From: Jason C. <J.L...@lb...> - 2010-02-04 11:27:06
|
Hi, Running vufind through https is a good move but won't protect your connection from vufind to the oracle server. You would have this situation [User] <---- Encrytped ----> [VuFind Server] <---- unencrypted SQL ---> [Oracle Server] If there isn't a standard secure way to talk SQL to an oracle server I would suggest using ssh to create an encrypted tunnel from your vufind machine to your oracle server. Which would give you [User] <---- Encrytped ----> [VuFind Server] <---- encrypted SSH Tunnel containing the SQL ---> [Oracle Server] Regards, Jason Cooper Loughborough University Library Systems Team From: Osullivan L. [mailto:L.O...@sw...] Sent: 04 February 2010 10:20 To: vuf...@li...; vuf...@li... Subject: [VuFind-Tech] Encryption Hi Folks, One of our partner institutions has raised concerns over the security of data passed from its servers to our Vufind server. This may be an installation specific problem as we have three remote ILS / LMS severs to connect to. Does anyone have any ideas for / solution to this problem? Running VuFind under https is a possible solution but I am unsure if this would cover the connection to the Oracle and Sybase sql connections and data. Kind Regards, Luke O'Sullivan Library Systems Officer - Virtual Academic Library South West Wales Higher Education Partnership (SWWHEP) Tel: 01792 602772 Website: www.swwhep.ac.uk<http://www.swwhep.ac.uk/> Ffôn: 01792 602772 Gwefan: www.swwhep.ac.uk<http://www.swwhep.ac.uk/> Check out the new SWWHEP Online GreenGuide at: www.swwhep.ac.uk/en/projects/sustainability<blocked::http://www.swwhep.ac.uk/en/projects/sustainability> |