pcp
[Top] [All Lists]

Re: [pcp] proc pmda access control changes

To: Nathan Scott <nathans@xxxxxxxxxx>
Subject: Re: [pcp] proc pmda access control changes
From: Ken McDonell <kenj@xxxxxxxxxxxxxxxx>
Date: Thu, 25 Jul 2013 06:14:47 +1000
Cc: PCP Mailing List <pcp@xxxxxxxxxxx>
Delivered-to: pcp@xxxxxxxxxxx
In-reply-to: <1461308559.1266316.1374665942271.JavaMail.root@xxxxxxxxxx>
References: <51EFBB29.1000807@xxxxxxxxxxxxxxxx> <1461308559.1266316.1374665942271.JavaMail.root@xxxxxxxxxx>
User-agent: Mozilla/5.0 (X11; Linux i686; rv:17.0) Gecko/20130623 Thunderbird/17.0.7
On 24/07/13 21:39, Nathan Scott wrote:
...
For remote fetching though (which this test does), SASL authentication
is the only way now.  This is much harder to test (there are so many
different auth mechanisms) - I've started automated SASL testing but
its not generalised yet.  Will get back to you when I have an example,
for now I'd _notrun it.  There is no pmdaproc backdoor, credentials
must be presented ... should we consider adding one for back-compat?
I'd prefer not to, but guess we could go either way - it'd just take
a non-default command line option to disable the checks.

Having gone to the effort of addressing the authentication issues, I'd prefer we leave it as is and do NOT provide a backdoor, and rework the QA ... if as a policy, we don't want to allow remote access to these metrics w/out authentication, then QA does not need to test it.

I'll move onto other things and await your developments ... I'm seeing 20+ failures per host on the first few I've tried this time round, so there are lots of other gophers to smack.

<Prev in Thread] Current Thread [Next in Thread>