Summary of password strength discussion

Bastien Nocera bnocera at redhat.com
Wed Jul 29 10:14:10 UTC 2015



----- Original Message -----
> On Mon, Jul 27, 2015 at 03:27:03PM -0600, Chris Murphy wrote:
> > Firewalld needs to be easier to inform what networks are trusted, so
> > that when I go to a cafe it automatically blocks (or drops) requests
> > to ports 22, 445, 2049, etc. By default. Without asking me. Just do it
> > because I have no good reason having those available when I'm in a
> > cafe. And if I do, I'll trust the network.
> 
> Here, we definitely agree.

Firewalld is as good as unused in Workstation. If you want ssh to run
per-network (as media, and file sharing do already), we can certainly do
that.

> > When enabling sshd in the GUI, it should use AllowUsers in sshd_config
> > rather than allowing all users access. ClientAliveInterval probably
> 
> I like this too, but editing sshd_config is more than a bit scary.
> 
> 
> --
> Matthew Miller
> <mattdm at fedoraproject.org>
> Fedora Project Leader
> --
> desktop mailing list
> desktop at lists.fedoraproject.org
> https://admin.fedoraproject.org/mailman/listinfo/desktop


More information about the desktop mailing list