[torquedev] [Bug 211] pbs_sched does not read TRQ_IFNAME

bugzilla-daemon at supercluster.org bugzilla-daemon at supercluster.org
Wed Aug 22 10:28:02 MDT 2012


--- Comment #12 from Taras <taras.shapovalov at brightcomputing.com> 2012-08-22 10:28:01 MDT ---
Hi Michael,

> I'm sure Bright Computing has security people on staff.  I bet one of them
> could go into more detail for you, but the short answer is that you never want
> private services listening publicly.  It's an unnecessary risk.

Sure, of cause I agree (and secure people will agree as well) that this is a
bad practice in general. 


1. On computing clusters usually all ports (except several) are closed for
external interfaces.
2. PBS Pro pbs_sched and pbs_mom listen to any (ok, lets suppose for now there
are no security people in PBS Pro team).
3. TORQUE pbs_server listens to any:
tcp  0      0*    LISTEN   3682/pbs_server 

Could you, please, explain if you follow the rule "do not listen to any" then
why TORQUE pbs_server does not follow this rule as well?

