Lydia Sobot writes:
> It can also accept commands over a console protocol, many people run
> the server headless and managed by service managers, and I have done
> the same on OpenBSD (but not with the official Minecraft server, but
> forks such as PaperMC), so I actually think we should allocate a user
> and run it with rc.d.

The problem with RCON is it's not a secure protocol. The traffic is
unencrypted, there are no server fingerprints to prevent MITM, the only
form of user authentication is a password that can be sniffed or brute
forced. Minecraft listens on the same address for both RCON and normal
client connections, so the only way to use it remotely securely is by
locking things down with pf. IMO any configuration we could provide
through an rc script would be significantly less secure than just
running the server directly in tmux.

Reply via email to