From: Martin L. <mar...@ma...> - 2001-01-23 03:20:55
|
Fleet Teachout wrote: > > Has anyone here set up SQL-Ledger on a Cobalt RAQ2 server for remote > access? If so, any problems, lessons learned, issues, etc.? not RAQ specific, but here are few ideas for a remote server in general: - SSL is a must for data confidentiality - no (untrusted) users on server with any form of web scripting ability (cgi/perl/php/etc..) - storngly consider using apache suexec feature and creating separate account for sql-ledger i think it would be a good idea to rewrite whole sql-ledger authentication system before putting it into a public server, but for starters even using crypt() instead of plaintext would be a good start.. plaintext is barely suitable on for a system on small trusted network behind firewall but a definite no-no for server with direct Internet connection. -- Martin Lillepuu | E-mail: mar...@ma... | GSM: 051 56 450 |