EPICS Controls Argonne National Laboratory

Experimental Physics and
Industrial Control System

1994  <19951996  1997  1998  1999  2000  2001  2002  2003  2004  2005  2006  2007  2008  2009  2010  2011  2012  2013  2014  2015  2016  2017  2018  2019  2020  2021  2022  2023  2024  Index 1994  <19951996  1997  1998  1999  2000  2001  2002  2003  2004  2005  2006  2007  2008  2009  2010  2011  2012  2013  2014  2015  2016  2017  2018  2019  2020  2021  2022  2023  2024 
<== Date ==> <== Thread ==>

Subject: Re: Making releases
From: [email protected] (Alan K Biocca)
Date: Tue, 14 Feb 95 08:37:40 PST
> From [email protected]  Tue Feb 14 01:15:15 1995
> 
> At the consortium meeting I suggested distribution via CDs.  This was 
> considered too expensive.  In the light of the new concerns about 
> security,  is this cost now overshadowed by the secure method of 
> distribution that it offers?

Perhaps more important than cost is timeliness - the distribution needs to 
be tweaked too often to produce cdroms.  Who would want to wait for the
'final' tweak, and then wait another N weeks for production and transportation..
We normally get started with an early version and then incorporate the final
later.  This would make for many cdrom versions.  Cdrom is excellent for
infrequent releases of stable products to large audiences.  Our audience is
small - production costs are high until a thousand or more
are molded in a run...


I think we should combine suggestions and provide a three-pronged approach:

1) Use an ftp site with an account/password (this minimizes the number of
   copies of the encrypted tarfiles floating about) AND

2) Encrypt with PGP -c (normal private key encryption), handling keys
   by off-net channels to a minimum set of individuals who have signed
   non-disclosure agreements on the keys and source.

   Remember that the need to keep the key secure is exactly the same as
   keeping the source distribution secure.  If it is relatively difficult
   to get the encrypted distribution the key alone is not useful.
    
3) For those sites who don't or can't handle the encryption, put an
   exebyte in the mail, or setup a special account and password and
   then break it down as soon as they have downloaded.  This is still
   weak since snooping the download is not difficult.
   
     
Alan K Biocca


Navigate by Date:
Prev: ASCII database formats (was Re: EPICS on the Alpha) winans
Next: Re: Making releases winans
Index: 1994  <19951996  1997  1998  1999  2000  2001  2002  2003  2004  2005  2006  2007  2008  2009  2010  2011  2012  2013  2014  2015  2016  2017  2018  2019  2020  2021  2022  2023  2024 
Navigate by Thread:
Prev: Re: Making releases Ian Smith
Next: Re: Making releases winans
Index: 1994  <19951996  1997  1998  1999  2000  2001  2002  2003  2004  2005  2006  2007  2008  2009  2010  2011  2012  2013  2014  2015  2016  2017  2018  2019  2020  2021  2022  2023  2024 
ANJ, 10 Aug 2010 Valid HTML 4.01! · Home · News · About · Base · Modules · Extensions · Distributions · Download ·
· Search · EPICS V4 · IRMIS · Talk · Bugs · Documents · Links · Licensing ·