public inbox for cygwin-xfree@sourceware.org
help / color / mirror / Atom feed
* Re: security, cvs, was Re: interface bindings of x-server
@ 2003-11-19 14:01 devzero
  0 siblings, 0 replies; 12+ messages in thread
From: devzero @ 2003-11-19 14:01 UTC (permalink / raw)
  To: keithp; +Cc: cygwin-xfree, keith, xserver

Hi!

i`d like if discussion "unix domain socket vs.  127.0.0.1/TCP for local X connections" would be a complete separate discussion thread. could we separate this?

ok, it seems my thread has alreade become somewhat a separate one (the "was" in the subject line)   ;)

MY intention with this thread is , just to add feature to X-Server which enables binding to dedicated interfaces - which is a quite common feature for popular server-daemons. being able to tune the interface bindings of an applications is a matter of "good implementation style", IMHO.
I wished if i could do that with ALL applications which bind to interfaces.
I`m sure this feature is easy to implement (because there are tons of code examples on the net and because it seems to be already in tightvnc).

is there anybody who already thinksa about doing that ?
i`m really a bad programmer - maybe i could try my luck with that - but i don`t like it starting such work and fiddling around for some days and then somebody says: ok - i`ve done it. was just 5 mins - TRIVIAL ! :D

regards
roland


Keith Packard <keithp@keithp.com> schrieb am 19.11.03 10:35:24:
> 
> 
> Around 10 o'clock on Nov 19, "roland@webde" wrote:
> 
> > the only chance to get rid of it, is to use unix domain socket (via
> > -nolisten tcp)
> 
> That option should be the default; ssh refuses to listen on a unix 
> domain socket, but appears quite happy to connect to a unix domain 
> socket.
> 
> I don't know of any compelling reason to run X raw over TCP/IP these days; 
> it's insecure, and a bandwidth pig.
> 
> -keith
> 
> 


______________________________________________________________________________
WEB.DE FreeMail wird 5 Jahre jung! Feiern Sie mit uns und
nutzen Sie die neuen Funktionen http://f.web.de/features/?mc=021130


^ permalink raw reply	[flat|nested] 12+ messages in thread
* Re: interface bindings of x-server
@ 2003-11-19  4:13 Keith Packard
  2003-11-19  8:15 ` security, cvs, was " Keith Whitwell
  0 siblings, 1 reply; 12+ messages in thread
From: Keith Packard @ 2003-11-19  4:13 UTC (permalink / raw)
  To: roland@webde; +Cc: cygwin-xfree, xserver, Keith Packard


Around 2 o'clock on Nov 19, "roland@webde" wrote:

> Keith, could you put this (being able to specify the interface bindings of
> the xserver on the commandline) as a feature request on http://
> www.freedesktop.org/Software/XserverWishlist if you find this feature
> request useful ? i registerd a wiki account, but logging in doesn`t seem to
> work for me.

I'd like to switch the server so that -nolisten tcp is the default; I 
don't see much sense in having it listen to even 127.0.0.1.  But, if you 
wanted to make the list of IP addresses that the server bound to 
configurable, that seems like a good idea.

ssh -X -C should be the only way to talk to an X server over the network, 
at least for now.  If we find a better way in the future, we might revisit 
this.

Patches to implement any such changes would be gratefully accepted to the 
fd.o X server tree.

The wiki has anti-defacement "security"; please ask most anyone on
#freedesktop to be added to the list of accounts with wiki write access.

-keith



^ permalink raw reply	[flat|nested] 12+ messages in thread

end of thread, other threads:[~2003-11-20  0:32 UTC | newest]

Thread overview: 12+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2003-11-19 14:01 security, cvs, was Re: interface bindings of x-server devzero
  -- strict thread matches above, loose matches on Subject: below --
2003-11-19  4:13 Keith Packard
2003-11-19  8:15 ` security, cvs, was " Keith Whitwell
2003-11-19  8:49   ` Keith Packard
2003-11-19  9:22   ` roland@webde
2003-11-19  9:35     ` Keith Packard
2003-11-19  9:52       ` Corinna Vinschen
2003-11-19 19:34     ` Alan Coopersmith
2003-11-19 21:12       ` roland@webde
2003-11-19 23:49       ` Dave Dodge
2003-11-20  0:13         ` Alan Coopersmith
2003-11-20  0:13         ` Keith Packard
2003-11-20  0:32           ` Dave Dodge

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).