-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On 2010-08-03 12:46, Johannes Meixner wrote:
Hello,
On Jul 26 20:13 Carlos F Lange wrote:
In the Firewall Configuration of YaST, the list of services to allow for the External Zone no longer contains "cups". Instead, When setting up the Printer Configuration to accept printer announcements from CUPS servers, YaST pops up a recommendation to open UDP port 631 in the firewall.
There should be no recommendation to open any port in the firewall. But the current popup texts could be misunderstood to do it. Therefore I filed https://bugzilla.novell.com/show_bug.cgi?id=627799
Any sane reason to make this process less convenient?
This is intentionally to avoid that almost all normal users open a security hole because in the usual network environments, the IPP port should never be opened for the EXT zone, see http://en.opensuse.org/SDB:CUPS_and_SANE_Firewall_settings
But the "external" network is also the internal one in many cases, such as mine. There is an ADSL router that connects to Internet. Behind there is an internal network, which some prefer to consider as external in the firewall config for extra protection. But it is this one which has to be opened to connect to other machines in the local network. - -- Cheers / Saludos, Carlos E. R. (from 11.2 x86_64 "Emerald" GM (Elessar)) -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.12 (GNU/Linux) Comment: Using GnuPG with SUSE - http://enigmail.mozdev.org/ iEYEARECAAYFAkxZubEACgkQU92UU+smfQUz0ACghGuxKjKg5gCVlSxLU+Y+TMlS 9pEAoIx6RNoSc9wlgPUbaJHCFRYXYgcZ =a7Ex -----END PGP SIGNATURE----- -- To unsubscribe, e-mail: opensuse+unsubscribe@opensuse.org For additional commands, e-mail: opensuse+help@opensuse.org