Re: enable/disable features in running configuration

Patrick Schaaf <[email protected]>
Newsgroups gmane.linux.keepalived.devel
Message-ID <CAJ26g5RXaTV7d_5Jf+MEEXL2Y-=kak4WS31A5zRaT1NLtSZvcA@mail.gmail.com>
Am 02.05.2015 18:24 schrieb "Alexandre Cassen" <[email protected]>:
>
> What is great with CLI/VTY, IMHO, is the fact that client to access is
really simple and widely supported on every OS (telnet).

Hi,

I hope telnet (TCP on localhost) will not be the only alternative. Unix
domain sockets would be preferred. For TCP, do you tack on some kind of ad
hoc authentication? I think keepalived is quite often deployed on hosts
that also run internet facing non-root processes (think apache), and a
nonauthenticated TCP interface would open a path for a hacked non-root
apache process to command the root-run keepalived process.

best regards
  Patrick

------------------------------------------------------------------------------
One dashboard for servers and applications across Physical-Virtual-Cloud 
Widest out-of-the-box monitoring support with 50+ applications
Performance metrics, stats and reports that give you Actionable Insights
Deep dive visibility with transaction tracing using APM Insight.
http://ad.doubleclick.net/ddm/clk/290420510;117567292;y

_______________________________________________
Keepalived-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/keepalived-devel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.