[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Xen-devel] [PATCH] libxl: Query VNC listening port through QMP



On Tue, 2012-04-24 at 14:41 +0100, Ian Jackson wrote:
> Ian Campbell writes ("Re: [Xen-devel] [PATCH] libxl: Query VNC listening port 
> through QMP"):
> > I'm tempted to suggest that we remove this support -- having plain text
> > passwords in xenstore (thankfully with perms set somewhat sanely) just
> > doesn't seem like a Good Thing to me...
> 
> It isn't a good thing.  But currently we have the following three
> options:
> 
> (a) allow access to anyone who can reach the vnc server's TCP port;
> 
> (b) make noninteractive invocation of vnc clients (including
>     screenshot utilities, and automatic invocation of the client
>     by xl) impossible;
> 
> (c) put a plaintext password in the config file (or the xl/xm
>     command line) and copy it to xenstore.
> 
> I don't think we should abolish (c) until we have another way of
> avoiding the problems of (a) and (b).

Fair enough.

I should revisit my vnc TLS patches (with client cert support) for 4.3.

Ian.



_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxx
http://lists.xen.org/xen-devel


 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.