Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 67848 - Distcc Howto should mention the potential risks of distccd
Summary: Distcc Howto should mention the potential risks of distccd
Status: RESOLVED FIXED
Alias: None
Product: [OLD] Docs-user
Classification: Unclassified
Component: Other (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Sven Vermeulen (RETIRED)
URL: http://distcc.samba.org/security.html
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2004-10-17 00:41 UTC by Wernfried Haas (RETIRED)
Modified: 2004-11-09 03:37 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Wernfried Haas (RETIRED) gentoo-dev 2004-10-17 00:41:49 UTC
/etc/conf.d/distccd (recently) has a clear warning about the potential risks of running distccd and tells the user to use --allow/--listen. Unluckily the distcc guide - which is probably the first and only thing a user sometimes reads when dealing with distcc - doesn't mention anything about this. 

Quote:
(Add distccd to the default runlevel)
# rc-update add distccd default
(Start the distcc daemon)
# /etc/init.d/distccd start

This implies that distccd is easy to set up and nothing else would be necessary, only advanced users might consider taking a look at /etc/conf.d/distccd.
One sentence like "Edit /etc/conf.d/distccd to your needs and be sure to set the  --allow directive to allow only hosts you trust, see http://distcc.samba.org/security.html for more information." would be a big improvement.

Reproducible: Always
Steps to Reproduce:
Comment 1 Sven Vermeulen (RETIRED) gentoo-dev 2004-10-20 02:10:05 UTC
Lisa, can this be "automated"? I mean, can we assume that only the hosts defined by distcc-config are allowed to access distcc? If we do, we can allow this transparently without having the users update a file. If not, I'll add a paragraph before the "rc-update add distcc default" statement.
Comment 2 Wernfried Haas (RETIRED) gentoo-dev 2004-11-08 14:53:20 UTC
Any update on this issue?
Comment 3 Lisa Seelye (RETIRED) gentoo-dev 2004-11-08 15:06:52 UTC
Any change to the docs from me will have to wait until December as I am on vacation and away from my main machine.
Comment 4 Sven Vermeulen (RETIRED) gentoo-dev 2004-11-09 03:37:58 UTC
Okay, proposal put in document. Thanks for reporting!