Fri, 20 Jan 2006

Changing remote access rules

For a long while now, remote access to the IMSc network has been through two machines.

As those who administer such services can imagine, managing access1 is quite complex. This is accentuated by the fact that it is outside a NAT firewall. Configuring RPC services like NIS and NFS across a firewall in a secure way when the NFS server is a Solaris machine --- luckily this was fully documented when it was done, or I wouldn't be able to re-create it!

Since we are switching ISP's as well, this seemed like a good time to combine the best features of both services. The older machines are kept on the old link (to be shut down on 1st February) and the new link has the new remote access machine.

This eliminates NIS passwords, NFS and at the same time gives "full service" to users. Detailed instructions for generating public-keys have also been provided. Unfortunately, some users don't see it that way.

This is not a sudden decision. Extensive discussions have taken place prior to this. Re-creating access1 just to accomodate some lazy and recalcitrant users of proprietary software is not my cup of tea. However, the latter statement is seen as a "threat".

For sticks-in-the-mud any change is a threat.


