List Info

Thread: Does Kickstart Support Secure HTTP (port 443)




Does Kickstart Support Secure HTTP (port 443)
country flaguser name
United States
2007-11-21 08:23:29

I have been asked to disable port 80 for security reasons.  I use it to supply a kickstart file to other systems on the network for Red Hat Enterprise Linux 4 (update 4).  Trying to get the kickstart with ks=https://ip_address/kickstart_filename.cfg fails.

Should I expect this to work or not?

Thanks,
---d.dembrow
Re: Does Kickstart Support Secure HTTP (port 443)
user name
2007-11-21 08:31:25
I looked into it for similar reasons and from what I can see
it doesn't. 
What we ended up doing is just making the firewall ACL more
specific to 
allow only port 80 to the kickstart host.

Maybe I'm wrong, I would be happy to hear it did support
this, but I 
don't think it does.

			- Matt

dadembrorockwellcollins.com wrote:
> 
> I have been asked to disable port 80 for security
reasons.  I use it to 
> supply a kickstart file to other systems on the network
for Red Hat 
> Enterprise Linux 4 (update 4).  Trying to get the
kickstart with 
> ks=https://ip_
address/kickstart_filename.cfg fails.
> 
> Should I expect this to work or not?
> 
> Thanks,
> ---d.dembrow
> 

-- 
------------------------------------------------------------
---------
Matt Fahrner                                    2 South Park
St.
Chief Systems Architect                         Willis
House
Burlington Coat Factory Warehouse               Lebanon,
N.H.  03766
Tel: (603) 448-4100 x5150                       USA
Fax: (603) 443-6190                            
Matt.FahrnerCOAT.COM
------------------------------------------------------------
---------

_______________________________________________
Kickstart-list mailing list
Kickstart-listredhat.com
https://www.redhat.com/mailman/listinfo/kickstart-list


Re: Does Kickstart Support Secure HTTP (port 443)
user name
2007-11-21 11:30:33
> I have been asked to disable port 80 for security
reasons.  I use it to 
> supply a kickstart file to other systems on the network
for Red Hat 
> Enterprise Linux 4 (update 4).  Trying to get the
kickstart with 
> ks=https://ip_
address/kickstart_filename.cfg fails.
> 
> Should I expect this to work or not?

No, and it's not limited to kickstart.  The URL fetching
code in the
loader does not support HTTPS at all, so you would discover
that this
does not work in interactive installs either.

- Chris

_______________________________________________
Kickstart-list mailing list
Kickstart-listredhat.com
https://www.redhat.com/mailman/listinfo/kickstart-list


[1-3]

about | contact  Other archives ( Real Estate discussion Medical topics )