Xen 
 
Home About Xen.org Xen Xen Summit Wiki Mailing List Bug Tracker Xen Downloads
 
   
 

xen-devel

Re: [Xen-devel] [PATCH] vnclisten for HVM vnc

To: Jeremy Katz <katzj@xxxxxxxxxx>
Subject: Re: [Xen-devel] [PATCH] vnclisten for HVM vnc
From: "Daniel P. Berrange" <berrange@xxxxxxxxxx>
Date: Wed, 27 Sep 2006 20:42:02 +0100
Cc: xen-devel <xen-devel@xxxxxxxxxxxxxxxxxxx>
Delivery-date: Wed, 27 Sep 2006 12:42:35 -0700
Envelope-to: www-data@xxxxxxxxxxxxxxxxxx
In-reply-to: <1159385776.16252.17.camel@xxxxxxxxxxxxxxxxxxxxxxxxxx>
List-help: <mailto:xen-devel-request@lists.xensource.com?subject=help>
List-id: Xen developer discussion <xen-devel.lists.xensource.com>
List-post: <mailto:xen-devel@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-devel>, <mailto:xen-devel-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/cgi-bin/mailman/listinfo/xen-devel>, <mailto:xen-devel-request@lists.xensource.com?subject=unsubscribe>
References: <1157216132.2805.4.camel@xxxxxxxxxxxxxx> <1159385776.16252.17.camel@xxxxxxxxxxxxxxxxxxxxxxxxxx>
Reply-to: "Daniel P. Berrange" <berrange@xxxxxxxxxx>
Sender: xen-devel-bounces@xxxxxxxxxxxxxxxxxxx
User-agent: Mutt/1.4.1i
On Wed, Sep 27, 2006 at 03:36:16PM -0400, Jeremy Katz wrote:
> On Sat, 2006-09-02 at 12:55 -0400, Jeremy Katz wrote:
> > Implement a 'vnclisten' option to limit the interface that the VNC
> > server from qemu listens on.  This leaves the default behavior as
> > listening on all interfaces.
> > 
> > Signed-off-by: Jeremy Katz <katzj@xxxxxxxxxx>
> 
> danpb said something about this and it reminded me I never saw any
> feedback.... Bueller? :-)

IMHO, we should only listen on 127.0.0.1  by default - particularly since
the Xen 3.0.3 release isn't going to have password authentication on the
VNC servers yet :-(   It'll be all too easy for someone to turn on VNC
in the guest config & not realize they just opened themselves up to any
person on the network by default. That kind of default insecure behaviour 
is best left in the Windows world 

Dan.
-- 
|=- Red Hat, Engineering, Emerging Technologies, Boston.  +1 978 392 2496 -=|
|=-           Perl modules: http://search.cpan.org/~danberr/              -=|
|=-               Projects: http://freshmeat.net/~danielpb/               -=|
|=-  GnuPG: 7D3B9505   F3C9 553F A1DA 4AC2 5648 23C1 B3DF F742 7D3B 9505  -=| 

_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-devel