X2Go Bug report logs - #354
Make x2goagent listening to TCP connections configurable in x2goserver.conf

version graph

Package: x2goserver; Maintainer for x2goserver is X2Go Developers <x2go-dev@lists.x2go.org>; Source for x2goserver is src:x2goserver.

Reported by: Mike Gabriel <mike.gabriel@das-netzwerkteam.de>

Date: Fri, 6 Dec 2013 11:33:02 UTC

Severity: wishlist

Tags: pending

Fixed in version 4.0.1.10

Done: Mike Gabriel <mike.gabriel@das-netzwerkteam.de>

Bug is archived. No further changes may be made.

Full log


Message #66 received at 354@bugs.x2go.org (full text, mbox, reply):

Received: (at 354) by bugs.x2go.org; 8 Dec 2013 15:13:06 +0000
From n_ingegneri@yahoo.com  Sun Dec  8 16:13:04 2013
X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on
	ymir.das-netzwerkteam.de
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 required=5.0 tests=BAYES_00,FREEMAIL_FROM,
	HTML_MESSAGE,RCVD_IN_DNSWL_NONE,T_DKIM_INVALID,URIBL_BLOCKED autolearn=ham
	version=3.3.2
Received: from nm7-vm0.bullet.mail.ne1.yahoo.com (nm7-vm0.bullet.mail.ne1.yahoo.com [98.138.91.66])
	by ymir (Postfix) with SMTP id 17E525DB1E
	for <354@bugs.x2go.org>; Sun,  8 Dec 2013 16:13:03 +0100 (CET)
Received: from [98.138.101.132] by nm7.bullet.mail.ne1.yahoo.com with NNFMP; 08 Dec 2013 15:13:02 -0000
Received: from [98.138.89.161] by tm20.bullet.mail.ne1.yahoo.com with NNFMP; 08 Dec 2013 15:13:02 -0000
Received: from [127.0.0.1] by omp1017.mail.ne1.yahoo.com with NNFMP; 08 Dec 2013 15:13:02 -0000
X-Yahoo-Newman-Property: ymail-3
X-Yahoo-Newman-Id: 816773.44313.bm@omp1017.mail.ne1.yahoo.com
Received: (qmail 58840 invoked by uid 60001); 8 Dec 2013 15:13:02 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s1024; t=1386515582; bh=HeDG37EwrTAdjdLnqDBiXJDEhw114l+cxmSYLqBEtyo=; h=X-YMail-OSG:Received:X-Rocket-MIMEInfo:X-Mailer:References:Message-ID:Date:From:Reply-To:Subject:To:Cc:In-Reply-To:MIME-Version:Content-Type; b=mbeqcXKfQ4fuWJVrmrOgvNHxXwdC8rfudRvKwOPNhACU1yngM0u2e8AWYt1HomWGRll2YG79c7TgDn0ggn6E+BrOo2AMGF28RPfVKerdv0HicVT2eY5qng4R3VAAaMfiPX1E+RJII7yGUor6YJz8TM7INIonGHfdbBZOrQENq7Y=
DomainKey-Signature:a=rsa-sha1; q=dns; c=nofws;
  s=s1024; d=yahoo.com;
  h=X-YMail-OSG:Received:X-Rocket-MIMEInfo:X-Mailer:References:Message-ID:Date:From:Reply-To:Subject:To:Cc:In-Reply-To:MIME-Version:Content-Type;
  b=oO9DLpjqb55hLNv9Kja1iRIKoLj6ABJfAAHtRl3TYvN3BblPGm/Mu0LBP1qeiYjoWUws54bzv0d+bRA4j57vjBN7y6y519V1mqX3aW4vTRdYiEjLgMp7bfWKaYU0KWzCJQzjsR5ZhTMaJincyO1pfL+BhjAOmH8laSENTLUVhQA=;
X-YMail-OSG: 8RV4M4sVM1kYeNo5GKyw2lLEdKIiYcox4p5oH96rCbwH28x
 EsoUHDcwJXw8oaI2AfvDiQNzSexuNcKR3EmaEj1StvZ2Tnb2J2Jq1On1BPwT
 lrCkBmyW6BPkuerdFX_LVo0ifd5RGEz4_2ZekeKN93EqrQ01vqmqHDXgbOU5
 mzFY_lWQwaABifdSvu1CKvuyKjPl45I8CzM2yVGwvRuXkH4tloQNFKrxIWr3
 fVV3NTxkFZGpJa0dutmozGnqcwvJd7xRVOpxSIJdfVHwVm0t7lwVP.1YguO5
 .4yF6kE5JOE7uH9RRpP6kJ8Ax8sAprsp_0.05KfjwGZa84bVMeu6f6ZqRXzl
 g69dFIYRlkrB7Vn7waePHqA4BFjpTbKdulXWHAv6imuAf7KW9y6F2_x1xAhZ
 .6ZmKdUumQmaRVGV1XHWw2.2dtlAvK6eFsQBasFliFPvORmzrWBuIoazg4H9
 Y5LCWF0I4OlZCwVWIgm4pqspEjXOJQ7n69_SlG4HpFdT4Xfughfk7YmV.LVy
 nvZqyb9yZy8ZlLBkcSQsQW2w87vub8PvNrhMHm8KnTcXXjeeoZCTi4hqIdQW
 ltlNdN0ao6gUmpL3KuhvaQlGGfUhoTb4PBamYkSGwGASFsCVjQzTzqu7SJ7N
 XVTY2GPovQctVkNcgID15g3QkXSxnpezg
Received: from [97.124.169.17] by web122106.mail.ne1.yahoo.com via HTTP; Sun, 08 Dec 2013 07:13:02 PST
X-Rocket-MIMEInfo: 002.001,TWlrZSwgU3RlZmFuLCBBbGV4YW5kZXIsIGV0IGFsLiwKCkkgd2FzIHdhdGNoaW5nIHRoaXMgY29udmVyc2F0aW9uIHBsYXkgb3V0IGJlZm9yZSByZXBseWluZy4KCkl0IGlzbid0IGdvaW5nIHRvIGJlIGZydWl0ZnVsIHRvIGJlIHB1bGxlZCBpbnRvIGEgbG9uZyBkaXNjdXNzaW9uIGFib3V0IHRoZSBzcGVjaWZpY3Mgb2Ygb3VyIGNvbXB1dGUgZW52aXJvbm1lbnQuIFRoZXJlIGFyZSBtYW55IGFzc3VtcHRpb25zIGJlaW5nIG1hZGUgaW4gdGhpcyBkaXNjdXNzaW9uIHRoYXQgYXJlbid0IGNvcnJlY3QsIGFuZCABMAEBAQE-
X-Mailer: YahooMailWebService/0.8.169.609
References: <20131206112155.Horde.SbfwdHK-kyPj8MElQt3mrQ1@mail.das-netzwerkteam.de> <52A1BBAE.90909@stefanbaur.de> <20131206120625.Horde.SkFUuwsrCrkJ3OMw64wKaA1@mail.das-netzwerkteam.de> <52A1C089.3090709@stefanbaur.de> <1386351855.74486.YahooMailNeo@web122101.mail.ne1.yahoo.com> <52A21285.7090407@stefanbaur.de> <20131206195600.GA26961@cip.informatik.uni-erlangen.de> <20131207204759.Horde.ykUqekidzsjvppwa3ypAiQ7@mail.das-netzwerkteam.de> <52A39369.8050408@stefanbaur.de> <20131207215054.Horde.bR0h7aVrFSgs8VMWz2Sp2g2@mail.das-netzwerkteam.de> 
Message-ID: <1386515582.31556.YahooMailNeo@web122106.mail.ne1.yahoo.com>
Date: Sun, 8 Dec 2013 07:13:02 -0800 (PST)
From: Nick Ingegneri <n_ingegneri@yahoo.com>
Reply-To: Nick Ingegneri <n_ingegneri@yahoo.com>
Subject: Re: [X2Go-Dev] Bug#354: Bug#354: Make x2goagent listening to TCP connections configurable in x2goserver.conf
To: Mike Gabriel <mike.gabriel@das-netzwerkteam.de>,
  Stefan Baur <newsgroups.mail2@stefanbaur.de>
Cc: Alexander Wuerstlein <snalwuer@cip.informatik.uni-erlangen.de>,
  "354@bugs.x2go.org" <354@bugs.x2go.org>
In-Reply-To: <20131207215054.Horde.bR0h7aVrFSgs8VMWz2Sp2g2@mail.das-netzwerkteam.de>
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="61789334-543769667-1386515582=:31556"
[Message part 1 (text/plain, inline)]
Mike, Stefan, Alexander, et al.,

I was watching this conversation play out before replying.

It isn't going to be fruitful to be pulled into a long discussion about the specifics of our compute environment. There are many assumptions being made in this discussion that aren't correct, and saying "don't use TCP" without knowing these specifics is ignorant. There are industry-standard commercial products that disabling TCP breaks. Our IT department cannot decide to stop supporting TCP; it is the users and our commercial suppliers who determine what IT has to support.

I think that because I used "xhost +" in my original debugging example, the assumption was immediately made that "xhost +" was my primary concern. My primary concern is that disabling TCP
 breaks almost every possible use model except for one narrow case (ssh). Among other things, it breaks the MIT-MAGIC-COOKIE-1 mechanism. While there are very valid concerns regarding use of TCP on the internet, we have a different hierarchy of concerns regarding what happens on our internal network.

One incorrect assumption that is being made in this discussion is that some action to initiate the display can take place on the system the user is logged into, or that the user is even involved in initiating the display.  Consider this use model:

1: User's display is system100:24
2: Automated processes, with no user involvement, launch a program on a randomly chosen system (let's say it is system204).
3: The new program running on system204 now has to connect back to the display on system100:24

Personally, the problem is solved for us for at least the moment and we can move forward with what we are trying to do. Having to
 edit /usr/bin/x2gostartagent every time we install or upgrade the package is inelegant and creates additional administrative overhead, but it is manageable.

This is your project, not mine, I merely came to the mailing list with a problem looking for a solution. I can tell you that our use model is extremely common in industry and that breaking it will render X2Go unusable. Of the five alternatives we are looking at, X2Go was the only one with TCP disabled. Most system administrators trying to set up an evaluation of X2Go aren't typically going to dig further than the documentation and config files in trying to fix this problem. If you make fixing it so obscure that it escapes these system administrators, then X2Go isn't going to get very far in those evaluations.

How accessible or obscure you make this setting is up to you as developers, but saying to users "your use model is wrong" doesn't show appreciation for the diversity of ways that X is used in production.

Cheers,
Nick






On Saturday, December 7, 2013 2:51 PM, Mike Gabriel <mike.gabriel@das-netzwerkteam.de> wrote:
 
Control: tag -1 wontfix
Control: close -1

Hi Stefan,

On  Sa 07 Dez 2013 22:30:17 CET, Stefan Baur wrote:

> [...]

> Man, where are my pills, I don't want to go into full Theo de Raadt mode ...

Okokokok... heard!

@Nick: please place a copy of x2gostartagent into
 /usr/local/bin for a  
transition period and modify it to your needs. We won't reenable TCP  
listening in upstream X2Go. For long term usage of X2Go, adapt your  
workflows to a more secure model.

Mike
-- 

DAS-NETZWERKTEAM
mike gabriel, herweg 7, 24357 fleckeby
fon: +49 (1520) 1976 148

GnuPG Key ID 0x25771B31

mail: mike.gabriel@das-netzwerkteam.de, http://das-netzwerkteam.de

freeBusy:
https://mail.das-netzwerkteam.de/freebusy/m.gabriel%40das-netzwerkteam.de.xfb
[Message part 2 (text/html, inline)]

Send a report that this bug log contains spam.


X2Go Developers <owner@bugs.x2go.org>. Last modified: Fri Apr 19 06:13:05 2024; Machine Name: ymir.das-netzwerkteam.de

X2Go Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.