pcp
[Top] [All Lists]

Re: pcp Digest, Vol 44, Issue 9

To: pcp@xxxxxxxxxxx
Subject: Re: pcp Digest, Vol 44, Issue 9
From: Chandana De Silva <chandana@xxxxxxxxxxxxx>
Date: Tue, 13 Mar 2012 06:56:23 +1100
In-reply-to: <mailman.1.1331571602.108749.pcp@xxxxxxxxxxx>
References: <mailman.1.1331571602.108749.pcp@xxxxxxxxxxx>
Reply-to: chandana@xxxxxxxxxxxxx
> From: "Frank Ch. Eigler" <fche@xxxxxxxxxx>

> Following on from last week's meetings, here are a couple of sketchy
> thoughts about how we can improve pcp security.  Recall that there
> were several different desires:
> 
> - wire level security
> - non-root pmcd / pmda operation 
> - access control for pmdas
> 
> ssh or stunnel or s_client:
> nss or openssl:

> Option #1 may be a reasonable quick hack.

I would think that a variation of option#1 is available even now on *nix
hosts, by using an ssh tunnel, by opening port 44321 to the localhost
only, and using ssh to tunnel to port 44321.

However, any variation of option 1 may be hard to implement on a Windows
system.

Chandana

<Prev in Thread] Current Thread [Next in Thread>
  • Re: pcp Digest, Vol 44, Issue 9, Chandana De Silva <=