[gollem] How Gollem works...

Chuck Hagenbuch chuck at horde.org
Sat Jul 1 08:48:16 PDT 2006


Quoting Chris <cjdl01 at brokensolstice.com>:

> I want to use gollem with ftp, but my biggest concern is undermining
> all my efforts at security.  It does not look like gollem can use sftp.

The ssh2 VFS backend might be what you're looking for.

> My hope is that when a file is uploaded, that it is uploaded via https
> to a temp dir

Right.

> then ftpd connects to the localhost and moves the file
> where it needs to go.

Or however you configure it.

> My fear is that Gollem will upload the file using unencrypted ftp
> directly to the server, broadcasting the username, password and
> contents of the file to any who might be listening.

Gollem can't cause anything to be uploaded; it can only receive an  
upload. Only the browser can initiate an upload.

-chuck

-- 
"we are plastered to the windshield of the bus that is time." - Chris


More information about the gollem mailing list