pcp
[Top] [All Lists]

Re: [pcp] user/group access control question

To: Dave Brolley <brolley@xxxxxxxxxx>, pcp@xxxxxxxxxxx
Subject: Re: [pcp] user/group access control question
From: Ken McDonell <kenj@xxxxxxxxxxxxxxxx>
Date: Thu, 30 Oct 2014 09:33:48 +1100
Delivered-to: pcp@xxxxxxxxxxx
In-reply-to: <54510015.1000405@xxxxxxxxxx>
References: <001f01cff196$66cf3e00$346dba00$@internode.on.net> <544FD6DF.8060206@xxxxxxxxxx> <545027F9.2020205@xxxxxxxxxxxxxxxx> <54510015.1000405@xxxxxxxxxx>
User-agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.2.0
On 30/10/14 01:56, Dave Brolley wrote:
On 10/28/2014 07:34 PM, Ken McDonell wrote:

I have this change in the context of more diagnostics and the
extensions to qa/944, so I'll push the commit if everyone is OK with
that.

OK with me. Thanks.

Dave


This got delayed a little.

It turns out that if you use user or group access controls, and you try to access pmcd via a tcp socket (rather than a unix domain socket) then
(a) if you DO NOT have secure sockets, the access fails, but
(b) if you DO have secure sockets the SASL callback leads us back into libpcp where _if_ you have a console, we get a Username: and Password: prompt.

Case (b) is a non-starter for automated QA, so I've had to make this test conditional, which in turn leads to variant output files being needed.

<Prev in Thread] Current Thread [Next in Thread>