AW: Nagios plugin to copy large text files
Jason Bodnar
jason at shakabuku.org
Fri Sep 16 20:36:32 CEST 2005
On Fri, 16 Sep 2005 18:57:09 +0200, Mohr James wrote
> scp, ftp, rsync, ftp, wget and CFEngine are not a viable solution
> for security reasons. Basically, we are not allowed to open ports
> through the various firewalls without permission from the customer.
> Several are online brokers that are obviously very security
> conscious. It is extremely unlikely that all of the would allow us
> to open additional ports *and* install the necessary applications.
> Since you can start only the applications that are configured in
> nrpe.cfg, this is an acceptable risk as the bank auditors that check
> the brokers servers (which we manage) can instantly identify which
> applications could be run on the remote system.
I have not used check_by_ssh but if it doesn't have the character limit you
can run sshd on the nrpe port (if you can't get the ssh port opened [which is
really bad]) and limit the commands that the user logging in can run. See the
"AUTHORIZED_KEYS FILE FORMAT" section of the sshd man page for
details.
--
Jason Bodnar
jason at shakabuku.org
http://www.shakabuku.org
"You want free speech? Let's see you acknowledge a man whose words make
your blood boil who is standing center stage advocating at the top of
his lungs that which you would spend a lifetime opposing at the top of
yours." -- President Andrew Shephard, "The American President"
-------------------------------------------------------
SF.Net email is sponsored by:
Tame your development challenges with Apache's Geronimo App Server.
Download it for free - -and be entered to win a 42" plasma tv or your very
own Sony(tm)PSP. Click here to play: http://sourceforge.net/geronimo.php
_______________________________________________
Nagios-users mailing list
Nagios-users at lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/nagios-users
::: Please include Nagios version, plugin version (-v) and OS when reporting any issue.
::: Messages without supporting info will risk being sent to /dev/null
More information about the Users
mailing list