Re: Fedora tcp_wrappers (missing) support for custom acl scripts, aclexec

2015-01-13 Thread Pasi Kärkkäinen
On Mon, Jan 12, 2015 at 10:35:39AM +0200, Pasi Kärkkäinen wrote: > On Mon, Jan 12, 2015 at 09:15:39AM +0100, Petr Lautrbach wrote: > > On 01/11/2015 09:22 PM, Pasi Kärkkäinen wrote: > > > Hello, > > > > > > People who have their names in the Fedora tcp_wrappers changelog added to > > > CC list..

Re: Fedora tcp_wrappers (missing) support for custom acl scripts, aclexec

2015-01-13 Thread Pasi Kärkkäinen
On Mon, Jan 12, 2015 at 05:17:08PM +0100, Lennart Poettering wrote: > On Sun, 11.01.15 21:29, Tomasz Torcz (to...@pipebreaker.pl) wrote: > > > On Sat, Jan 10, 2015 at 12:16:38AM +0200, Pasi Kärkkäinen wrote: > > > Hello, > > > > > > I recently noticed Debian/Ubuntu has had support for "aclexec" i

Re: Fedora tcp_wrappers (missing) support for custom acl scripts, aclexec

2015-01-12 Thread Lennart Poettering
On Sun, 11.01.15 21:29, Tomasz Torcz (to...@pipebreaker.pl) wrote: > On Sat, Jan 10, 2015 at 12:16:38AM +0200, Pasi Kärkkäinen wrote: > > Hello, > > > > I recently noticed Debian/Ubuntu has had support for "aclexec" in > > tcp_wrappers via a custom patch since 2006, > > so you can do this in /et

Re: Fedora tcp_wrappers (missing) support for custom acl scripts, aclexec

2015-01-12 Thread Pasi Kärkkäinen
On Mon, Jan 12, 2015 at 09:15:39AM +0100, Petr Lautrbach wrote: > On 01/11/2015 09:22 PM, Pasi Kärkkäinen wrote: > > Hello, > > > > People who have their names in the Fedora tcp_wrappers changelog added to > > CC list.. > > > > Any comments about the below? Obviously aclexec feature would be use

Re: Fedora tcp_wrappers (missing) support for custom acl scripts, aclexec

2015-01-12 Thread Petr Lautrbach
On 01/11/2015 09:22 PM, Pasi Kärkkäinen wrote: > Hello, > > People who have their names in the Fedora tcp_wrappers changelog added to CC > list.. > > Any comments about the below? Obviously aclexec feature would be useful for > all services using tcpwrappers/libwrap (ftp,telnet,tftp,ident,nfs,

Re: Fedora tcp_wrappers (missing) support for custom acl scripts, aclexec

2015-01-11 Thread Pasi Kärkkäinen
On Sun, Jan 11, 2015 at 09:29:08PM +0100, Tomasz Torcz wrote: > On Sat, Jan 10, 2015 at 12:16:38AM +0200, Pasi Kärkkäinen wrote: > > Hello, > > > > I recently noticed Debian/Ubuntu has had support for "aclexec" in > > tcp_wrappers via a custom patch since 2006, > > so you can do this in /etc/host

Re: Fedora tcp_wrappers (missing) support for custom acl scripts, aclexec

2015-01-11 Thread Tomasz Torcz
On Sat, Jan 10, 2015 at 12:16:38AM +0200, Pasi Kärkkäinen wrote: > Hello, > > I recently noticed Debian/Ubuntu has had support for "aclexec" in > tcp_wrappers via a custom patch since 2006, > so you can do this in /etc/hosts.allow or hosts.deny: > > > What do people feel about that? I'd like to

Re: Fedora tcp_wrappers (missing) support for custom acl scripts, aclexec

2015-01-11 Thread Pasi Kärkkäinen
Hello, People who have their names in the Fedora tcp_wrappers changelog added to CC list.. Any comments about the below? Obviously aclexec feature would be useful for all services using tcpwrappers/libwrap (ftp,telnet,tftp,ident,nfs, and many others), and thus very nice to have. Thanks, -- P

Re: Fedora tcp_wrappers (missing) support for custom acl scripts, aclexec

2015-01-09 Thread Pasi Kärkkäinen
On Sat, Jan 10, 2015 at 12:57:22AM +0200, Pasi Kärkkäinen wrote: > On Fri, Jan 09, 2015 at 11:47:52PM +0100, Michael Stahl wrote: > > On 09.01.2015 23:16, Pasi Kärkkäinen wrote: > > > Hello, > > > > > > I recently noticed Debian/Ubuntu has had support for "aclexec" in > > > tcp_wrappers via a cus

Re: Fedora tcp_wrappers (missing) support for custom acl scripts, aclexec

2015-01-09 Thread Pasi Kärkkäinen
On Fri, Jan 09, 2015 at 11:47:52PM +0100, Michael Stahl wrote: > On 09.01.2015 23:16, Pasi Kärkkäinen wrote: > > Hello, > > > > I recently noticed Debian/Ubuntu has had support for "aclexec" in > > tcp_wrappers via a custom patch since 2006, > > so you can do this in /etc/hosts.allow or hosts.den

Re: Fedora tcp_wrappers (missing) support for custom acl scripts, aclexec

2015-01-09 Thread Michael Stahl
On 09.01.2015 23:16, Pasi Kärkkäinen wrote: > Hello, > > I recently noticed Debian/Ubuntu has had support for "aclexec" in > tcp_wrappers via a custom patch since 2006, > so you can do this in /etc/hosts.allow or hosts.deny: > > sshd: ALL: aclexec /usr/local/bin/sshfilter.sh %a > > if sshfilter

Fedora tcp_wrappers (missing) support for custom acl scripts, aclexec

2015-01-09 Thread Pasi Kärkkäinen
Hello, I recently noticed Debian/Ubuntu has had support for "aclexec" in tcp_wrappers via a custom patch since 2006, so you can do this in /etc/hosts.allow or hosts.deny: sshd: ALL: aclexec /usr/local/bin/sshfilter.sh %a if sshfilter.sh returns true the access is allowed, if sshfilter.sh return