login
Header Space

 
 

Re: pf tag goes missing post sshd tcp decapsulization

Score:
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: scott <8f27e956@...>
Cc: <misc@...>
Date: Monday, March 3, 2008 - 9:30 am

scott escreveu:
Tags are only visible while in the kernel. Once you send them to a
application, unless it has the ability to set a tag, the tag will be
lost. The ftp-proxy(8) AFAICR, since 4.1 has the ability to set a tag on
the packet. It would be nice if more userland applications like sshd,
spamd, hoststated, etc, could set tags too. In this case (sshd) you
can't do much thing as it runs with root privileges. You can't classify
it with the user keyword from pf. So i believe you will have to redesign
your rules in this case.

My regards,

--
Giancarlo Razzolini
Linux User 172199
Red Hat Certified Engineer no:804006389722501
Moleque Sem Conteudo Numero #002
Slackware Current
OpenBSD Stable
Ubuntu 7.04 Feisty Fawn
Snike Tecnologia em Informatica
4386 2A6F FFD4 4D5F 5842  6EA0 7ABE BBAB 9C0E 6B85

[demime 1.01d removed an attachment of type application/pgp-signature which had a name of signature.asc]
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: pf tag goes missing post sshd tcp decapsulization, Giancarlo Razzolini, (Mon Mar 3, 9:30 am)
Re: pf tag goes missing post sshd tcp decapsulization, Henning Brauer, (Mon Mar 3, 11:19 am)
Re: pf tag goes missing post sshd tcp decapsulization, Giancarlo Razzolini, (Mon Mar 3, 12:02 pm)
Re: pf tag goes missing post sshd tcp decapsulization, Giancarlo Razzolini, (Mon Mar 3, 2:02 pm)
Re: pf tag goes missing post sshd tcp decapsulization, Reyk Floeter, (Tue Mar 4, 6:15 am)
Re: pf tag goes missing post sshd tcp decapsulization , Theo de Raadt, (Thu Mar 6, 2:35 am)
Re: pf tag goes missing post sshd tcp decapsulization, Henning Brauer, (Mon Mar 3, 9:08 am)
speck-geostationary