public inbox for pve-devel@lists.proxmox.com
 help / color / mirror / Atom feed
From: Thomas Lamprecht <t.lamprecht@proxmox.com>
To: Oguz Bektas <o.bektas@proxmox.com>,
	Proxmox VE development discussion <pve-devel@lists.proxmox.com>
Subject: Re: [pve-devel] [PATCH common/manager/http-server/docs] improve binding, docs and access-control for pveproxy/spiceproxy
Date: Wed, 5 May 2021 07:36:59 +0200	[thread overview]
Message-ID: <4f5cc64d-199b-1943-8ca9-0ef4daf5a0c6@proxmox.com> (raw)
In-Reply-To: <20210504112503.GA15687@gaia.proxmox.com>

On 04.05.21 13:25, Oguz Bektas wrote:
> hi,
> 
> thank you for the fixes :)
> 
> 
> tested the following to verify:
>> I tested it in the following scenarios:
>> * ipv6 disabled via kernel commandline (listen on 0.0.0.0)
>> * ipv6 disabled via sysctl (listen on 0.0.0.0)
>> * no settings dual-stacked (listen on *)
>> * no settings v6 only (listen on *)
>>
> and tested some scenarios also with ALLOW_FROM and LISTEN_IP.

Please list what scenarios you actually tested, else a T-b tag is not really
telling... I mean, you said you tested the patches you send too, but obv. not in
IPv6 disable setups, so having the actual list of things here can really help.

If unsure, check out how Dominic reports such things, those are always good,
concise but not leaving out interesting (test scenario/setup) details.

For example,
https://lists.proxmox.com/pipermail/pve-devel/2021-March/047375.html
https://lists.proxmox.com/pipermail/pve-devel/2021-April/047827.html

> 
> it's also worth noting that disabling ipv6 in the commandline will
> change the access.log format to show the standard IPv4 address instead
> of the mapped v6 address.

good note, could have been used in the new "Disabling IPv6 on the Node" docs
section Stoiko adds.

Updating https://pve.proxmox.com/wiki/Fail2ban could help too, or did you
already check if mapped notation works there too just fine with the config
proposal from the wiki?




  reply	other threads:[~2021-05-05  5:37 UTC|newest]

Thread overview: 14+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2021-05-04 10:12 Stoiko Ivanov
2021-05-04 10:12 ` [pve-devel] [PATCH common 1/2] daemon: drop Domain parameter from create_reusable_socket Stoiko Ivanov
2021-05-04 10:12 ` [pve-devel] [PATCH common 2/2] daemon: explicitly bind to wildcard address Stoiko Ivanov
2021-05-04 11:28   ` Wolfgang Bumiller
2021-05-04 10:12 ` [pve-devel] [PATCH manager 1/1] proxy: fix wildcard address use Stoiko Ivanov
2021-05-04 10:12 ` [pve-devel] [PATCH http-server 1/2] access control: correctly match v4-mapped-v6 addresses Stoiko Ivanov
2021-05-04 10:12 ` [pve-devel] [PATCH http-server 2/2] access control: also include ipv6 in 'all' Stoiko Ivanov
2021-05-04 10:12 ` [pve-devel] [PATCH docs 1/3] pveproxy: add note about bindv6only sysctl Stoiko Ivanov
2021-05-04 10:12 ` [pve-devel] [PATCH docs 2/3] pveproxy: update documentation on 'all' alias Stoiko Ivanov
2021-05-04 10:12 ` [pve-devel] [PATCH docs 3/3] network: shortly document disabling ipv6 support Stoiko Ivanov
2021-05-04 11:25 ` [pve-devel] [PATCH common/manager/http-server/docs] improve binding, docs and access-control for pveproxy/spiceproxy Oguz Bektas
2021-05-05  5:36   ` Thomas Lamprecht [this message]
2021-05-05  9:25     ` Oguz Bektas
2021-05-04 12:20 ` Wolfgang Bumiller

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4f5cc64d-199b-1943-8ca9-0ef4daf5a0c6@proxmox.com \
    --to=t.lamprecht@proxmox.com \
    --cc=o.bektas@proxmox.com \
    --cc=pve-devel@lists.proxmox.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal