[Bug 1379567] Re: maas-proxy is an open proxy with no ACLs; it should add networks automatically

2016-04-01 Thread Andres Rodriguez
maas-proxy was never meant to be used on internet facing scenarios. The maas-proxy configuration status that MAAS doesn't automatically add networks and that one that it would. This will be done for 2.0 and wont be done for any earlier release. MAAS documentation will be updated to state this

[Bug 1379567] Re: maas-proxy is an open proxy with no ACLs; it should add networks automatically

2016-04-01 Thread LaMont Jones
For the 1.9 backport of this fix, rather than introduce a schema migration (as done for 2.0), we'll simply allow all known subnets to use the proxy, with a note in the proxy config to disable unwanted subnets with iptables. ** Also affects: maas (Ubuntu Trusty) Importance: Undecided

[Bug 1379567] Re: maas-proxy is an open proxy with no ACLs; it should add networks automatically

2016-03-31 Thread Jeff Lane
** Tags added: hwcert-server -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to maas in Ubuntu. https://bugs.launchpad.net/bugs/1379567 Title: maas-proxy is an open proxy with no ACLs; it should add networks automatically To manage

[Bug 1379567] Re: maas-proxy is an open proxy with no ACLs; it should add networks automatically

2016-03-31 Thread Jeff Lane
This also needs a 1.9 target as well. I just discovered this while investigating proxy issues on a customer MAAS server and found that they have an open maas proxy with a ton of external connections to it :/ -- You received this bug notification because you are a member of Ubuntu Server Team,

[Bug 1379567] Re: maas-proxy is an open proxy with no ACLs; it should add networks automatically

2016-03-29 Thread LaMont Jones
** Branch linked: lp:~lamont/maas/create-maas-proxy.conf-packaging -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to maas in Ubuntu. https://bugs.launchpad.net/bugs/1379567 Title: maas-proxy is an open proxy with no ACLs; it should

[Bug 1379567] Re: maas-proxy is an open proxy with no ACLs; it should add networks automatically

2016-03-24 Thread Andres Rodriguez
** Changed in: maas Status: Triaged => In Progress -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to maas in Ubuntu. https://bugs.launchpad.net/bugs/1379567 Title: maas-proxy is an open proxy with no ACLs; it should add

[Bug 1379567] Re: maas-proxy is an open proxy with no ACLs; it should add networks automatically

2016-03-23 Thread LaMont Jones
** Changed in: maas Assignee: (unassigned) => LaMont Jones (lamont) -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to maas in Ubuntu. https://bugs.launchpad.net/bugs/1379567 Title: maas-proxy is an open proxy with no ACLs; it

[Bug 1379567] Re: maas-proxy is an open proxy with no ACLs; it should add networks automatically

2016-03-09 Thread Mike Pontillo
I agree with the concerns about documentation. Currently, maas-proxy is an optional package which does not depend on the MAAS region server (or any other MAAS component). It's analogous to squid-deb-proxy. The squid-deb-proxy approach to security is to ship (in an autogenerated/ directory, which

[Bug 1379567] Re: maas-proxy is an open proxy with no ACLs; it should add networks automatically

2016-03-09 Thread Jay R. Wren
I'm disappointed that maas being an open proxy isn't mentioned anywhere in the documentation, that I could find. It should be mentioned in big bold red letters, maybe blink or marquee. The, "not designed to be run on the internet" is fine, but it should be well documented and so should the

[Bug 1379567] Re: maas-proxy is an open proxy with no ACLs; it should add networks automatically

2016-03-09 Thread Mike Pontillo
I've seen users complain that when we change this file it gets overwritten automatically. (I guess we should also move it to /var, if we're going to be automatically generating the configuration.) Should every network MAAS knows about be included in the allow list? Or is finer control needed? --

[Bug 1379567] Re: maas-proxy is an open proxy with no ACLs; it should add networks automatically

2016-03-09 Thread Mike Pontillo
s/when we change this/when they change that/ -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to maas in Ubuntu. https://bugs.launchpad.net/bugs/1379567 Title: maas-proxy is an open proxy with no ACLs; it should add networks

[Bug 1379567] Re: maas-proxy is an open proxy with no ACLs; it should add networks automatically

2016-03-04 Thread Launchpad Bug Tracker
Status changed to 'Confirmed' because the bug affects multiple users. ** Changed in: maas (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to maas in Ubuntu. https://bugs.launchpad.net/bugs/1379567

[Bug 1379567] Re: maas-proxy is an open proxy with no ACLs; it should add networks automatically

2016-02-18 Thread Andres Rodriguez
** Changed in: maas Milestone: 1.9.0 => 2.0.0 ** Changed in: maas Importance: Wishlist => Critical -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to maas in Ubuntu. https://bugs.launchpad.net/bugs/1379567 Title: maas-proxy is