
1 . Web Mgmt Interface

- Use stunnel

Passwords are NOT sent as clear text, a CHAP protocol is used making standard user
authentication safe over http. HOWEVER, the user administration screens that change/set
passwords send md5 encoded passwords over the wire thus giving an attacker
a chance to get the encoded password which could potentially be used (with some special code)
to get an authenticated login.

If this is an issue, configure the server running the Aware webserver to use stunnel to expose an https
port for access and have it pass the packets back to the unencrypted port.

2. Aware "Slave" Agents Communicating

Aware "slave" agents receive their configuration files from the
"master". This is an unencrypted transfer. Also, Aware agents may relay
events back to the "master" via an unencrypted message. If this is a
concern, you should do one or all of the following:

	- Create a separate independent network for monitoring (this could be a VPN)

	- Encrypt traffic network over monitoring network. Common utilities like 
	ssh and stunnel make setting up encrypted tunnels very easy. Alternatively, 
	lower level encrytpion is also possible with IPSEC.







