Changes between Version 6 and Version 7 of GENIRacksHome/InstageniRacks/AcceptanceTestStatus/IG-ADM-2


Ignore:
Timestamp:
05/16/12 10:27:44 (12 years ago)
Author:
chaos@bbn.com
Comment:

--

Legend:

Unmodified
Added
Removed
Modified
  • GENIRacksHome/InstageniRacks/AcceptanceTestStatus/IG-ADM-2

    v6 v7  
    55''This page is GPO's working page for performing IG-ADM-2.  It is public for informational purposes, but it is not an official status report.  See [wiki:GENIRacksHome/InstageniRacks/AcceptanceTestStatus] for the current status of InstaGENI acceptance tests.''
    66
    7 ''Last substantive edit of this page: 2012-05-15''
     7''Last substantive edit of this page: 2012-05-16''
    88
    99== Page format ==
     
    2020
    2121|| '''Step''' || '''State'''               || '''Date completed''' || '''Tickets'''  || '''Comments'''                                   ||
    22 || 1A         || [[Color(orange,Blocked)]] ||                      || instaticket:18 || blocked on IG verification of root sshd behavior ||
    23 || 1B         ||                           ||                      ||                || ready to test                                    ||
     22|| 1A         || [[Color(green,Pass)]] ||                      || instaticket:18 || question about root SSH access was resolved satisfactorily with no change to rack ||
     23|| 1B         || [[Color(green,Pass)]] ||                      ||                || ||
    2424|| 1C         ||                           ||                      ||                || ready to test                                    ||
    2525|| 2A         ||                           ||                      ||                || ready to test                                    ||
     
    144144 * Login does not succeed via any unencrypted login protocol
    145145
     146==== Results of testing: 2012-05-16 ====
     147
     148Note: this isn't a penetration test.  I'm just looking for known unencrypted login protocols on public networks.  On FreeBSD, `sockstat -lL46` shows IPv4 and IPv6 listeners on non-loopback networks.
     149
     150I found the following listeners, none of which are problematic for our purposes here:
     151{{{
     152httpd
     153sshd
     154inetd (serving the flashpolicy service for Flack)
     155sslxmlrpc_server.py (emulab)
     156sdcollectd (emulab)
     157capserver (emulab)
     158tmcd (emulab)
     159bootinfo (emulab)
     160dhcpd
     161sendmail
     162pubsubd (emulab)
     163mfrisbeed (emulab)
     164ntpd
     165mountd
     166rpcbind
     167named
     168syslogd
     169}}}
     170
    146171=== Step 1C: verify sudo and sudo logging ===
    147172