Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Stats default to On #51

Closed
patch0 opened this issue Jun 13, 2017 · 4 comments
Closed

Stats default to On #51

patch0 opened this issue Jun 13, 2017 · 4 comments
Assignees

Comments

@patch0
Copy link
Contributor

patch0 commented Jun 13, 2017

I strongly believe Stats should be disabled OR the stats http page be password protected by default.

Originally reported on Bytemark's Gitlab by @mpoland on 2017-03-07T15:00:28.117Z

@patch0
Copy link
Contributor Author

patch0 commented Jun 13, 2017

password protection seems sensible. We could use PAM with mod_authnz_external to require the admin user? Quite possibly a dodgy idea, security wise. Could generate an htpasswd file specifically for the stats and dump the password out in /srv or something.

Originally posted by @telyn on 2017-03-13T11:03:37.946Z

@patch0
Copy link
Contributor Author

patch0 commented Jun 13, 2017

ooh, or - disabled by default, add a 'config/stats' file containing user:pass entries and get symbiosis-httpd-configure to generate an htpasswd and enable it.

Originally posted by @telyn on 2017-03-14T10:12:27.861Z

@patch0
Copy link
Contributor Author

patch0 commented Jul 10, 2017

I think as a first pass, we can disable stats by default.

@patch0 patch0 added this to the stretch release milestone Jul 20, 2017
@smsm1
Copy link

smsm1 commented Aug 3, 2017

If the stats are enabled, they should probably only work over SSL and not plain text /non secure connections. With the ease of enabling secure connections now this shouldn't be a problem.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants