cacert-sysadm AT lists.cacert.org
Subject: CAcert System Admins discussion list
List archive
- From: Wytze van der Raay <wytze AT cacert.org>
- To: Mario Lipinski <mario AT cacert.org>
- Cc: cacert-sysadm AT lists.cacert.org, jandd AT cacert.org
- Subject: Re: Outbound fire-walling for CAcert infrastructure
- Date: Sun, 08 Jul 2012 12:24:56 +0200
- Organization: CAcert
Op 8-7-2012 0:54, Mario Lipinski schreef:
> today I received a request to disable outbound packet filtering (for a
> host) within CAcert infrastructure.
>
> While I can fully understand the request and personally have not that
> much concerns with outgoing traffic, This restrictive filtering has
> tradition at CAcert.
>
> What do you think about allowing all outbound traffic for some or all
> CAcert infrastructure hosts?
Instead of fully "opening the gates" (outbound), you could consider
adding a firewall rule to allow only root to enjoy this privilege.
That way a sysadmin will require "sudo" to perform outbound network
operations exceeding the normal firewall rules. Usually this is to
install software, which requires sudo privileges anyway, so no extra
burden is introduced.
In iptables language you can do this with something like:
iptables -A OUTPUT -m owner --uid-owner 0 -j ACCEPT
Regards,
-- wytze
Attachment:
smime.p7s
Description: S/MIME-cryptografische ondertekening
- Outbound fire-walling for CAcert infrastructure, Mario Lipinski, 07/07/2012
- Re: Outbound fire-walling for CAcert infrastructure, Jan Dittberner, 07/08/2012
- Re: Outbound fire-walling for CAcert infrastructure, Mario Lipinski, 07/08/2012
- Re: Outbound fire-walling for CAcert infrastructure, Ian G, 07/08/2012
- Re: Outbound fire-walling for CAcert infrastructure, David McIlwraith, 07/09/2012
- Re: Outbound fire-walling for CAcert infrastructure, Ian G, 07/08/2012
- Re: Outbound fire-walling for CAcert infrastructure, Mario Lipinski, 07/08/2012
- Re: Outbound fire-walling for CAcert infrastructure, Wytze van der Raay, 07/08/2012
- Re: Outbound fire-walling for CAcert infrastructure, Mario Lipinski, 07/08/2012
- Re: Outbound fire-walling for CAcert infrastructure, David McIlwraith, 07/09/2012
- Re: Outbound fire-walling for CAcert infrastructure, Mario Lipinski, 07/08/2012
- Re: Outbound fire-walling for CAcert infrastructure, Jan Dittberner, 07/08/2012
Archive powered by MHonArc 2.6.16.