Skip to content

noVNC missing Authentication and Security  #521

@fffaraz

Description

@fffaraz

I have installed latest version of Archipel Agent and Client from nightly builds.
Almost everything works fine.
But I think there is a security problem with VNC client.
Everyone in my network can access VM's vnc without any authentication using a noVNC client and connect to my Archipel agent server on port 6900, ...

Is it ok ?!!
Is it the way it should be or am I doing something wrong ?

I think Achipel agent should create and assign a random password using livbirt (or qemu's monitor console) and also websockify should start listening on the proxy port only for seconds after a request for VM's vnc console in Archipel Client.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions