Re: Pyro4 and connection authentication

Irmen de Jong <[email protected]>
Newsgroups gmane.comp.python.pyro
Message-ID <[email protected]>
On 25 jun 2012, at 03:17, Hilary Oliver wrote:

> Hi Irmen,
> 
> Firstly, thanks for your excellent work - Pyro3 has served us well for several years now in the cylc suite engine (http://hjoliver.github.com/cylc/). 

Great, I am glad you like it and that Pyro has been useful to you!

> Planning for the future, I figure we'll need to upgrade to Pyro4 at some point, but unfortunately the operation of cylc currently depends quite critically on the "connection authentication" mechanism of Pyro3 (or at least it will do, from the upcoming release onward). I note you posted to pyro-core about a year ago that this was on the To Do list for Pyro4.  Is that still the case?

More or less... the To do list is available in the subversion repository (TODO.txt). The item is still on that list. However, I wanted to build it upon a new way of 'hooking' into the server.

That new hook methodology has never been implemented thus far, and you're one of the very few that actually inquires about the authentication feature.

Thus! I would like to ask you a few questions about it :-)

Is it important to you that Pyro itself provides the feature? (or can you move to a different security layer such as SSH)? 
What are your experiences with the implementation as it is in Pyro3?
Do you think the API should be the same (or at least similar)?
Have you looked at the HMAC key that Pyro4 can require for 'authorized' connections? How useful (or silly) is that for your situation?

>  If so, do you have a rough estimate of when this feature might be available in Pyro4? 

Sorry, no, but you've sparked my interest again. I may well consider implementing it without the 'nice hook mechanism' that I talked about earlier, just to make it available in Pyro4.

To be honest, the other uses for the server hook mechanism are obscure at best right now.


Greetings,

Irmen de Jong


------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.