I've worked for two stock exchanges, I've done infosec for several banks and currently work in a mission critical environment where a large portion of my job is infosec and there is a fairly high probability if I can set the time aside that I will get a CISP cert this year. None of my production servers except for my spacewalk servers are in a isolated vlan which has outbound internet access that is only to natted private IPs. Furthermore when I worked for the stock exchanges our satellite servers went through a squid proxy which limited them to specific URI's and virus scanned all traffic. so I really do understand security but again I'm failing to understand the requirement and even so the whole adding a vhost to the spacewalk server is superfluous and in the case of spacewalk may cause problems. If some one can give a full explanation of the specific security concerns and requirements I can suggest several ranging from simple to more elaborate methods for handling them which have been tested and follow best practices appropriate to the environment. By the way rsync won't work with the spacewalk repos you need to use wget recursively "-r" instead Sent from my BlackBerry 10 smartphone.
I have to agree with Joe here. I am not overly security paranoid, but I’d plan to lock down the OS deployment/patch services for 90% of the servers in my company too – whether or not I had a gov’t contract to protect. Also, I am not finding this a “complicated solution.” After working for a banking system, this is comparatively trivial.
Brian
From: [email protected] [mailto:[email protected]] On Behalf Of [email protected]
Wow you guys do like complicated solutions why not just put the repo in a subdirectory of /pub off the docroot spacewalk doesn't password protect that directly off the webserver for just such uses. Just to be clear what repos precisely are you intending to mirror? Server, client, EPEL or what?
Sent from my BlackBerry 10 smartphone.
Also here is another one. if you want to use nfs as well.
—Joe
| |||
_______________________________________________ Spacewalk-list mailing list [email protected] https://www.redhat.com/mailman/listinfo/spacewalk-list
_______________________________________________ Spacewalk-list mailing list [email protected] https://www.redhat.com/mailman/listinfo/spacewalk-list
