what exactly is the server secret *for*

"Brian K. Jones" <[email protected]>
Newsgroups gmane.network.up2date.current.devel
Message-ID <1034081886.1540.15.camel@newhotness>
Hello.

It would seem logical that the server secret be used for client access
to the server resources.  However, in practice, this doesn't seem to be
happening.  

The comments in current.conf say:
# server_secret = text to get sha1'd for systemid tokens.
#                 Must be kept secret, and site specific.

First of all, what the h*** does that word "sha1'd" mean?  Can you dumb
that down for me?  Is that a star trek reference or something that I'm
just not geeky enough to get or something? :-)

Second, if this is to be kept secret, why is it essentially in plain
view of everything?  What is at risk by keeping this 'not secret'?  Even
if someone knows the server secret, they still need the server's
RHNS-CA-CERT, no?  Maybe I'm a little confused here.  Did I miss a doc? 

Third, is this secret somehow used in creating the RHNS-CA-CERT?  I
can't think of another reason you'd have to re-register clients after
changing the secret.  

Also, while we're on registration, I don't remember ever seeing a place
that kept track of who has registered with the server.  Is this logged
somewhere along with the activity (what packages were grabbed, and the
like)?  

Thanks.

-- 

Brian K. Jones
System Administrator
Dept. of Computer Science, Princeton University
http://www.linuxlaboratory.org
[email protected]
Voice: (609) 258-6080
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.