[Zope] scary security questions

mindlace mindlace@imeme.net
Thu, 11 May 2000 18:00:43 -0600


Paul Abrams wrote:

> 2) Is there any way to turn off the manage screens, or set
> them so that they can only be run locally?
> 
> 5 er...3) Is there any way to run the manage screens on a
> different port than the rest of Zope? (i.e. not port 80)
> This would allow us to open/close that port in our firewall
> whenever we needed to access the manage screens remotely,
> or run it over a VPN.

You can use apache and SiteAccess to put all management screens behind
SSL.  You could use SiteAccess to prohibit management access to the
outside world, but that seems silly, since you can already limit logins
for users by domain or IP.

-- 
ethan mindlace fremen        mindlace@imeme.net
zope    -&-     imap email   -&-   mailing list
weave your web with the web at http://imeme.net