From: Mick <michaelkintzios@gmail.com>
To: gentoo-user@lists.gentoo.org
Subject: Re: [gentoo-user] A networking question...
Date: Thu, 7 May 2009 23:34:42 +0100 [thread overview]
Message-ID: <200905072335.00108.michaelkintzios@gmail.com> (raw)
In-Reply-To: <4A032AC0.6000801@shic.co.uk>
[-- Attachment #1: Type: text/plain, Size: 3163 bytes --]
On Thursday 07 May 2009, Steve wrote:
> Anthony Metcalf wrote:
> > *That* depends on the exact specifics of what he is/isn't allowed to
> > be showing....."They" may not even want the service to show as
> > existing at that address for whatever reason.
>
> Thanks for all your discussion... I'll try to clarify - the PPP over
> SSH approach does seem to offer the best compromise.
>
> I've a development site which hosts https and http services for existing
> applications both remotely and locally. I'm developing an entirely new
> https service under Apache and want to be absolutely sure that I get no
> unexpected interactions between configurations for "live" services and
> the experimental in-development service - and I definitely don't want a
> random member of the public stumbling across the in-development site -
> which might expose unacceptable vulnerabilities as rough-cuts of code
> are trialled.
Have your development https service set up as a virtual host on a webroot of
your choice, listening to a random port and also set up user authentication
for the webroot fs.
In this way, whether accessed via the Internet or LAN, visitors will need to
know the port to connect to and will also have to provide suitable
credentials. You can even control access to parts of the development https
fs using <location> tags to define them and setting different user defined
access to them. If you use AuthDigest you can also set separate realms if
the fs is extensive and access requirements complex.
> It is entirely acceptable for any host on my LAN to access the
> in-development service. I want to allow collaborators to access the
> in-development service remotely over a SSH tunnel from their LAN, too
> (where I'm also not concerned about abuse...)
For collaboration setting DAV on is probably a better option as it uses
lockfiles and won't have one developer overwritting (un)wittingly changes
made by others.
> The snag I'm finding at the moment I'm sure I'll overcome... and relates
> to access from my LAN. While I can sort-of see how to establish a new
> device with a new IP address on the remote LAN (with SSH and pppd) I'm
> not sure how to establish a second IP address for my single Ethernet
> adaptor to make this work on my LAN (though I'm sure it is do-able...)
An adaptor can have more than one public IP address (multi-homing) and you can
use something like: ifconfig eth0:0 192.168.0.2 netmask 255.255.255.0 up to
set them up (increment eth0:1, eth0:2, etc accordingly). However, if your
SSL vhost is listening on a random port you don't need binding of many
addresses to one NIC. You can use the same ip address.
> I'm also curious to discover if there is a neat Gentooish way to
> establish my two instances of Apache. I'm broadly familiar to doing
> this a hackish way - but I'd prefer it plays nicely with any emerge
> updates.
Other than vhost I guest you can run a second instance by reading section 5
here (but I'm not sure you need to do that anyway):
http://www.gentoo.org/proj/en/php/php4-php5-configuration.xml
--
Regards,
Mick
[-- Attachment #2: This is a digitally signed message part. --]
[-- Type: application/pgp-signature, Size: 198 bytes --]
next prev parent reply other threads:[~2009-05-07 22:34 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2009-05-05 20:32 [gentoo-user] A networking question Steve
2009-05-05 21:23 ` Sascha Hlusiak
2009-05-05 21:28 ` Steve
2009-05-05 21:51 ` Sascha Hlusiak
2009-05-05 22:07 ` Mick
2009-05-06 0:24 ` Mike Kazantsev
2009-05-06 7:54 ` Neil Bothwick
2009-05-06 10:09 ` Anthony Metcalf
2009-05-06 10:42 ` Neil Bothwick
2009-05-06 12:08 ` Anthony Metcalf
2009-05-07 18:38 ` Steve
2009-05-07 22:34 ` Mick [this message]
2009-05-08 12:38 ` Steve
2009-05-08 14:43 ` Mick
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=200905072335.00108.michaelkintzios@gmail.com \
--to=michaelkintzios@gmail.com \
--cc=gentoo-user@lists.gentoo.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox