Re: cfengine, firewall and security

From: Christopher Browne
Subject: Re: cfengine, firewall and security
Date: Thu, 09 Nov 2000 22:30:48 -0600

On Thu, 09 Nov 2000 11:46:42 +0100, the world broke into rejoicing as
"Patrice GUERLAIS" <address@hidden>  said:
> has anybody ever tried to use cfengine through a firewall without
> compromising security ? I mean, keep the reference server protected
> behind a firewall, and synchronize clients located both inside and
> outside the firewall.

There seems to me to be considerable merit to the idea of using rsync
to distribute the files; that provides two things:

 a) rsync already knows how to do strong authentication using RSA;

 b) rsync can cope well minimizing the traffic required, pushing out
    only those portions of files that have changed.

It would be eminently sensible for cfengine to be used to move into
place the initial authentication information for rsync, and then to
invoke rsync to pull datafiles.
