Re: Pyro4 and connection authentication

Hilary Oliver <[email protected]>
Newsgroups gmane.comp.python.pyro
Message-ID <CAOBnPpKhFhGTPwHSBAR86NaJmongo4=nV0j6VUjk15yCygfJOg@mail.gmail.com>
Hi Irmen,

> The next release (4.15) will contain the sorely needed fix for the threadpool lockup
> problem (and some other minor changes). I will release this first.
> The version after that, 4.16, can be the first to contain a connection authentication
> feature similar to that what Pyro3 has.
> I'm not sure yet what the fate of the HMAC authentication will be.


That is great news, thanks a lot!

Thanks also for correcting my impression of the HMAC authentication
(however, with the key visible in the source code I would still much
prefer Pyro3-style connection authentication).

Finally, I have updated the Pyro footnote on the cylc homepage (and
listed Pyro under the acknowledgments sections too).

cheers,
Hilary


On 27 June 2012 06:30, Irmen de Jong <[email protected]> wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> On 26-6-2012 0:44, Hilary Oliver wrote:
>
>> When I started developing cylc I knew (and still know) next to nothing about
>> networking, but Pyro allowed me to get the required client/server functionality
>> working very quickly and easily in spite of my ignorance :-)
>
> That's great to hear!
>
> And thanks for answering my questions. It helps a lot to consider when and how the
> connection authentication feature can be added to Pyro4.
>
> The next release (4.15) will contain the sorely needed fix for the threadpool lockup
> problem (and some other minor changes). I will release this first.
> The version after that, 4.16, can be the first to contain a connection authentication
> feature similar to that what Pyro3 has.
> I'm not sure yet what the fate of the HMAC authentication will be.
>
>
>>> Have you looked at the HMAC key that Pyro4 can require for 'authorized'
>>> connections? How useful (or silly) is that for your situation?
>>
>> My impression is that this is "less secure" than the Pyro3 connection
>> authentication as the key goes over the wire unencrypted - is that right?  If so,
>> it may still be sufficient as an interim measure
>
> This impression is wrong, the key itself is private and it is only used to construct a
> HMAC digest of the transmitted data. They key is never transmitted.
> Then again, it's only as secure as your source code is (unless you have a clever way
> to provide your program with a secure secret key that's not written in the source code
> - -- Pyro doesn't provide such a feature at this time).
>
> By the way, on http://hjoliver.github.com/cylc/#acknowledgements there's a footnote
> about Pyro4 not being recommended for production use. That statement has been false
> for quite a while now. ;-)
>
>
> Irmen.
>
> -----BEGIN PGP SIGNATURE-----
> Version: GnuPG v1.4.12 (Cygwin)
> Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/
>
> iQEcBAEBAgAGBQJP6f/QAAoJEHC9o7RHFlf2cokH/1yxgwgne702FmUADsY2Nf5c
> 39VBY8Sy7cN6LcUTpTfhlwsFMTM8rDUrjG4MbtMYYmXD9bD753YpUH81kc6XprpG
> 57/84LkfSWkdQf4H3dhjiiJeioPlubFE8GIM1fiErxXYeQJzlYHvmwfGdozZsraP
> gO0ctd0SDphuKpM1hCACVXnYwd2R2Yo0W+yb8Bu83BmuOYmKDo1sUdE2LxIp0X83
> IocR3dfoaUkWHb6+q+DxzF8jl9MsFpUAiakandD6kTVy5rLfQ68C+oeU5lu613R/
> xtW3Q2J9ruu555hVQNBvoykZBgDHdFNbAdnhwcD/Vxvg7ugdWJ0Wl9IgSWAyRGU=
> =6TuH
> -----END PGP SIGNATURE-----
>
> ------------------------------------------------------------------------------
> Live Security Virtual Conference
> Exclusive live event will cover all the ways today's security and
> threat landscape has changed and how IT managers can respond. Discussions
> will include endpoint security, mobile security and the latest in malware
> threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
> _______________________________________________
> Pyro-core mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/pyro-core

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.