Secure Global Desktop Administration Guide > Security > Getting started with the Sun Secure Global Desktop Security Pack
Read this topic to... |
---|
|
Installing the Sun Secure Global Desktop Security Pack on a Secure Global Desktop server lets you give users secure connections between their client devices and that Secure Global Desktop server. The connections are secured using SSL, the Secure Sockets Layer.
Secure connections have these benefits:
Benefit | Description |
---|---|
No eavesdropping | SSL encrypts all information before transmission. |
No tampering | SSL can check that a message hasn't changed between the client device and the Secure Global Desktop server. |
No message forgery | SSL requires that the server prove its identity to client devices before communications can take place, and also guards against replay attacks. |
Internet transactions are open to many forms of attack, for example packet-sniffing, DNS spoofing, and man-in-the-middle attacks. It is critical to recognize that even when SSL is used, a connection is only secure if SSL is configured correctly.
The Security Pack can only help raise security levels as part of an ongoing security strategy. The Security Pack can't transform your intranet into a high-security installation by itself.
Once the Security Pack is installed on a Secure Global Desktop server, you must do the following before secure connections are possible:
tarantella security start
. This
enables secure connections for the users you've configured to have
them.You can decide which users receive secure (SSL-based) connections, and which users receive standard (unencrypted) connections. To do so, you configure the Connections attribute for a person object, organizational unit object, or organization object.
You can configure the type of connection based on these factors:
The initial connection to a Secure Global Desktop server, before users type their username and password, is always secure if the Security Pack is installed and running. This means that usernames and passwords are always sent securely. Once the user is identified, the connection may be downgraded to a standard connection according to your configuration.
Here are some examples for customizing connection types:
The Security Pack secures Secure Global Desktop-related connections between the client device and Secure Global Desktop server. It does not secure any other type of connection: for example, the connections made to a web server on the same host.
We recommend that you use a secure (HTTPS) web server. To do so you need an X.509 certificate for the web server as well as for the Secure Global Desktop server. Some web servers allow you to share the X.509 certificate between the web server and the Security Pack.
If you are using the browser-based webtop or you have developed your own web applications, you must also secure the SOAP connections to a Secure Global Desktop server.
Secure connections between the client device and Secure Global Desktop server use port 5307/tcp.
Copyright © 1997-2005 Sun Microsystems, Inc. All rights reserved.