|
|
7d5a1d |
From 0f28f2b7b8072bdc2e483d035230ddcb8b00a919 Mon Sep 17 00:00:00 2001
|
|
|
7d5a1d |
From: Eric Garver <e@erig.me>
|
|
|
7d5a1d |
Date: Mon, 9 Jul 2018 11:29:33 -0400
|
|
|
7d5a1d |
Subject: [PATCH] Add cockpit by default to some zones
|
|
|
7d5a1d |
|
|
|
7d5a1d |
Fixes: #1581578
|
|
|
7d5a1d |
---
|
|
|
7d5a1d |
config/zones/home.xml | 1 +
|
|
|
7d5a1d |
config/zones/internal.xml | 1 +
|
|
|
7d5a1d |
config/zones/public.xml | 1 +
|
|
|
7d5a1d |
config/zones/work.xml | 1 +
|
|
|
7d5a1d |
src/tests/features/service_include.at | 2 +-
|
|
|
7d5a1d |
src/tests/firewall-cmd.at | 14 +++++++++++++-
|
|
|
7d5a1d |
src/tests/regression/gh366.at | 3 +++
|
|
|
7d5a1d |
src/tests/regression/gh453.at | 2 ++
|
|
|
7d5a1d |
src/tests/regression/rhbz1514043.at | 2 +-
|
|
|
7d5a1d |
9 files changed, 24 insertions(+), 3 deletions(-)
|
|
|
7d5a1d |
|
|
|
7d5a1d |
diff --git a/config/zones/home.xml b/config/zones/home.xml
|
|
|
7d5a1d |
index 42b29b2f2d50..8aa8afa0e8aa 100644
|
|
|
7d5a1d |
--- a/config/zones/home.xml
|
|
|
7d5a1d |
+++ b/config/zones/home.xml
|
|
|
7d5a1d |
@@ -6,4 +6,5 @@
|
|
|
7d5a1d |
<service name="mdns"/>
|
|
|
7d5a1d |
<service name="samba-client"/>
|
|
|
7d5a1d |
<service name="dhcpv6-client"/>
|
|
|
7d5a1d |
+ <service name="cockpit"/>
|
|
|
7d5a1d |
</zone>
|
|
|
7d5a1d |
diff --git a/config/zones/internal.xml b/config/zones/internal.xml
|
|
|
7d5a1d |
index e646b48c94e8..40cb7e14424b 100644
|
|
|
7d5a1d |
--- a/config/zones/internal.xml
|
|
|
7d5a1d |
+++ b/config/zones/internal.xml
|
|
|
7d5a1d |
@@ -6,4 +6,5 @@
|
|
|
7d5a1d |
<service name="mdns"/>
|
|
|
7d5a1d |
<service name="samba-client"/>
|
|
|
7d5a1d |
<service name="dhcpv6-client"/>
|
|
|
7d5a1d |
+ <service name="cockpit"/>
|
|
|
7d5a1d |
</zone>
|
|
|
7d5a1d |
diff --git a/config/zones/public.xml b/config/zones/public.xml
|
|
|
7d5a1d |
index 49795d8c9068..617e131a4895 100644
|
|
|
7d5a1d |
--- a/config/zones/public.xml
|
|
|
7d5a1d |
+++ b/config/zones/public.xml
|
|
|
7d5a1d |
@@ -4,4 +4,5 @@
|
|
|
7d5a1d |
<description>For use in public areas. You do not trust the other computers on networks to not harm your computer. Only selected incoming connections are accepted.</description>
|
|
|
7d5a1d |
<service name="ssh"/>
|
|
|
7d5a1d |
<service name="dhcpv6-client"/>
|
|
|
7d5a1d |
+ <service name="cockpit"/>
|
|
|
7d5a1d |
</zone>
|
|
|
7d5a1d |
diff --git a/config/zones/work.xml b/config/zones/work.xml
|
|
|
7d5a1d |
index 6ea5550a40bd..9609ee6f65c2 100644
|
|
|
7d5a1d |
--- a/config/zones/work.xml
|
|
|
7d5a1d |
+++ b/config/zones/work.xml
|
|
|
7d5a1d |
@@ -4,4 +4,5 @@
|
|
|
7d5a1d |
<description>For use in work areas. You mostly trust the other computers on networks to not harm your computer. Only selected incoming connections are accepted.</description>
|
|
|
7d5a1d |
<service name="ssh"/>
|
|
|
7d5a1d |
<service name="dhcpv6-client"/>
|
|
|
7d5a1d |
+ <service name="cockpit"/>
|
|
|
7d5a1d |
</zone>
|
|
|
7d5a1d |
diff --git a/src/tests/features/service_include.at b/src/tests/features/service_include.at
|
|
|
7d5a1d |
index b3a50a84bd88..992c5ef0ba92 100644
|
|
|
7d5a1d |
--- a/src/tests/features/service_include.at
|
|
|
7d5a1d |
+++ b/src/tests/features/service_include.at
|
|
|
7d5a1d |
@@ -90,7 +90,7 @@ FWD_CHECK([--zone=drop --list-services], 0, [dnl
|
|
|
7d5a1d |
|
|
|
7d5a1d |
])
|
|
|
7d5a1d |
FWD_CHECK([--zone=public --list-services], 0, [dnl
|
|
|
7d5a1d |
-dhcpv6-client ssh
|
|
|
7d5a1d |
+cockpit dhcpv6-client ssh
|
|
|
7d5a1d |
])
|
|
|
7d5a1d |
FWD_CHECK([-q --permanent --service=my-service-with-include --remove-include=does-not-exist])
|
|
|
7d5a1d |
FWD_RELOAD
|
|
|
7d5a1d |
diff --git a/src/tests/firewall-cmd.at b/src/tests/firewall-cmd.at
|
|
|
7d5a1d |
index efc8f9c50757..6444b4566af5 100644
|
|
|
7d5a1d |
--- a/src/tests/firewall-cmd.at
|
|
|
7d5a1d |
+++ b/src/tests/firewall-cmd.at
|
|
|
7d5a1d |
@@ -1046,6 +1046,7 @@ FWD_START_TEST([rich rules priority])
|
|
|
7d5a1d |
chain filter_IN_public_allow {
|
|
|
7d5a1d |
tcp dport 22 ct state new,untracked accept
|
|
|
7d5a1d |
ip6 daddr fe80::/64 udp dport 546 ct state new,untracked accept
|
|
|
7d5a1d |
+ tcp dport 9090 ct state new,untracked accept
|
|
|
7d5a1d |
tcp dport 1122 ct state new,untracked accept
|
|
|
7d5a1d |
tcp dport 3333 ct state new,untracked accept
|
|
|
7d5a1d |
tcp dport 4444 ct state new,untracked accept
|
|
|
7d5a1d |
@@ -1061,6 +1062,7 @@ FWD_START_TEST([rich rules priority])
|
|
|
7d5a1d |
])
|
|
|
7d5a1d |
IPTABLES_LIST_RULES([filter], [IN_public_allow], 0, [dnl
|
|
|
7d5a1d |
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:22 ctstate NEW,UNTRACKED
|
|
|
7d5a1d |
+ ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:9090 ctstate NEW,UNTRACKED
|
|
|
7d5a1d |
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:1122 ctstate NEW,UNTRACKED
|
|
|
7d5a1d |
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:3333 ctstate NEW,UNTRACKED
|
|
|
7d5a1d |
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:4444 ctstate NEW,UNTRACKED
|
|
|
7d5a1d |
@@ -1075,6 +1077,7 @@ FWD_START_TEST([rich rules priority])
|
|
|
7d5a1d |
IP6TABLES_LIST_RULES([filter], [IN_public_allow], 0, [dnl
|
|
|
7d5a1d |
ACCEPT tcp ::/0 ::/0 tcp dpt:22 ctstate NEW,UNTRACKED
|
|
|
7d5a1d |
ACCEPT udp ::/0 fe80::/64 udp dpt:546 ctstate NEW,UNTRACKED
|
|
|
7d5a1d |
+ ACCEPT tcp ::/0 ::/0 tcp dpt:9090 ctstate NEW,UNTRACKED
|
|
|
7d5a1d |
ACCEPT tcp ::/0 ::/0 tcp dpt:1122 ctstate NEW,UNTRACKED
|
|
|
7d5a1d |
ACCEPT tcp ::/0 ::/0 tcp dpt:3333 ctstate NEW,UNTRACKED
|
|
|
7d5a1d |
ACCEPT tcp ::/0 ::/0 tcp dpt:4444 ctstate NEW,UNTRACKED
|
|
|
7d5a1d |
@@ -1156,6 +1159,7 @@ FWD_START_TEST([rich rules priority])
|
|
|
7d5a1d |
chain filter_IN_public_allow {
|
|
|
7d5a1d |
tcp dport 22 ct state new,untracked accept
|
|
|
7d5a1d |
ip6 daddr fe80::/64 udp dport 546 ct state new,untracked accept
|
|
|
7d5a1d |
+ tcp dport 9090 ct state new,untracked accept
|
|
|
7d5a1d |
}
|
|
|
7d5a1d |
}
|
|
|
7d5a1d |
])
|
|
|
7d5a1d |
@@ -1259,6 +1263,7 @@ FWD_START_TEST([rich rules priority])
|
|
|
7d5a1d |
])
|
|
|
7d5a1d |
IPTABLES_LIST_RULES([filter], [IN_public_allow], 0, [dnl
|
|
|
7d5a1d |
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:22 ctstate NEW,UNTRACKED
|
|
|
7d5a1d |
+ ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:9090 ctstate NEW,UNTRACKED
|
|
|
7d5a1d |
])
|
|
|
7d5a1d |
IPTABLES_LIST_RULES([filter], [FWDI_public_pre], 0, [dnl
|
|
|
7d5a1d |
])
|
|
|
7d5a1d |
@@ -1293,6 +1298,7 @@ FWD_START_TEST([rich rules priority])
|
|
|
7d5a1d |
IP6TABLES_LIST_RULES([filter], [IN_public_allow], 0, [dnl
|
|
|
7d5a1d |
ACCEPT tcp ::/0 ::/0 tcp dpt:22 ctstate NEW,UNTRACKED
|
|
|
7d5a1d |
ACCEPT udp ::/0 fe80::/64 udp dpt:546 ctstate NEW,UNTRACKED
|
|
|
7d5a1d |
+ ACCEPT tcp ::/0 ::/0 tcp dpt:9090 ctstate NEW,UNTRACKED
|
|
|
7d5a1d |
])
|
|
|
7d5a1d |
IP6TABLES_LIST_RULES([filter], [FWDI_public_pre], 0, [dnl
|
|
|
7d5a1d |
])
|
|
|
7d5a1d |
@@ -1340,6 +1346,7 @@ FWD_START_TEST([rich rules priority])
|
|
|
7d5a1d |
chain filter_IN_public_allow {
|
|
|
7d5a1d |
tcp dport 22 ct state new,untracked accept
|
|
|
7d5a1d |
ip6 daddr fe80::/64 udp dport 546 ct state new,untracked accept
|
|
|
7d5a1d |
+ tcp dport 9090 ct state new,untracked accept
|
|
|
7d5a1d |
icmp type echo-request accept
|
|
|
7d5a1d |
icmpv6 type echo-request accept
|
|
|
7d5a1d |
}
|
|
|
7d5a1d |
@@ -1380,6 +1387,7 @@ FWD_START_TEST([rich rules priority])
|
|
|
7d5a1d |
])
|
|
|
7d5a1d |
IPTABLES_LIST_RULES([filter], [IN_public_allow], 0, [dnl
|
|
|
7d5a1d |
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:22 ctstate NEW,UNTRACKED
|
|
|
7d5a1d |
+ ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:9090 ctstate NEW,UNTRACKED
|
|
|
7d5a1d |
ACCEPT icmp -- 0.0.0.0/0 0.0.0.0/0 icmptype 8
|
|
|
7d5a1d |
])
|
|
|
7d5a1d |
IPTABLES_LIST_RULES([filter], [FWDI_public_pre], 0, [dnl
|
|
|
7d5a1d |
@@ -1402,6 +1410,7 @@ FWD_START_TEST([rich rules priority])
|
|
|
7d5a1d |
IP6TABLES_LIST_RULES([filter], [IN_public_allow], 0, [dnl
|
|
|
7d5a1d |
ACCEPT tcp ::/0 ::/0 tcp dpt:22 ctstate NEW,UNTRACKED
|
|
|
7d5a1d |
ACCEPT udp ::/0 fe80::/64 udp dpt:546 ctstate NEW,UNTRACKED
|
|
|
7d5a1d |
+ ACCEPT tcp ::/0 ::/0 tcp dpt:9090 ctstate NEW,UNTRACKED
|
|
|
7d5a1d |
ACCEPT icmpv6 ::/0 ::/0 ipv6-icmptype 128
|
|
|
7d5a1d |
])
|
|
|
7d5a1d |
IP6TABLES_LIST_RULES([filter], [FWDI_public_pre], 0, [dnl
|
|
|
7d5a1d |
@@ -1458,6 +1467,7 @@ FWD_START_TEST([rich rules priority])
|
|
|
7d5a1d |
chain filter_IN_public_allow {
|
|
|
7d5a1d |
tcp dport 22 ct state new,untracked accept
|
|
|
7d5a1d |
ip6 daddr fe80::/64 udp dport 546 ct state new,untracked accept
|
|
|
7d5a1d |
+ tcp dport 9090 ct state new,untracked accept
|
|
|
7d5a1d |
}
|
|
|
7d5a1d |
}
|
|
|
7d5a1d |
])
|
|
|
7d5a1d |
@@ -1495,6 +1505,7 @@ FWD_START_TEST([rich rules priority])
|
|
|
7d5a1d |
])
|
|
|
7d5a1d |
IPTABLES_LIST_RULES([filter], [IN_public_allow], 0, [dnl
|
|
|
7d5a1d |
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:22 ctstate NEW,UNTRACKED
|
|
|
7d5a1d |
+ ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:9090 ctstate NEW,UNTRACKED
|
|
|
7d5a1d |
])
|
|
|
7d5a1d |
IPTABLES_LIST_RULES([filter], [IN_public_deny], 0, [dnl
|
|
|
7d5a1d |
])
|
|
|
7d5a1d |
@@ -1515,6 +1526,7 @@ FWD_START_TEST([rich rules priority])
|
|
|
7d5a1d |
IP6TABLES_LIST_RULES([filter], [IN_public_allow], 0, [dnl
|
|
|
7d5a1d |
ACCEPT tcp ::/0 ::/0 tcp dpt:22 ctstate NEW,UNTRACKED
|
|
|
7d5a1d |
ACCEPT udp ::/0 fe80::/64 udp dpt:546 ctstate NEW,UNTRACKED
|
|
|
7d5a1d |
+ ACCEPT tcp ::/0 ::/0 tcp dpt:9090 ctstate NEW,UNTRACKED
|
|
|
7d5a1d |
])
|
|
|
7d5a1d |
IP6TABLES_LIST_RULES([filter], [IN_public_deny], 0, [dnl
|
|
|
7d5a1d |
])
|
|
|
7d5a1d |
@@ -1540,7 +1552,7 @@ FWD_START_TEST([rich rules priority])
|
|
|
7d5a1d |
icmp-block-inversion: no
|
|
|
7d5a1d |
interfaces:
|
|
|
7d5a1d |
sources:
|
|
|
7d5a1d |
- services: dhcpv6-client ssh
|
|
|
7d5a1d |
+ services: cockpit dhcpv6-client ssh
|
|
|
7d5a1d |
ports:
|
|
|
7d5a1d |
protocols:
|
|
|
7d5a1d |
masquerade: no
|
|
|
7d5a1d |
diff --git a/src/tests/regression/gh366.at b/src/tests/regression/gh366.at
|
|
|
7d5a1d |
index 1441a6be53bf..51ff504e6a9d 100644
|
|
|
7d5a1d |
--- a/src/tests/regression/gh366.at
|
|
|
7d5a1d |
+++ b/src/tests/regression/gh366.at
|
|
|
7d5a1d |
@@ -7,6 +7,7 @@ table inet firewalld {
|
|
|
7d5a1d |
chain filter_IN_public_allow {
|
|
|
7d5a1d |
tcp dport 22 ct state new,untracked accept
|
|
|
7d5a1d |
ip6 daddr fe80::/64 udp dport 546 ct state new,untracked accept
|
|
|
7d5a1d |
+tcp dport 9090 ct state new,untracked accept
|
|
|
7d5a1d |
ip daddr 224.0.0.251 udp dport 5353 ct state new,untracked accept
|
|
|
7d5a1d |
ip6 daddr ff02::fb udp dport 5353 ct state new,untracked accept
|
|
|
7d5a1d |
}
|
|
|
7d5a1d |
@@ -14,11 +15,13 @@ ip6 daddr ff02::fb udp dport 5353 ct state new,untracked accept
|
|
|
7d5a1d |
])
|
|
|
7d5a1d |
IPTABLES_LIST_RULES([filter], [IN_public_allow], 0, [dnl
|
|
|
7d5a1d |
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:22 ctstate NEW,UNTRACKED
|
|
|
7d5a1d |
+ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:9090 ctstate NEW,UNTRACKED
|
|
|
7d5a1d |
ACCEPT udp -- 0.0.0.0/0 224.0.0.251 udp dpt:5353 ctstate NEW,UNTRACKED
|
|
|
7d5a1d |
])
|
|
|
7d5a1d |
IP6TABLES_LIST_RULES([filter], [IN_public_allow], 0, [dnl
|
|
|
7d5a1d |
ACCEPT tcp ::/0 ::/0 tcp dpt:22 ctstate NEW,UNTRACKED
|
|
|
7d5a1d |
ACCEPT udp ::/0 fe80::/64 udp dpt:546 ctstate NEW,UNTRACKED
|
|
|
7d5a1d |
+ACCEPT tcp ::/0 ::/0 tcp dpt:9090 ctstate NEW,UNTRACKED
|
|
|
7d5a1d |
ACCEPT udp ::/0 ff02::fb udp dpt:5353 ctstate NEW,UNTRACKED
|
|
|
7d5a1d |
])])
|
|
|
7d5a1d |
|
|
|
7d5a1d |
diff --git a/src/tests/regression/gh453.at b/src/tests/regression/gh453.at
|
|
|
7d5a1d |
index f57a79dcf9a2..6d820fce840a 100644
|
|
|
7d5a1d |
--- a/src/tests/regression/gh453.at
|
|
|
7d5a1d |
+++ b/src/tests/regression/gh453.at
|
|
|
7d5a1d |
@@ -18,6 +18,7 @@ NFT_LIST_RULES([inet], [filter_IN_public_allow], 0, [dnl
|
|
|
7d5a1d |
chain filter_IN_public_allow {
|
|
|
7d5a1d |
tcp dport 22 ct state new,untracked accept
|
|
|
7d5a1d |
ip6 daddr fe80::/64 udp dport 546 ct state new,untracked accept
|
|
|
7d5a1d |
+ tcp dport 9090 ct state new,untracked accept
|
|
|
7d5a1d |
tcp dport 21 ct helper set "helper-ftp-tcp"
|
|
|
7d5a1d |
tcp dport 21 ct state new,untracked accept
|
|
|
7d5a1d |
}
|
|
|
7d5a1d |
@@ -42,6 +43,7 @@ NFT_LIST_RULES([inet], [filter_IN_public_allow], 0, [dnl
|
|
|
7d5a1d |
chain filter_IN_public_allow {
|
|
|
7d5a1d |
tcp dport 22 ct state new,untracked accept
|
|
|
7d5a1d |
ip6 daddr fe80::/64 udp dport 546 ct state new,untracked accept
|
|
|
7d5a1d |
+ tcp dport 9090 ct state new,untracked accept
|
|
|
7d5a1d |
tcp dport 21 ct helper set "helper-ftp-tcp"
|
|
|
7d5a1d |
tcp dport 21 ct state new,untracked accept
|
|
|
7d5a1d |
tcp dport 5060 ct helper set "helper-sip-tcp"
|
|
|
7d5a1d |
diff --git a/src/tests/regression/rhbz1514043.at b/src/tests/regression/rhbz1514043.at
|
|
|
7d5a1d |
index deb93a5fac94..88ce4934e5ea 100644
|
|
|
7d5a1d |
--- a/src/tests/regression/rhbz1514043.at
|
|
|
7d5a1d |
+++ b/src/tests/regression/rhbz1514043.at
|
|
|
7d5a1d |
@@ -5,7 +5,7 @@ FWD_CHECK([-q --set-log-denied=all])
|
|
|
7d5a1d |
FWD_CHECK([-q --permanent --zone=public --add-service=samba])
|
|
|
7d5a1d |
FWD_RELOAD
|
|
|
7d5a1d |
FWD_CHECK([--zone=public --list-all | TRIM | grep ^services], 0, [dnl
|
|
|
7d5a1d |
-services: dhcpv6-client samba ssh
|
|
|
7d5a1d |
+services: cockpit dhcpv6-client samba ssh
|
|
|
7d5a1d |
])
|
|
|
7d5a1d |
dnl check that log denied actually took effect
|
|
|
7d5a1d |
m4_if(iptables, FIREWALL_BACKEND, [
|
|
|
7d5a1d |
--
|
|
|
7d5a1d |
2.20.1
|
|
|
7d5a1d |
|