LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 01-02-2007, 03:04 PM   #1
jarome
LQ Newbie
 
Registered: Mar 2004
Posts: 6

Rep: Reputation: 0
cupsd does not read hosts.allow/deny properly


I am running SUSE 10.2. If I try to add a printer in YaST2, or use the cups admin GUI, cupsd starts spewing our GBs of error messages, and I have to turn it off.

I need to have hosts.allow to filter out every site except where I work and my local net so that I do not get attacked on my ssh port. The two hosts. files work fine with sshd.

But for cupsd, I get messages like:
Jan 2 10:07:12 romeja cupsd: warning: /etc/hosts.allow, line 62: Unable to handle client address: unknown
Jan 2 10:07:12 romeja cupsd: warning: /etc/hosts.allow, line 64: Unable to handle client address: unknown
Jan 2 10:07:12 romeja cupsd: warning: /etc/hosts.allow, line 65: Unable to handle client address: unknown
Jan 2 10:07:12 romeja cupsd: warning: /etc/hosts.allow, line 66: Unable to handle client address: unknown
Jan 2 10:07:12 romeja cupsd: warning: /etc/hosts.deny, line 5: Unable to handle client address: unknown
Jan 2 10:07:12 romeja cupsd: warning: /etc/hosts.deny, line 5: Unable to handle client address: unknown

My hosts.allow has
ALL : 192.168.1. : ALLOW
ALL : .mycompany.org : ALLOW
ALL : 127.0.0.1, localhost : ALLOW
cupsd : 192.168.1.10 : ALLOW
cupsd : 127.0.0.1 : ALLOW

hosts.deny has:
ALL : ALL EXCEPT 192.168.1., 127.0.0.1, LOCAL

I have tried numerous variations on these with no success.

The cups log gives a zillion lines like:
[26/Dec/2006:22:11:14 -0500] tcp_wrappers refused connection from unknown. See /etc/hosts.allow and /etc/hosts.deny.

I am stuck. Please help.

Jim
 
Old 01-03-2007, 01:42 PM   #2
anomie
Senior Member
 
Registered: Nov 2004
Location: Texas
Distribution: RHEL, Scientific Linux, Debian, Fedora
Posts: 3,935
Blog Entries: 5

Rep: Reputation: Disabled
Just a thought -

This is on my FC5 box:
Code:
[hector@troy ~]$ whereis cupsd
cupsd: /usr/sbin/cupsd /usr/share/man/man8/cupsd.8.gz
[hector@troy ~]$ ldd /usr/sbin/cupsd | grep 'libwrap.so' 
[hector@troy ~]$
There is no tcp_wrappers support compiled into cupsd in my case. If the same is true for you, you will not be able to use the hosts.allow file to control access. Instead you'll have to add a rule to your iptables INPUT chain.
 
Old 01-03-2007, 02:50 PM   #3
jarome
LQ Newbie
 
Registered: Mar 2004
Posts: 6

Original Poster
Rep: Reputation: 0
Why would cupsd be parsing the two hosts. files then? But I may have to resort to just using iptables.

Thanks for your suggestion. I will check it.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] question about hosts.allow/hosts.deny Wim Sturkenboom Linux - Security 9 05-30-2006 01:33 AM
/etc/hosts.deny/hosts.allow have no effect on sshd access bganesh Linux - Security 4 05-04-2006 08:06 PM
hosts.allow & hosts.deny question... jonc Linux - Security 9 03-05-2005 09:41 PM
Adding shell commands to hosts.deny and hosts.allow ridertech Linux - Security 3 12-29-2003 03:52 PM
hosts.deny and hosts.allow defaults? gui10 Linux - Security 5 12-20-2001 01:57 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 01:46 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration