× The internal search function is temporarily non-functional. The current search engine is no longer viable and we are researching alternatives.
As a stop gap measure, we are using Google's custom search engine service.
If you know of an easy to use, open source, search engine ... please contact support@midrange.com.


  • Subject: Telnet security risk
  • From: "Steve Bireley" <sbireley@xxxxxxxxx>
  • Date: Tue, 4 Apr 2000 17:52:22 -0400
  • Importance: Normal


If you are using TN5250E with Client Access, Renex BlueZone or another
TN5250E compliant emulator, you can encrypt the password and bypass the
signon screen.  Set QRMTSGN to *Verify on the AS/400 and enter your user ID
and password into the signon bypass dialog in the emulator.  You may have
noticed the IBMRSEED in a trace.  This is a seed value used to setup an
encrypted session to pass the user ID and password from the client to the
server. The user bypasses the signon screen and goes to their configured
menu or the main menu.

The one drawback to this method is the use can sign out and get back to the
sign on screen.  If they enter their login information here, it will be in
the clear.  You can use an exit to prevent users from getting to this screen
and force them to use the encrypted substitute password method.

The best method is to use Secure Port SSL for telnet or FTP.  The SSL
connection is setup prior to any telnet or FTP data being passed between the
client and the user, ensuring that user IDs and passwords are protected.

Steve Bireley
VP Engineering
Renex Corporation
www.renex.com
BlueZone Emulators
BlueZone Free FTP
BlueZone Secure FTP
Secure Web-to-Host

+---
| This is the Midrange System Mailing List!
| To submit a new message, send your mail to MIDRANGE-L@midrange.com.
| To subscribe to this list send email to MIDRANGE-L-SUB@midrange.com.
| To unsubscribe from this list send email to MIDRANGE-L-UNSUB@midrange.com.
| Questions should be directed to the list owner/operator: david@midrange.com
+---

As an Amazon Associate we earn from qualifying purchases.

This thread ...


Follow On AppleNews
Return to Archive home page | Return to MIDRANGE.COM home page

This mailing list archive is Copyright 1997-2024 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact [javascript protected email address].

Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.