Prev · NextSTR #3736: Allow ACLs based on domain sockets

Status:4 - Pending
Priority:1 - Request for Enhancement, e.g. asking for a feature
Scope:3 - Applies to all machines and operating systems
Subsystem:Scheduler
Summary:Allow ACLs based on domain sockets
Version: -feature
Created By:mike
Assigned To:mike
Fix Version:Unassigned
Update Notification:

Receive EMails Don't Receive EMails


Trouble Report Files:

No files


Trouble Report Dialog:

Name/Time/Date/Text
mike: 11:22 Dec 01, 2010
 
Based on STR #2625 and offline discussions, it would be nice to be able to disallow IP access for things like PUTs to /admin/conf, limiting access instead to the domain sockets.

Currently we always allow access from the loopback interface, which may pose security risks from browser attacks.