Anope SSL

The UnrealIRCd team does not officially provide support for any services packages that you may be using or want to use. This forum is provided so the community can help each other with services issues.

Moderator: Supporters

Locked
pstruh22
Posts: 48
Joined: Mon Jan 31, 2005 2:14 pm

Anope SSL

Post by pstruh22 »

Hi

I using unrealICRD+SSL and Anope 1.7.8

Its possilbe to connect Anope services to SSL port ?
commandr
Posts: 40
Joined: Tue Jan 04, 2005 3:18 am
Location: Argentina

Post by commandr »

Anope doesn't support SSL
pstruh22
Posts: 48
Joined: Mon Jan 31, 2005 2:14 pm

Post by pstruh22 »

commandr wrote:Anope doesn't support SSL

OK,
If Anope doesn't support SSL, and is connected to non-SSL port, can user sniffing comunication between me an Nickserv ? Can he stolen my registered password to nickserv ?
commandr
Posts: 40
Joined: Tue Jan 04, 2005 3:18 am
Location: Argentina

Post by commandr »

hums.. I suppose that no
commandr
Posts: 40
Joined: Tue Jan 04, 2005 3:18 am
Location: Argentina

Post by commandr »

install a firewall in your computer
pstruh22
Posts: 48
Joined: Mon Jan 31, 2005 2:14 pm

Post by pstruh22 »

I need encrypted comunication between me and services. Firewall I have instaled.
Syzop
UnrealIRCd head coder
Posts: 2179
Joined: Sat Mar 06, 2004 8:57 pm
Location: .nl
Contact:

Post by Syzop »

uh, a firewall doesn't protect against sniffing ;).

Anyway... stuff can only be sniffed if an attacker has control over a device (eg: a computer) in the path between ircserver<----this---->anope.
If you link anope via localhost to your irc server (or in any other way does not cross a LAN/WAN/whatever), then it cannot be sniffed
[uh ok, it can be sniffed, but only by persons on that host and if you got rood/admin privileges]

So, if services are on another server than your IRCd, then you could either install an ircd at that server, or you could run something like stunnel @ your services location and let services connect to the stunnel, then the topology is: ircserver<------SSL secure connection--->stunnel<-->anope.
pstruh22
Posts: 48
Joined: Mon Jan 31, 2005 2:14 pm

Post by pstruh22 »

I am linking anope via localhost to my irc server. It running on same localhost as ircd server which support SSL.

I am connected to IRCD via SSL, Services not.
pstruh22
Posts: 48
Joined: Mon Jan 31, 2005 2:14 pm

Post by pstruh22 »

and what about attack man-in-the-middle ?
Caedmon
Posts: 14
Joined: Sun Dec 26, 2004 11:21 am

Post by Caedmon »

As it's been said, If Services are connected to your network locally, then there is no way someone can "sniff" your password. Especially if you're connected to the server as an SSL Client
codemastr
Former UnrealIRCd head coder
Posts: 811
Joined: Sat Mar 06, 2004 8:47 pm
Location: United States
Contact:

Post by codemastr »

pstruh22 wrote:and what about attack man-in-the-middle ?
I take it you have no idea what a man-in-the-middle attack is? It has absolutely nothing to do with this scenario. If it is on the local machine, there can be no man-in-the-middle attack because there is no man and no middle! The communication is direct - it's the same machine!
-- codemastr
Locked