Hello,
Is it possible to revert an option to default (i.e. remove it from opsiclientd on all clients) which was previously configured on the server?
Steps to reproduce:
1) add a new option for opsiclientd on a specific machine on the OPSI server (the option appears in client config after reboot)
2 ...
Die Suche ergab 29 Treffer
- 25 Mai 2015, 16:54
- Forum: Free Support
- Thema: opsiclientd: revert option to default
- Antworten: 1
- Zugriffe: 2012
- 29 Mär 2015, 00:37
- Forum: Free Support
- Thema: Security concerns: server authentication
- Antworten: 3
- Zugriffe: 3373
Re: Security concerns: server authentication
Hi stanislav,
that's because the verify_server_cert option is not a full security feature. If you set this option, your clients will save the public key of the server ssl-cert on a initial connect. After that, the client will be decline connections, if your server-ssl-cert will be changed or ...
that's because the verify_server_cert option is not a full security feature. If you set this option, your clients will save the public key of the server ssl-cert on a initial connect. After that, the client will be decline connections, if your server-ssl-cert will be changed or ...
- 16 Mär 2015, 16:34
- Forum: Free Support
- Thema: Security concerns: server authentication
- Antworten: 3
- Zugriffe: 3373
Security concerns: server authentication
Hello,
Is there any reason why "verify_server_cert" is disabled in default configuration?
Best regards,
Stanislav
Is there any reason why "verify_server_cert" is disabled in default configuration?
Best regards,
Stanislav
- 09 Mär 2015, 12:04
- Forum: Free Support
- Thema: Security concerns (Samba)
- Antworten: 3
- Zugriffe: 3275
Re: Security concerns (Samba)
Hi Niko,
If we chose one of suggested solutions I would adopt that one:
...
Deny for the user pcpatch the access to all other shares than the opsi_depot share. You should do this by adding the following entry to all share definitions (besides the opsi_depot) at the /etc/samba/smb.conf:
invalid ...
If we chose one of suggested solutions I would adopt that one:
...
Deny for the user pcpatch the access to all other shares than the opsi_depot share. You should do this by adding the following entry to all share definitions (besides the opsi_depot) at the /etc/samba/smb.conf:
invalid ...
- 06 Mär 2015, 13:09
- Forum: Free Support
- Thema: Security concerns (Samba)
- Antworten: 3
- Zugriffe: 3275
Re: Security concerns (Samba)
Hello,
I have found the answer following http://download.uib.de/opsi4.0/doc/html ... ty-pcpatch.
Why is this not default?
Best regards,
Stanislav German-Evtushenko
I have found the answer following http://download.uib.de/opsi4.0/doc/html ... ty-pcpatch.
Why is this not default?
Best regards,
Stanislav German-Evtushenko
- 06 Mär 2015, 09:12
- Forum: Free Support
- Thema: Security concerns (Samba)
- Antworten: 3
- Zugriffe: 3275
Security concerns (Samba)
Hello,
Please tell me if I get it wrong.
opsi_depot_rw, opsi_images, opsi_config and opsi_workbench shares are writable for pcpatch user. So if a PC user (this can be virus or trojan) catches pcpatch password while opsi-client-agent communicates with Samba server then the whole infrastructure is ...
Please tell me if I get it wrong.
opsi_depot_rw, opsi_images, opsi_config and opsi_workbench shares are writable for pcpatch user. So if a PC user (this can be virus or trojan) catches pcpatch password while opsi-client-agent communicates with Samba server then the whole infrastructure is ...
- 12 Feb 2015, 13:52
- Forum: Free Support
- Thema: BUG: client deployment doesn't work from different network
- Antworten: 6
- Zugriffe: 4565
Re: BUG: client deployment doesn't work from different netwo
Hello Niko,
The script can now handle an IP instead of a hostname / fqdn. This was giving weird results before.
This is the answer to my question. Thank you.
I did a quick test this morning accessing an client with winexe via an IP and it did work. I used the statically linked version that ...
The script can now handle an IP instead of a hostname / fqdn. This was giving weird results before.
This is the answer to my question. Thank you.
I did a quick test this morning accessing an client with winexe via an IP and it did work. I used the statically linked version that ...
- 11 Feb 2015, 16:32
- Forum: Free Support
- Thema: BUG: client deployment doesn't work from different network
- Antworten: 6
- Zugriffe: 4565
Re: BUG: client deployment doesn't work from different netwo
Hello Stanislav,
I just touched the script.
Providing a new version of winexe over Opensuse Build Service is a big pain. If you want a newer version I'd recommend compiling it yourself.
I prefer having a working DNS in my environment as it saves you a lot of hassle.
With kind regards
Niko
Hi ...
I just touched the script.
Providing a new version of winexe over Opensuse Build Service is a big pain. If you want a newer version I'd recommend compiling it yourself.
I prefer having a working DNS in my environment as it saves you a lot of hassle.
With kind regards
Niko
Hi ...
- 11 Feb 2015, 15:47
- Forum: Free Support
- Thema: BUG: client deployment doesn't work from different network
- Antworten: 6
- Zugriffe: 4565
Re: BUG: client deployment doesn't work from different netwo
Hello Nico,n.wenselowski hat geschrieben:Hello Stanislav,
for the upcoming release the deployment via IP should be possible without touching the script.
With kind regards
Niko
winexe is updated, right?
I suppose IP address is more reliable than DNS anyway, what do you think?
Stanislav
- 09 Dez 2014, 10:48
- Forum: Free Support
- Thema: ./create_driver doesn't work
- Antworten: 23
- Zugriffe: 12615
Re: ./create_driver doesn't work
Exactly.loggenk hat geschrieben:Hi Stanislav,
So, if I understand it correctly, byAudit don't need a create_drivers_link?
May be I missed something from this long thread.I thought I saw it beofre. Okay, thnxs, i'll test it.
Stanislav