The only thing I can think of is whether it will confuse the AllowConnectionsFrom and TrustKeysFrom settings as the cfengine connections will probably all show as coming from the ssh server, rather than the cfagent client, and you may have to use AllowMultipleConnectionsFrom to get around that.

Regards,

Marco

Pletan, Ray wrote:
I finally got cfengine working over an ssh tunnel, but . . . If anyone has experience (or just opinions) with this technique, why would I NOT want to use it? I am trying to justify not using it and asking security to open up a firewall port. Thanks,

*/Ray Pletan/*


------------------------------------------------------------------------

_______________________________________________
Help-cfengine mailing list
[email protected]
http://lists.gnu.org/mailman/listinfo/help-cfengine

--
Marco van Beek
==========================================
Supporting Role Ltd / Forget About IT Ltd.
Grove Park Studios,
188-192 Sutton Court Rd,
London, W4 3HR
==========================================
T: 0870 757 2824 / 0870 757 2924
F: 0870 757 2826 / 0870 757 2926
M: 0788 770 3604
E: [EMAIL PROTECTED]
E: [EMAIL PROTECTED]
==========================================


_______________________________________________
Help-cfengine mailing list
[email protected]
http://lists.gnu.org/mailman/listinfo/help-cfengine

Reply via email to