[Bug 595011] Review Request: <sshdfilter> <Filter for SSH ports>

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Please do not reply directly to this email. All additional
comments should be made in the comments box of this bug.


https://bugzilla.redhat.com/show_bug.cgi?id=595011

--- Comment #3 from David Highley <dhighley@xxxxxxxxxxxxxxxxxxxxxxx> 2010-05-22 19:18:57 EDT ---
Rafael,

It is the first submission and I did create a Fedora account and subscribe to
the required mailing lists. I did try and read the copious packaging guides. I
understand that I would become the maintainer of this package. My one concern
in that is having access to test on unreleased Fedora versions. I have made all
the suggested corrections to the spec file, with the exception of the last one. 

I know of no way to cleanly deal with iptables and rsyslog. The script needs to
read what is being logged to determine if port scans and ssh connections are
being made. It needs to have a chain defined to drop block rules into the
iptables rules. I know of no other way of accomplishing this, I'm open for
ideas and felt that this was an issue as well for general distribution. There
are issues with iptables as a restart will empty the block chain. But I thought
the benefits out weighed the issues. I did add some more checking to deal with
updating so that the rsyslog.conf and iptables files were not modified if they
all ready had the needed modifications.

Thank you for the suggestion on cleaning up the spec file.

-- 
Configure bugmail: https://bugzilla.redhat.com/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are on the CC list for the bug.
_______________________________________________
package-review mailing list
package-review@xxxxxxxxxxxxxxxxxxxxxxx
https://admin.fedoraproject.org/mailman/listinfo/package-review

[Index of Archives]     [Fedora Legacy]     [Fedora Desktop]     [Fedora SELinux]     [Yosemite News]     [KDE Users]     [Fedora Tools]