EPICS Controls Argonne National Laboratory

Experimental Physics and
Industrial Control System

1994  <19951996  1997  1998  1999  2000  2001  2002  2003  2004  2005  2006  2007  2008  2009  2010  2011  2012  2013  2014  2015  2016  2017  2018  2019  2020  2021  2022  2023  2024  Index 1994  <19951996  1997  1998  1999  2000  2001  2002  2003  2004  2005  2006  2007  2008  2009  2010  2011  2012  2013  2014  2015  2016  2017  2018  2019  2020  2021  2022  2023  2024 
<== Date ==> <== Thread ==>

Subject: Re: Making releases
From: Tony Cox - (415)926-3105 <[email protected]>
Date: Mon, 13 Feb 1995 10:23:32 PST
Alan writes:-

>Bob:
>
>I suggest we use pgp encryption for releases.  Pass phrases can be handled
>over the landline or some other reasonably secure medium.  We can select
>one pass-phrase per release or one per year to make it easier.  Only the
>1-2 people per site who actually get and install releases need to know
>this access key.

I think this is too lax. With all the EPICS sites, this pass phrase will
become an open secret.

Better to encrypt the distributions with the public keys of people who have
signed the EPICS collaborators agreements. The corresponding private keys
for decryption are far less likely to be given away, and even if the
private keys are stolen the `keyrings' are useless without a private
passphrase.

Note that this doesn't mean that a separate encrypted versions need be
generated for each user. PGP uses a two-step encryption algorithm. The data 
is encoded with IDEA, and it is the IDEA session key which is then further
encrypted with the intended recipients public keys. For each intended
recipient, this adds only around 1000 bytes to the total size of the
distribution. Encrypting for 50 intended recipients would seem quite practical.

>
>Pgp is available from MIT free of charge for all US based sites.

PGP is also available (in various international flavours) from sites outside
the US, so that ITAR regulations need not be violated. A list of international
distributions sites is posted regularly to alt.security.pgp.  

Tony Cox

--------------------------------------------------------------------------------
Dr Anthony D Cox
Computer Systems Specialist
Stanford Synchrotron Radiation Laboratory
Stanford Linear Accelerator Center
MS 69, Box 4349
Stanford CA 94305
[email protected]
--------------------------------------------------------------------------------

Navigate by Date:
Prev: LeCroy 1131 Jeffrey Gross
Next: Re: EPICS on the Alpha 415
Index: 1994  <19951996  1997  1998  1999  2000  2001  2002  2003  2004  2005  2006  2007  2008  2009  2010  2011  2012  2013  2014  2015  2016  2017  2018  2019  2020  2021  2022  2023  2024 
Navigate by Thread:
Prev: Re: Making releases Alan K Biocca
Next: Re: Making releases Ian Smith
Index: 1994  <19951996  1997  1998  1999  2000  2001  2002  2003  2004  2005  2006  2007  2008  2009  2010  2011  2012  2013  2014  2015  2016  2017  2018  2019  2020  2021  2022  2023  2024 
ANJ, 10 Aug 2010 Valid HTML 4.01! · Home · News · About · Base · Modules · Extensions · Distributions · Download ·
· Search · EPICS V4 · IRMIS · Talk · Bugs · Documents · Links · Licensing ·