Great Circle Associates Firewalls
(August 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Web Oriented Mail Clients
From: William McVey <wam @ fedex . com>
Date: Fri, 08 Aug 1997 17:20:30 -0500
To: Bob Dedrick <dedrick @ ans . net>
Cc: dittrich @ cac . washington . edu (Dave Dittrich), firewalls @ GreatCircle . COM

Bob Dedrick wrote:
>The bottom line is still the same, which is that there's no secure
>way to let users use these clients.

It would be entirely possible for an organization to write an 
http-> POP3/IMAP gateway that would tunnel the POP3 and/or IMAP session
over an ssh, IPSec, or SKIP tunnel.  This is exceptionally easy if
you trust your internal net and can simply use a VPN enabled firewall
to tunnel the session over the internet and then let the POP or
IMAP session travel through the organizations internal network.
The http to mail cgi could then be set to be accessed only from an
SSL enabled web server.  This would require the involvement of the
http to mail gateway as well as the firewall administrators, and
perhaps even the mail gateway admin (if they chose to use an ssh
host to host tunnel, as opposed to a gateway to gateway tunnel),
but it is far from impossible.

 -- William

Indexed By Date Previous: checkpoint and nt problem
From: khearn <khearn @ gte . net>
Next: re: Web Oriented Mail Clients
From: JDaggan @ cgsh . com
Indexed By Thread Previous: Re: Web Oriented Mail Clients
From: pomeranz @ netcom . com (Hal Pomeranz)
Next: re: Web Oriented Mail Clients
From: JDaggan @ cgsh . com

Google
 
Search Internet Search www.greatcircle.com