Re: TCP connections restricted to specific users

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Wed, 16 Apr 2014, Florian Weimer wrote:

Suppose I have a cluster of machines, running an application. The application opens up TCP connections to other machines, without any form of authentication. [...]
Would iptables owner match work here?

You can use it to restrict outgoing connections to addresses and ports where the application is listening. But it would be rather fragile because the restriction would have be enforced at every individual node able to connect to the app.

Is there some way to pass on user information with IPsec?

SELinux can do it with security contexts:
<http://selinuxproject.org/page/NB_Networking#Labeled_IPSec>

--
Pavel Kankovsky aka Peak                          / Jeremiah 9:21        \
"For death is come up into our MS Windows(tm)..." \ 21st century edition /
--
security mailing list
security@xxxxxxxxxxxxxxxxxxxxxxx
https://admin.fedoraproject.org/mailman/listinfo/security





[Index of Archives]     [Fedora Users]     [Fedora Desktop]     [Fedora SELinux]     [Big List of Linux Books]     [Yosemite News]     [KDE Users]     [Coolkey]

  Powered by Linux