Re: ftp vs. http servers [was Re: lug-bg: Slackware 9.1]
- Subject: Re: ftp vs. http servers [was Re: lug-bg: Slackware 9.1]
- From: Vesselin Kolev <vlk@xxxxxxxxxxxxxxxxx>
- Date: Tue, 30 Sep 2003 13:23:22 +0300
- Organization: Laboratory of Chemical Physics & Engineering, University of Sofia, Bulgaria
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
>
> Също като rsync: и двете страни имат доста да изчисляват. А разликата
> между FTP (или HTTP) и SFTP в локална мрежа е голяма (поне два пъти,
> дори и ако двата компютъра са сравнително бързи).
Ehe:) Chak 2 pyti.. silno kazano. Ponezhe naposledyk mi se nalozhi da pravia
shema, pri koiato osven cryptiran kanal traibva da ima i TLS login, napravih i
seria testove. Ako iskash moga da ti napravia i zhiva demonstracia.
Ta shemata e slednata. ProFTPD v dva rezhima: TLS i non-TLS.
TLS: Login s X.509 certificate - RSA 2048 bits
TLS: handshake : Key Exchange-RSA-2048 (RSA key from cert.)
TLS: handshake : Authentication-RSA-2048 (RSA key from cert.)
TLS: handshake : Encryption-BlowFish-128 (random generated key)
non-TLS : plain text login
Celta beshe transfer na 120 faila, kato za vzemaneto na vseki fail se izpolzva
login. T.e. login-transfer-logout
Slediat se dva etapa:
1) Skorost na login processa
2) Skorost na obmena na failovete
FTP Server:
CPU : Athlon 900 MHz
RAM: 512 DDR
HDD: Seagate SATA/7200/8MB
OS: Linux Mandrake 9.1
FTPD: ProFTPD 1.2.9rc2(TLS patched)
Rezultati:
1) Po pokazatel skorost na login processa - kakto e za ochakvane
pecheli plain text shemata, no samo s 13% pred TLS login (pri CPU
s po-malka taktova chestota razlikata nelineiono narastva zaradi RSA).
Nuzhno e da se znae, che sypostavkata ne e mnogo korektna, zashtoto
kato cialo TLS login processa vkliuichva tri etapa: udostoveriavane,
obmen na kliuch, i nachalo na kodiraneto.
2) Po pokazatel scorost na obmen na fail - razlikata e edna 5%. Vsasnost
tia zavisi ot izpokzvania encryption algorithm.
Beshe napraven opit i sys sftp server, vmesto s ProFTPD. Prezultatite v
sravnenie s ProFTPD sa v ramkite na greshkata na izmervaneto...
Pozdravi
Beco
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.7 (GNU/Linux)
iD8DBQE/eVmh+48lZPXaa+MRAoJyAKCVKdp9oVcqjPw07v/+78qMm61kJgCdG4KG
x1U+eHx62CONMY1E7hLB1oE=
=iVtz
-----END PGP SIGNATURE-----
============================================================================
A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers).
http://www.linux-bulgaria.org - Hosted by Internet Group Ltd. - Stara Zagora
To unsubscribe: http://www.linux-bulgaria.org/public/mail_list.html
============================================================================
|