Re: LPD configuration

From: Jarno Huuskonen (Jarno.Huuskonen@uku.fi)
Date: 10/11/01


Date: Thu, 11 Oct 2001 14:56:10 +0300
From: Jarno Huuskonen <Jarno.Huuskonen@uku.fi>
To: focus-linux@securityfocus.com
Subject: Re: LPD configuration
Message-ID: <20011011145610.A149368@messi.uku.fi>

On Tue, Oct 09, hg9627 wrote:

> Limit access to your printer via lpd.conf, there's some ways to restrict
> hosts by subnet and ip-addresses. tcp-wrappers should be mandatory
> nowadays.

A while back I made a patch for LPRng (3.6.26) to use
tcp_wrappers. AFAIK the patch still applies to more recent LPRng
versions (it's possible to use lpd.perms, but LPRng still accepts the
connection before determining that the client is not allowed to
connect/print). The patch is available from:
http://www.uku.fi/~jhuuskon/Patches/
(I have used the patch on my homenet, but I would appreciate if more
people could have a look at it before using in production).

I've also made a patch for LPRng to only listen on specified interface
(eg. 127.0.0.1). More recent LPRng (3.7.x??) already has similar option.
Using this might be worthwhile if you'll only need to allow local (from
the same machine) clients to print (i.e not on a central print server).

Any feedback/discussion is welcome.

-Jarno

-- 
Jarno Huuskonen - System Administrator   |  Jarno.Huuskonen@uku.fi
University of Kuopio - Computer Center   |  Work:   +358 17 162822
PO BOX 1627, 70211 Kuopio, Finland       |  Mobile: +358 40 5388169



Relevant Pages

  • SUMMARY: Solaris 8 Recommended Patches Broke LPRng
    ... Found the problem to be caused by patch 109320-13. ... After the patch cluster install, only root or members of the wheel group ... could print using LPRng. ...
    (SunManagers)
  • RE: Underlying connection was closed
    ... When you say, this patch applied to 1.1, do you mean we ... configuration be incorrect as this happens ... Web Services Client: ... >The underlying connection was closed. ...
    (microsoft.public.dotnet.framework.webservices)
  • Re: Grr...
    ... entered my password and "We could not authenticate your login..." ... Looked up the number for Customer Support (after going through SEVERAL ... the client hadn't been updated. ... checking uo.stratics there HAD been a client patch last week. ...
    (rec.games.computer.ultima.online)
  • Re: Grr...
    ... Looked up the number for Customer Support (after going through SEVERAL ... trees of menus) and finally got a nice young Indian gentleman who ... the client hadn't been updated. ... checking uo.stratics there HAD been a client patch last week. ...
    (rec.games.computer.ultima.online)
  • Re: web updates that work with binary patches?
    ... Which support running the binary patch on the client to ... >with regular files (not binary patches). ...
    (borland.public.delphi.thirdpartytools.general)