WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
Xen

xen-devel

[Top] [All Lists]

[Xen-API] Re: [Xen-devel] Is it possible to access XenStore remotely?

To: weiming <zephyr.zhao@xxxxxxxxx>
Subject: [Xen-API] Re: [Xen-devel] Is it possible to access XenStore remotely?
From: Tim Post <echo@xxxxxxxxxxxx>
Date: 2009年8月24日 21:03:19 +0800
Cc: "xen-devel@xxxxxxxxxxxxxxxxxxx" <xen-devel@xxxxxxxxxxxxxxxxxxx>, Vincent Hanquez <vincent.hanquez@xxxxxxxxxxxxx>, "xen-api@xxxxxxxxxxxxxxxxxxx" <xen-api@xxxxxxxxxxxxxxxxxxx>
Delivery-date: 2009年9月08日 07:16:38 -0700
Envelope-to: www-data@xxxxxxxxxxxxxxxxxxx
In-reply-to: <add59a3f0908200700r2a2adebv6009b07645af6cd6@xxxxxxxxxxxxxx>
List-help: <mailto:xen-api-request@lists.xensource.com?subject=help>
List-id: Discussion of API issues surrounding Xen <xen-api.lists.xensource.com>
List-post: <mailto:xen-api@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/mailman/listinfo/xen-api>, <mailto:xen-api-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/mailman/listinfo/xen-api>, <mailto:xen-api-request@lists.xensource.com?subject=unsubscribe>
References: <add59a3f0908191924i685933bcl84e32487a3a5e260@xxxxxxxxxxxxxx> <4A8D1650.4040902@xxxxxxxxxxxxx> <add59a3f0908200700r2a2adebv6009b07645af6cd6@xxxxxxxxxxxxxx>
Reply-to: echo@xxxxxxxxxxxx
Sender: xen-api-bounces@xxxxxxxxxxxxxxxxxxx
Hi,
On Thu, 2009年08月20日 at 10:00 -0400, weiming wrote:
> Hi VIncent,
>
> Yes, I'm considering adding a TCP socket for xenstored. 
>
> Since xen apis can be called remotely, there's no reason to prevent
> accessing xenstore in the same way.
We did this when working on an experiment to use Xen on a single system
image. Our implementation utilized a private back-end LAN which was not
exposed to dom-u's that faced the public, so no authentication mechanism
was needed. We needed to set up remote watches to facilitate a sort of
'cluster wide upstart for xen'. 
I would warn you, XenStore is fragile and often fickle, I've crashed it
many times within a guest while working on split drivers for various
character devices.
If you expose it via sockets, without having the API as a buffer to take
most 'brute force' abuse, be sure to code very defensively and utilize
iptables to restrict access. While xend can be re-started , xenstored
can not.
Yes, API's can be called remotely, however some diligence prevails
before the API actually talks to xenstore.
Cheers,
--Tim
>
> thanks,
> Weiming
>
> On Thu, Aug 20, 2009 at 5:24 AM, Vincent Hanquez
> <vincent.hanquez@xxxxxxxxxxxxx> wrote:
>
> weiming wrote:
> Hi,
>
> Is it possible to read/write the xenstore from another
> physical machine?
>
> I know it uses Unix socket. So it looks hard to access
> it remotely, isn't it?
> Hi weiming,
>
> whilst it's not possible at the moment and certainly a bad
> idea security wise, make xenstored listen on a tcp socket
> along with the unix socket is very easy.
>
> cheers,
> --
> Vincent
>
>
> _______________________________________________
> Xen-devel mailing list
> Xen-devel@xxxxxxxxxxxxxxxxxxx
> http://lists.xensource.com/xen-devel 
-- 
Monkey + Typewriter = Echoreply ( http://echoreply.us )
_______________________________________________
xen-api mailing list
xen-api@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/mailman/listinfo/xen-api
<Prev in Thread] Current Thread [Next in Thread>
Previous by Date: Re: [Xen-devel] Re: [PATCH] VT-d: prevent dom0 to use VT-d HW , Keir Fraser
Next by Date: [Xen-API] Re: [Xen-devel] Is it possible to access XenStore remotely? , Tim Post
Previous by Thread: [Xen-devel] [PATCH] Fix typo in p2m_pod_set_cache_target , George Dunlap
Next by Thread: [Xen-API] Re: [Xen-devel] Is it possible to access XenStore remotely? , Tim Post
Indexes: [Date] [Thread] [Top] [All Lists]

Copyright ©, Citrix Systems Inc. All rights reserved. Legal and Privacy
Citrix This site is hosted by Citrix

AltStyle によって変換されたページ (->オリジナル) /