| Summary: | add matahari to trusted services list in firewall in fedora | ||
|---|---|---|---|
| Product: | [Retired] Matahari | Reporter: | Steven Dake <sdake> |
| Component: | matahari | Assignee: | Zane Bitter <zbitter> |
| Status: | CLOSED WONTFIX | QA Contact: | Dave Johnson <dajohnso> |
| Severity: | unspecified | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | unspecified | CC: | matahari-maint, ovasik, rbryant, whayutin, zbitter |
| Target Milestone: | --- | ||
| Target Release: | 0.7 | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2012-07-17 12:30:15 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
|
Description
Steven Dake
2011-07-19 18:13:08 UTC
Do we need to register the port with the IANA to get it in the /etc/services file? That seems the obvious way to go about it. Yep, please follow the official IANA registration process from http://www.iana.org/go/draft-ietf-tsvwg-iana-ports (or the final version of the document, once available). Port 49000 has been assigned to matahari by the IANA: https://fedorahosted.org/pipermail/matahari/2011-August/001767.html (In reply to comment #0) > Description of problem: > Configuring the firewall in fedora without a trusted services entry in the > system-config-firewall tool is difficult lokkit -p 49000:tcp Is all you need to do to open the port on the firewall. We should however support something like: lokkit -s matahari Now that we have an official iana port. However, I do not think that this port should be open by default on all Fedora systems. The security model with QMF is _lax by default_ so opening this port would be a security risk. So we'll focus this bug instead on getting port 49000 added to /etc/services so that lokkit -s matahari will work I will sync /etc/services with IANA in Fedora Rawhide soon... As discussed above, we don't wish to open the firewall port by default. The better way to connect to a remote box is to configure it to use broker federation to a trusted server. The port registration is present in /etc/services in Fedora Rawhide, setup-2.8.43-1.fc17 |