Security Basics mailing list archives

Secure FTP


From: aaronr () imcu com
Date: 20 Mar 2007 14:34:41 -0000

Hi all,

Long time reader, first time poster.  Got a quick question that I was =
hoping you all could point me in the right direction...

We have a public facing FTP server that we would like to secure.  We are =
running a MS 2003 Active Directory domain and this box is running on =
Win2k Server.  What is the best way to secure this FTP server?  I've =
tried SFTP, but was just curious as to what else is out there.  Right =
now we are using the builtin IIS FTP server.  Our goal is to provide a =
public FTP server so that clients or customers can dropoff large files =
there without the need to e-mail them.  We aren't too keen on the fact =
that FTP is cleartext and these are domain user/pass going back and =
forth.  Plus, we are a financial institution and any way to encrypt this =
traffic would definitely be a plus....even if we have to provide a link =
to connecting clients so that they can download a free secure FTP =
client.

Any thoughts?

Thanks in advance!
Aaron


Current thread: