|
LTSP Kiosk Introduction
Basic Setup
Additional Features
Advanced Issues |
Man-in-a-middle IssueThe standard LTSP setup uses two insecure protocols:
Although your web kiosks hardly contain any confidential information (as long as you secure the possible LDAP connections) the protocols are open to man-in-a-middle attacks. Here, the attacker would set up a LTSP server of his/her own. Instead of connecting to official kiosk server the attacker would distribute a changed kiosk environment of his/her choice. Such a system could log all traffic, e.g. authentication and interesting web content to be used later on for illegal and despicable purposes. Replacing these protocols with SSL-secured equivalents solves both problems:
To achieve this, following arrangements can be made: Updated: 27-MAY-2004
|