Great Circle Associates Firewalls
(June 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Netscape & Firewalls & Wells Fargo
From: sedayao @ argus . intel . com (Jeffrey C. Sedayao)
Date: Sat, 24 Jun 95 17:07:47 PDT
To: davidm @ dublin . eiffel . com (David Morgan)
Cc: firewalls @ greatcircle . com
In-reply-to: <9506231619 . AA11528 @ dublin . eiffel . com . noname> from "David Morgan" at Jun 23, 95 09:19:59 am

> This may already have been raised but I haven't had much time ot read this
> mail lately.
 
> One of our users is running Netscapoe 1.1 through our firewall.
 
> He is told by his banck that he can do online enquiries.  (Wells Fargo)
 
> He tried to make an enquiry and it failed.
 
> He rang up Wells Fargo and they asked "are you using a firewall"
> "yes" he says
> "well that's the problem." they say.
 
> Does anybody know the truth to this especially as Netscape is proxy aware?

The problem here is that Netscape's Secure Sockets Layer (SSL) protocol
is unable to make it through your firewall.  I have found two ways of
getting around it.

1.  Using Netscape's Proxy Server and configure it to pass SSL.  The
Netscape browser also needs to have its security proxy defined.
2.  Use Socks as the proxy mechanism.  SSL will then pass cleanly
through.

Doing either of the above made the Wells Fargo application work.

I haven't yet tried setting up a plug-gw to Wells Fargo.  This would
probably work, although you would only have SSL access to Wells Fargo
and not to other sites using SSL, like MCI Marketplace.

Wells Fargo's application requires a user to send his Social Security
number and a PIN encrypted over the Internet in order to get bank
balances and latest transactions.

One issue is whether people feel comfortable sending their Social 
Security Number, PIN, and bank balances over the Internet with 40 Bit 
key RSA (remember Marcus Ranum's discussion of this).  The exportable
version of Netscape is the one that is used here.

> -- 
> Regards
>  David Morgan
 
> Interactive Software Engineering        Web: http://www.eiffel.com
> 270 Storke Rd, Suite 7                  ftp: ftp.eiffel.com
> Goleta, CA 93107 USA                    fax: +1 (805) 685-6869
>                                         ph : +1 (805) 685-1006
> Customer support: support @
 eiffel .
 com  email: davidm @
 eiffel .
 com

-- 
Jeff Sedayao
Intel Corporation
sedayao @
 argus .
 intel .
 com


References:
Indexed By Date Previous: Re: Different ways in which Firewalls work, which is more secure ?
From: mulligan @ future . incog . com
Next: Re: Netscape & Firewalls & Wells Fargo
From: mmk @ centrum . is (Magnus Mar Kristinsson)
Indexed By Thread Previous: Re: Netscape & Firewalls & Wells Fargo
From: Amos Shapira <amoss @ cs . huji . ac . il>
Next: Re: Netscape & Firewalls & Wells Fargo
From: mmk @ centrum . is (Magnus Mar Kristinsson)

Google
 
Search Internet Search www.greatcircle.com