[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: RFS: schooltool



* Tom Hoffman (tom.hoffman@gmail.com) [040907 03:42]:
> The situation is similar to Zope.  It has its own perfectly capable
> web server -- which doesn't do SSL, and runs on a non-standard port by
> default.  In production, most people put it behind Apache and/or Squid
> for various reasons, but you can also just switch the built in server
> to port 80 and use it.
> 
> I'd think whatever the Zope package does would be a good starting point.

i agree that zope is a very nice and powerfull application.
however it is not renowned to be secure. if you hand out a
"unsecure by defaut" application to teachers and secretaries in
schools you *must not* expect that they manage to grasp the
concept of security or even take the practical steps to secure
it.

therefor i would ask to build in or integrate with whatever is
needed for operation. you can rely on us as the distributors to
help along but dont expect your users to fix the app. if you ship
it unsecure by default it will be operated unsecure by defaut.
is that your goal?

practically, to be properly packaged for debian and debian-edu, i
would like to see it operate with ssl by default, so no password
go over the wire (or air, in case of wlan!) in the clear. 



Reply to: