************************************************
> ***
> This message, together with any attachments, is intended only for the
> use of the individual or entity to which it is addressed. It may
> contain information that is confidential and prohibited from
> disclosure.  If you are not the intended recipient, you are hereby
> notified that any dissemination or copying of this message or any
> attachment is strictly prohibited. If you have received this message
> in error, please notify the original sender immediately by telephone
> or by return e-mail and delete this message along with any
> attachments, from your computer. Thank you.
> **********************************************************************
> ***
> 
> 
> 
> **********************************************************************
> ***
> This message, together with any attachments, is intended only for the
> use of the individual or entity to which it is addressed. It may
> contain information that is confidential and prohibited from
> disclosure.  If you are not the intended recipient, you are hereby
> notified that any dissemination or copying of this message or any
> attachment is strictly prohibited. If you have received this message
> in error, please notify the original sender immediately by telephone
> or by return e-mail and delete this message along with any
> attachments, from your computer. Thank you.
> **********************************************************************
> ***
> 
> 
> 
> **********************************************************************
> ***
> This message, together with any attachments, is intended only for the
> use of the individual or entity to which it is addressed. It may
> contain information that is confidential and prohibited from
> disclosure.  If you are not the intended recipient, you are hereby
> notified that any dissemination or copying of this message or any
> attachment is strictly prohibited. If you have received this message
> in error, please notify the original sender immediately by telephone
> or by return e-mail and delete this message along with any
> attachments, from your computer. Thank you.
> **********************************************************************
> ***
> 
> 
> 
> **********************************************************************
> ***
> This message, together with any attachments, is intended only for the
> use of the individual or entity to which it is addressed. It may
> contain information that is confidential and prohibited from
> disclosure.  If you are not the intended recipient, you are hereby
> notified that any dissemination or copying of this message or any
> attachment is strictly prohibited. If you have received this message
> in error, please notify the original sender immediately by telephone
> or by return e-mail and delete this message along with any
> attachments, from your computer. Thank you.
> **********************************************************************
> ***
> 
> **********************************************
> This weeks sponsor Kevsoft Corporation 
> TScale by Kevsoft Corporation 
> Support 30% to 40% more users on your server farm
> without buying new hardware!  
> http://www.kevsoft.com/
> ***********************************************
> 
> For Archives, to Unsubscribe, Subscribe or 
> set Digest or Vacation mode use the below link.
> 
> http://thethin.net/citrixlist.cfm
> 
> -----BEGIN PGP SIGNATURE-----
> Version: PGP 7.1
> 
> iQA/AwUBPZOzyfl56xfvzmMfEQJEjQCdE2kxQvYG5SHSw8UbRgztXg7QONUAn3YN
> ez6pWCqWHuQFWqueYNGeJCfg
> =YaXO
> -----END PGP SIGNATURE-----
> 
> **********************************************
> This weeks sponsor Kevsoft Corporation 
> TScale by Kevsoft Corporation 
> Support 30% to 40% more users on your server farm
> without buying new hardware!  
> http://www.kevsoft.com/
> ***********************************************
> 
> For Archives, to Unsubscribe, Subscribe or 
> set Digest or Vacation mode use the below link.
> 
> http://thethin.net/citrixlist.cfm


**********************************************
This weeks sponsor Kevsoft Corporation 
TScale by Kevsoft Corporation 
Support 30% to 40% more users on your server farm
without buying new hardware!  
http://www.kevsoft.com/
***********************************************

For Archives, to Unsubscribe, Subscribe or 
set Digest or Vacation mode use the below link.

http://thethin.net/citrixlist.cfm
**********************************************
This weeks sponsor Kevsoft Corporation 
TScale by Kevsoft Corporation 
Support 30% to 40% more users on your server farm
without buying new hardware!  
http://www.kevsoft.com/
***********************************************

For Archives, to Unsubscribe, Subscribe or 
set Digest or Vacation mode use the below link.

http://thethin.net/citrixlist.cfm

Other related posts: