cfservd 2.0.4 and admit...

From: Juha Ylitalo
Subject: cfservd 2.0.4 and admit...
Date: 17 Jan 2003 10:02:39 +0200

I just found out that I have some serious problem in my cfservd.conf,
because my passwd, shadow, ... replication with cfengine seems to allow
anyone to copy central passwd, group, ... which should not be the case.
This is probably user error in a sense that I've manage to mess
something up in my config files and as such, any help on getting access
tightened up would be appreciated.

cfservd 2.0.4 running on RedHat Linux 7.3
cfagent 2.0.4 running on RedHat Linux 7.3/8.0
boat is
other hosts that were able to copy stuff (even though they are NOT
supposed to be able to do it) were and

cfserv.conf has following kind of settings:
[begin quote]

  domain = ( )
  AllowConnectionsFrom = ( )
  DynamicAddresses = ( )
  TrustKeysFrom = ( )

admit:   # or grant:

   /var/cfengine/masterfiles/inputs     *
[end of qoute]

Juha Ylitalo       address@hidden           <work e-mail>
+358 40 562 6152  <work www>
"Some tools are used, because its policy, others because they are good."

