From: Aaron Turner Date: 2008-05-25T00:46:39+09:00 Subject: Re: Need your recommendations for TCP Server/Client design On Fri, May 23, 2008 at 2:07 PM, Victor Reyes wrote: [snip] > Reading a new book I just acquired I came across a package called *GServer*. > I was wondering if this will be suitable for what I need. > Also, what type of encryption should I use? > > They were talking something like: > > Client sends connection request > Server replies with client's *hostname* and *time* > Client sends back the *time *received from server together with the command > which the client wants to execute at the remote server. > Server executes command if it is "happy" with the reply from the client. > > Of course all communication must be ciphered. > > Any suggestions will be greatly appreciated. GServer is great. I'd use SSL for encryption. Require the client app to authenticate to each server via a password. Probably easiest to check against the root password. The easiest way to add SSL to any application is to run stunnel on each of your servers and have it proxy to your server listing on a port on the loopback interface. That way your server doesn't even have to know SSL and it's easy to debug. Whatever you do DO NOT design your own crypto solution- notice the Debian guys couldn't even make a small "fix" without breaking ssh horribly. On a side note, there are already free solutions for this sort of thing... just search freshmeat.net. -- Aaron Turner http://synfin.net/ http://tcpreplay.synfin.net/ - Pcap editing & replay tools for Unix They that can give up essential liberty to obtain a little temporary safety deserve neither liberty nor safety. -- Benjamin Franklin