AW: Nagios plugin to copy large text files

Jason Bodnar jason at shakabuku.org
Fri Sep 16 20:36:32 CEST 2005


On Fri, 16 Sep 2005 18:57:09 +0200, Mohr James wrote
> scp, ftp, rsync, ftp, wget and CFEngine are not a viable solution 
> for security reasons. Basically, we are not allowed to open ports 
> through the various firewalls without permission from the customer. 
> Several are online brokers that are obviously very security 
> conscious. It is extremely unlikely that all of the would allow us 
> to open additional ports *and* install the necessary applications. 
> Since you can start only the applications that are configured in 
> nrpe.cfg, this is an acceptable risk as the bank auditors that check 
> the brokers servers (which we manage) can instantly identify which 
> applications could be run on the remote system.

I have not used check_by_ssh but if it doesn't have the character limit you
can run sshd on the nrpe port (if you can't get the ssh port opened [which is
really bad]) and limit the commands that the user logging in can run. See the
"AUTHORIZED_KEYS FILE FORMAT" section of the sshd man page for
details. 

--
Jason Bodnar
jason at shakabuku.org
http://www.shakabuku.org

"You want free speech? Let's see you acknowledge a man whose words make
your blood boil who is standing center stage advocating at the top of
his lungs that which you would spend a lifetime opposing at the top of
yours." -- President Andrew Shephard, "The American President"



-------------------------------------------------------
SF.Net email is sponsored by:
Tame your development challenges with Apache's Geronimo App Server. 
Download it for free - -and be entered to win a 42" plasma tv or your very
own Sony(tm)PSP.  Click here to play: http://sourceforge.net/geronimo.php
_______________________________________________
Nagios-users mailing list
Nagios-users at lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/nagios-users
::: Please include Nagios version, plugin version (-v) and OS when reporting any issue. 
::: Messages without supporting info will risk being sent to /dev/null





More information about the Users mailing list