<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cookbook for transition to secure protocols? in Operating System - OpenVMS</title>
    <link>https://community.hpe.com/t5/operating-system-openvms/cookbook-for-transition-to-secure-protocols/m-p/6556392#M46172</link>
    <description>&lt;P&gt;VMS has no support for secure transports for LAN clustering, SMH, DECnet and any related traffic (if present) is usually firewalled to maintain security and privacy. &amp;nbsp; SCS is a wide-open LAN protocol, so you really don't want that mixed with any untrusted LAN devices. &amp;nbsp;&lt;A href="http://labs.hoffmanlabs.com/node/621" target="_blank"&gt;I usually recommend a firewall with VMS here&lt;/A&gt;. &amp;nbsp; (While most folks think of Windows clients in this context, these days even network printers aren't all that trustworthy, either.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Various of the higher-level IP networking packages have SSL/TLS and ssh options available (&lt;A href="http://labs.hoffmanlabs.com/node/1116" target="_blank"&gt;setting up ssh and sftp&lt;/A&gt;), and &lt;A href="http://labs.hoffmanlabs.com/node/1760" target="_blank"&gt;PuTTY has ssh certificate-based login capabilities&lt;/A&gt;&amp;nbsp;- above the level of VMS itself, this is more of a generic IP network security question, too. &amp;nbsp;Put another way, documents on how to secure IP traffic will — more or less — apply to VMS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ssh can accept a command for execution on a remote host, so that can be one way to trigger remote activity. &amp;nbsp; &lt;SPAN&gt;&amp;nbsp;(&lt;/SPAN&gt;&lt;A href="http://h71000.www7.hp.com/doc/84final/tcprn/tcp_rnpro_004.html" target="_blank"&gt;Some details&lt;/A&gt;&lt;SPAN&gt;) &amp;nbsp; &amp;nbsp;&lt;/SPAN&gt;Triggering via a web server and a CGI script is another. &amp;nbsp;(&lt;A href="http://labs.hoffmanlabs.com/node/277" target="_blank"&gt;Apache on VMS can invoke DCL procedures as CGI scripts&lt;/A&gt;, for instance, and these resources can be accessed via SSL/TLS.) &amp;nbsp; There are (were?) also some distributed process schedulers and job managers around for VMS, too, if you're looking to automate these sorts of activities.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've posted &lt;A href="http://labs.hoffmanlabs.com/node/619" target="_blank"&gt;some general notes from OpenVMS LDAP external authentication&lt;/A&gt;, but I didn't test the certificate-based access path. &amp;nbsp;Would have to dig into the details of getting that to work — configuring and troubleshooting the Open Directory LDAP connection was complex more than I'd expected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 28 Jul 2014 21:25:59 GMT</pubDate>
    <dc:creator>Hoff</dc:creator>
    <dc:date>2014-07-28T21:25:59Z</dc:date>
    <item>
      <title>Cookbook for transition to secure protocols?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/cookbook-for-transition-to-secure-protocols/m-p/6553842#M46168</link>
      <description>&lt;P&gt;My apologies if this has already been documented and I did not come across it in my search.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am working to put together a plan for transitioning an 8.4 cluster running on Integrity Blades from using protocols like ftp, rsh, telnet, etc... to sftp, ssh, etc...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to address everything in the plan but from a high level&lt;/P&gt;&lt;P&gt;- Reflections telnet and ftp access&lt;/P&gt;&lt;P&gt;- Batch and interactive ftp, rsh, etc...&lt;/P&gt;&lt;P&gt;- Authentication from Active directory over SSH (not here yet)&lt;/P&gt;&lt;P&gt;- Key files setup&lt;/P&gt;&lt;P&gt;- and the list goes on and on (this includes what I have captured and the stuff I am sure I missed)...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe some of you out there have been through similar exercises.&amp;nbsp; I would appreciate any pointers to a cook book, best practice or even "Hey, be sure to look out for this gotcha"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks to all for any help you can provide.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jul 2014 15:29:07 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/cookbook-for-transition-to-secure-protocols/m-p/6553842#M46168</guid>
      <dc:creator>Mike R Smith</dc:creator>
      <dc:date>2014-07-25T15:29:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cookbook for transition to secure protocols?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/cookbook-for-transition-to-secure-protocols/m-p/6553848#M46169</link>
      <description>TCPIP 5.7 Eco 4</description>
      <pubDate>Fri, 25 Jul 2014 15:30:26 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/cookbook-for-transition-to-secure-protocols/m-p/6553848#M46169</guid>
      <dc:creator>Mike R Smith</dc:creator>
      <dc:date>2014-07-25T15:30:26Z</dc:date>
    </item>
    <item>
      <title>Re: Cookbook for transition to secure protocols?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/cookbook-for-transition-to-secure-protocols/m-p/6554420#M46170</link>
      <description />
      <pubDate>Fri, 25 Jul 2014 18:20:42 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/cookbook-for-transition-to-secure-protocols/m-p/6554420#M46170</guid>
      <dc:creator>Steven Schweda</dc:creator>
      <dc:date>2014-07-25T18:20:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cookbook for transition to secure protocols?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/cookbook-for-transition-to-secure-protocols/m-p/6554446#M46171</link>
      <description>&lt;P&gt;Thanks for the tips Steven.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In answer to the question you put forth:&lt;/P&gt;&lt;P&gt;&amp;lt;Communicating with other cluster members, other VMS systems, other&lt;BR /&gt;non-VMS systems, ...?&amp;gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;The answer is yes to all of the above.&amp;nbsp; Our user base is just shy of 10,000 on a typical day so&amp;nbsp;every scenario you mentioned is happening.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jul 2014 18:48:46 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/cookbook-for-transition-to-secure-protocols/m-p/6554446#M46171</guid>
      <dc:creator>Mike R Smith</dc:creator>
      <dc:date>2014-07-25T18:48:46Z</dc:date>
    </item>
    <item>
      <title>Re: Cookbook for transition to secure protocols?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/cookbook-for-transition-to-secure-protocols/m-p/6556392#M46172</link>
      <description>&lt;P&gt;VMS has no support for secure transports for LAN clustering, SMH, DECnet and any related traffic (if present) is usually firewalled to maintain security and privacy. &amp;nbsp; SCS is a wide-open LAN protocol, so you really don't want that mixed with any untrusted LAN devices. &amp;nbsp;&lt;A href="http://labs.hoffmanlabs.com/node/621" target="_blank"&gt;I usually recommend a firewall with VMS here&lt;/A&gt;. &amp;nbsp; (While most folks think of Windows clients in this context, these days even network printers aren't all that trustworthy, either.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Various of the higher-level IP networking packages have SSL/TLS and ssh options available (&lt;A href="http://labs.hoffmanlabs.com/node/1116" target="_blank"&gt;setting up ssh and sftp&lt;/A&gt;), and &lt;A href="http://labs.hoffmanlabs.com/node/1760" target="_blank"&gt;PuTTY has ssh certificate-based login capabilities&lt;/A&gt;&amp;nbsp;- above the level of VMS itself, this is more of a generic IP network security question, too. &amp;nbsp;Put another way, documents on how to secure IP traffic will — more or less — apply to VMS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ssh can accept a command for execution on a remote host, so that can be one way to trigger remote activity. &amp;nbsp; &lt;SPAN&gt;&amp;nbsp;(&lt;/SPAN&gt;&lt;A href="http://h71000.www7.hp.com/doc/84final/tcprn/tcp_rnpro_004.html" target="_blank"&gt;Some details&lt;/A&gt;&lt;SPAN&gt;) &amp;nbsp; &amp;nbsp;&lt;/SPAN&gt;Triggering via a web server and a CGI script is another. &amp;nbsp;(&lt;A href="http://labs.hoffmanlabs.com/node/277" target="_blank"&gt;Apache on VMS can invoke DCL procedures as CGI scripts&lt;/A&gt;, for instance, and these resources can be accessed via SSL/TLS.) &amp;nbsp; There are (were?) also some distributed process schedulers and job managers around for VMS, too, if you're looking to automate these sorts of activities.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've posted &lt;A href="http://labs.hoffmanlabs.com/node/619" target="_blank"&gt;some general notes from OpenVMS LDAP external authentication&lt;/A&gt;, but I didn't test the certificate-based access path. &amp;nbsp;Would have to dig into the details of getting that to work — configuring and troubleshooting the Open Directory LDAP connection was complex more than I'd expected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jul 2014 21:25:59 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/cookbook-for-transition-to-secure-protocols/m-p/6556392#M46172</guid>
      <dc:creator>Hoff</dc:creator>
      <dc:date>2014-07-28T21:25:59Z</dc:date>
    </item>
  </channel>
</rss>

