What are some ways of securing an AGI script?
The FastAGI protocol itself has no support for authentication and encryption. You can add authentication at the application level using username and password parameters and verifying those. For encryption you have to revert to a VPN or other network-layer solutions. You could also consider writing a FastAGI ‘proxy’ which sits on the Asterisk server so that the clear unauthenticated text is only transmitted locally. The proxy could then demand authentication/encryption using something like SOAP to the actual end point.
Related Questions
- My firewall starts and restarts fine but if I try shorewall restore, the script fails because none of my shell variables from /etc/shorewall/params are set. Why?
- For securing the objects from movement while on display, what kind of product should I use (also meets conservation standard)?
- What are The Script Archeologist Analysis?