Bug 124161 - RFE: Addition of trusted services
Summary: RFE: Addition of trusted services
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: Fedora
Classification: Fedora
Component: system-config-securitylevel
Version: rawhide
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Chris Lumens
QA Contact:
URL:
Whiteboard:
: 136800 137259 (view as bug list)
Depends On:
Blocks: 177950
TreeView+ depends on / blocked
 
Reported: 2004-05-24 15:51 UTC by mark
Modified: 2007-11-30 22:10 UTC (History)
5 users (show)

Fixed In Version:
Doc Type: Enhancement
Doc Text:
Clone Of:
Environment:
Last Closed: 2006-10-03 14:44:37 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description mark 2004-05-24 15:51:39 UTC
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.7) Gecko/20040514

Description of problem:
  i think the ability to add additional services to the "trusted
services" box (without modifying the source code) in
system-config-securitylevel would be very useful.

my reasons:

1. i realize i could simply add the port number to "other ports:" but
i have several obscure ports open on my box and i like the protocol
listed next to the port number as it is in the trusted services box
(to quickly remind me what each of them is).

2. when disabling the firewall this would avoid erasing the "other
ports" i had typed in (requiring me to retype them in when the
firewall was re-enabled.

Version-Release number of selected component (if applicable):
system-config-securitylevel-1.3.13-1

How reproducible:
Always

Steps to Reproduce:
1.not applicable
2.
3.
    

Additional info:

Comment 1 Bryan W Clark 2004-09-14 17:39:22 UTC
Paul, I'd like if you ping me when you start to work on this.  Thanks.

Comment 2 Paul Nasrat 2004-10-27 14:41:18 UTC
*** Bug 137259 has been marked as a duplicate of this bug. ***

Comment 3 Paul Nasrat 2004-11-15 14:33:44 UTC
*** Bug 136800 has been marked as a duplicate of this bug. ***

Comment 4 Daniel L. Rall 2004-11-23 17:54:13 UTC
Paul closed bug 138143 with the comment that the fix for this bug will
provide the ability to configure ALL ASPECTS of an iptables-based
firewall.

Even then, it won't provide what was requested in bug 138143 -- the
ability to work with other iptables tools which modify the
configuration file, and the ability to make hand edits, both without
risking blind overwrite of the configuration file by
system-config-firewall.

Comment 5 Daniel L. Rall 2004-11-23 18:03:59 UTC
The end of that last comment should read "system-config-securitylevel"
rather than "system-config-firewall".  And bug 138143 was closed as
WONTFIX.

Comment 6 Paul Nasrat 2004-11-23 21:25:58 UTC
Daniel - feel free to reopen bug # 138143 as an RFE then

Comment 7 Jungshik Shin 2005-07-10 12:56:01 UTC
If turning system-config-securitylevel to a full-fledged ipchains configuration
tool is not feasible in the near future, at least samba needs to be added to the
list of services. To enable samba service with the firewall turned on, multiple
lines need to be added to iptables file, but system-config-samba doesn't add
them automatically and there's no simple way to do that with
system-config-securitylevel.

 

Comment 8 Jungshik Shin 2005-07-10 13:56:25 UTC
I'm not sure how much this will help, but I thought a good first step in
resolving this bug would be to collect a set of rules for a number of services.
In early 2000's (when ipchains were used), I used 'fwup' (http://www.fwup.org)
with a great number of preconfigured services. It's never been updated to
iptables, but still its list of services and ports to open should be of some use
here.


Comment 9 Chris Lumens 2006-10-03 14:44:37 UTC
It's true that system-config-securitylevel is supposed to be more simple than a
full-fledged firewall config tool.  However I have made a variety of
improvements that should take care of this issue.  First, the firewall can be
disabled without forgetting the config, which takes care of that concern. 
Second, you can enter the port by descriptive name now and see the names when
you reload the config.  Finally, samba is now supported as a checkbox to take c
are of Jungshik's concern.


Note You need to log in before you can comment on or make changes to this bug.