Orenosp Secure Reverse Proxy

New:Orenosp Version 2 with OpenID, Single-Sign-On Support: Beta version is now available

[To Japanese page]

Orenosp is an HTTP/HTTPS secure reverse proxy, load-balancer and secure port forwarder that runs on Windows platforms (NT, 2000, XP and 2003), Linux x86, and Mac OS X.

If you need a simple and easy way of protecting remote desktop over a public network, please look at gtOrenoPC instead.

Introduction

With broadband prices dropping and becoming ubiquitous, the demand for remote access continues to grow even in SOHOs and households. However, most current products for home routers/firewalls, PC applications and web-enabled electronics don't offer secure remote access.

Orenosp protects and enables secure remote access of the following applications and servers with use of integrated security facility (user authentication, access authorization, access logging, and channel encryption):

Orenosp operates as an SSL reverse proxy and SSL port forwarder. More specifically, you close all TCP ports except for a single TCP port and Orenosp accepts all connections on that port, does security checks and various transformations and finally forwards them to web servers, web appliances and PCs in the LAN. You only need a single global IP address to make several PCs within the LAN available for remote access.
See diagrams:

Note: ordinary (forward) proxies are deployed at client side, but a reverse proxy is deployed at server side.

You can also use Orenosp to build a small-scale SSL VPN gateway that enables secure and low cost remote access to your small office. See Secure Port Forwarding.

Objectives

At the server side on the Internet, Orenosp serves three objectives.

Protect Web Servers in Your LAN

Distribute Workload among Multiple Web Servers

Control Internet Resource Usage by Your Web Servers

Other Features

Orenosp uses OpenSSL Toolkit developed by the OpenSSL Project (http://www.openssl.org/).

Features Not Planned

Usage Examples

Latest Version

Orenosp Secure Reverse Proxy is released as a shareware product from Orenosv.com.

Version history

development versions are here
early alpha versions are here

Required software other than Orenosp

These are optional related products/components. To handle a server digital certificate you might have to introduce additional software. If you intend to use a self-issued certificate only, you can use the certificate-generator program included in Orenosp package.
  1. When using orenosp-provided test certificate
    [Intended only for testing within your LAN]
    No additional software required.
  2. When using a self-issued certificate
    a) gencert.exe included in Orenosp.
    No additional software required.
    a) Kousec Server Certificate Manager - Basic Edition
    This software is a server certificate lifecycle management tool for both self-issued certificates (private CA built-in) and commercial CA's certificates.
    c) openssl.exe from Openssl pacakge
    For sophisticated configurations only.
    You can download openssl.exe utility program of Openssl 0.9.7b from here.
  3. When using a certificate signed by a commercial CA
    [Recommended for security]
    a) Kousec Server Certificate Manager - Basic Edition
    This software is a server certificate lifecycle management tool for both self-issued certificates (private CA built-in) and commercial CA's certificates.
    b) Openssl utility program (openssl.exe)
    Procedure to obtain a certificate is similar to that Apache+mod_ssl case. We have instructions document for Orenosp.

Documents

readme_en.txt - how to install
guide_en.txt - Orenosp User's Guide
certmemo_en.txt - Instructions on operating CA using Openssl
certvendor_en.html - Using Commercial SSL Certificates in Orenosp
sproxy_full.txt - configuration parameters file
ha_cluster.txt - HA-clustering Orenosp on Linux
webdav_en.txt - Notes on reverse-proxying WebDAV
Notes on IIS Basic and NTLM Authentication Schemes
tunnel/ssltunnel_en.txt - SSL Tunneling Guide
tunnel/sampleconfig_en.txt - Practisal Sample Configuration
changes.txt - detailed change description

System Requirements

Discussion forum

The phpBB-based discussion forums for Orenosv.com products are available.
Orenosv.com Forums: http://www.orenosv.com/bb/

Logs from the old BBS (Read-only): http://www.orenosv.com/oldbbs_en/

Customization and Commercial Licensing

are available. details.

Copyright

Please see copyright.txt.

 


Kousec Software, Inc.