jkeating@redhat.com wrote on 05/31/2012 12:17:39 -0700:
Also, are you really sure we only allow one install ssh session? 'cause I've sshed in as root@ multiple times in my testing, no restriction. Of course, can't do multiple install@ because the shell for that user is /sbin/anaconda :)
Yes, I've verified that as well. You can have multiple ssh root@ip open at once.
Are there any other opinions here?
I agree that if we change the default to open a shared vnc session and allow the user to specify a vncpassword (which we already do), then that should address any security concerns.
Mark
anaconda-devel@lists.stg.fedoraproject.org