cacert-sysadm AT lists.cacert.org
Subject: CAcert System Admins discussion list
List archive
- From: Mario Lipinski <mario AT cacert.org>
- To: Wytze van der Raay <wytze AT cacert.org>
- Cc: cacert-sysadm AT lists.cacert.org, jandd AT cacert.org
- Subject: Re: Outbound fire-walling for CAcert infrastructure
- Date: Sun, 08 Jul 2012 03:35:48 -0700
- Organization: CAcert (Infrastructure Team Leader, Organisation Assurer, Arbitrator / Case Manager)
Thanks for pointing this out. It would be interesting if that would work
together with lxc - the firewall is on the host and the containers are
somehow separated from the kernel.
This would indeed solve the problem for package upgrades and installations.
However, another thing on the wishlist were updates through web
applications (like Drupal or Wordpress) or usage of external feeds. This
would still have to be done individually then.
Mario
Am 08.07.2012 03:24, schrieb Wytze van der Raay:
> Op 8-7-2012 0:54, Mario Lipinski schreef:
>> today I received a request to disable outbound packet filtering (for a
>> host) within CAcert infrastructure.
>>
>> While I can fully understand the request and personally have not that
>> much concerns with outgoing traffic, This restrictive filtering has
>> tradition at CAcert.
>>
>> What do you think about allowing all outbound traffic for some or all
>> CAcert infrastructure hosts?
>
> Instead of fully "opening the gates" (outbound), you could consider
> adding a firewall rule to allow only root to enjoy this privilege.
> That way a sysadmin will require "sudo" to perform outbound network
> operations exceeding the normal firewall rules. Usually this is to
> install software, which requires sudo privileges anyway, so no extra
> burden is introduced.
> In iptables language you can do this with something like:
>
> iptables -A OUTPUT -m owner --uid-owner 0 -j ACCEPT
>
> Regards,
> -- wytze
>
--
Mit freundlichen Grüßen / Best regards
Mario Lipinski
Infrastructure Team Leader, E-Mail:
mario AT cacert.org
Organisation Assurer (Germany), Internet: http://www.cacert.org
Arbitrator / Case Manager
CAcert
Support CAcert: http://www.cacert.org/index.php?id=13
http://wiki.cacert.org/wiki/HelpingCAcert
Attachment:
smime.p7s
Description: S/MIME Kryptografische Unterschrift
- Outbound fire-walling for CAcert infrastructure, Mario Lipinski, 07/07/2012
- Re: Outbound fire-walling for CAcert infrastructure, Jan Dittberner, 07/08/2012
- Re: Outbound fire-walling for CAcert infrastructure, Mario Lipinski, 07/08/2012
- Re: Outbound fire-walling for CAcert infrastructure, Ian G, 07/08/2012
- Re: Outbound fire-walling for CAcert infrastructure, Mario Lipinski, 07/08/2012
- Re: Outbound fire-walling for CAcert infrastructure, Wytze van der Raay, 07/08/2012
- Re: Outbound fire-walling for CAcert infrastructure, Mario Lipinski, 07/08/2012
- Re: Outbound fire-walling for CAcert infrastructure, David McIlwraith, 07/09/2012
- Re: Outbound fire-walling for CAcert infrastructure, Mario Lipinski, 07/08/2012
- Re: Outbound fire-walling for CAcert infrastructure, Jan Dittberner, 07/08/2012
Archive powered by MHonArc 2.6.16.