[Zope] Major security flaw in Zope 2.3.2

Toby Dickenson tdickenson@geminidataloggers.com
Wed, 06 Jun 2001 15:13:39 +0100


On Wed, 6 Jun 2001 16:02:11 +0200, Ragnar Beer
<rbeer@uni-goettingen.de> wrote:

> (I just wonder why there is a *separate* ZServer with SSL
>capabilities and why SSL isn't simply integrated into the standard
>ZServer. Does anybody know?)

=46or the security concious, ZServer is not quite tough enough to be
exposed to the raw internet. If you have to use something like Apache
as a front-end proxy anyway, then it might as well handle SSL too.



Toby Dickenson
tdickenson@geminidataloggers.com