Re: [ClusterLabs] corosync 2.4.4 version provide secure the communication by default

2023-03-27 Thread Ken Gaillot
On Sun, 2023-03-26 at 10:42 +, S Sathish S via Users wrote: > Hi Jan, > > In Corosync which all scenario it send cpg message and what is impact > if we are not secure communication. Pacemaker uses CPG extensively to communicate between nodes. Sensitive information such as the entire CIB is

Re: [ClusterLabs] corosync 2.4.4 version provide secure the communication by default

2023-03-27 Thread Jan Friesse
On 26/03/2023 12:42, S Sathish S wrote: Hi Jan, Hi, In Corosync which all scenario it send cpg message and what is impact if we are not secure communication. It really depends of what services are used, but generally speaking corosync without cpg is not super useful so I guess cpg is

Re: [ClusterLabs] corosync 2.4.4 version provide secure the communication by default

2023-03-26 Thread S Sathish S via Users
Hi Jan, In Corosync which all scenario it send cpg message and what is impact if we are not secure communication. 1. Any outsider attacker can manipulate the system using unencrypted communication. 2. Corosync used for heartbeat communication in that we don't have any sensitive data

Re: [ClusterLabs] corosync 2.4.4 version provide secure the communication by default

2023-01-23 Thread Jan Friesse
Honza Thanks and Regards, S Sathish S -Original Message- From: Jan Friesse Sent: 23 January 2023 14:50 To: Cluster Labs - All topics related to open-source clustering welcomed Cc: S Sathish S Subject: Re: [ClusterLabs] corosync 2.4.4 version provide secure the communication by default

Re: [ClusterLabs] corosync 2.4.4 version provide secure the communication by default

2023-01-23 Thread S Sathish S via Users
nd Regards, S Sathish S -Original Message- From: Jan Friesse Sent: 23 January 2023 14:50 To: Cluster Labs - All topics related to open-source clustering welcomed Cc: S Sathish S Subject: Re: [ClusterLabs] corosync 2.4.4 version provide secure the communication by default Hi, On 23/

Re: [ClusterLabs] corosync 2.4.4 version provide secure the communication by default

2023-01-23 Thread Jan Friesse
Hi, On 23/01/2023 01:37, S Sathish S via Users wrote: Hi Team, corosync 2.4.4 version provide mechanism to secure the communication path between nodes of a cluster by default? bcoz in our configuration secauth is turned off but still communication occur is encrypted. Note : Capture tcpdump

[ClusterLabs] corosync 2.4.4 version provide secure the communication by default

2023-01-22 Thread S Sathish S via Users
Hi Team, corosync 2.4.4 version provide mechanism to secure the communication path between nodes of a cluster by default? bcoz in our configuration secauth is turned off but still communication occur is encrypted. Note : Capture tcpdump for port 5405 and I can see that the data is already