Gordon Saksena
unread,Mar 22, 2022, 7:31:26 PM3/22/22Sign in to reply to author
Sign in to forward
You do not have permission to delete messages in this group
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to Shiv Patil, Ignaty Leshchiner, David Roazen, Gad Getz, Meifang Qi, Steven Schumacher, Esther Rheinbay, Ting Wu, Chet Birger, Daniel Rosebrock, David Isaac Heiman, gdac, Chip Stewart, Francois Aguet, Sam Wiseman, William Hedglon, David Bernick, Chris Marko
Presumably the background behind this is that the infosec community is now on high alert, given the war in Ukraine, and that unpatched servers have been implicated in a large proportion of successful attacks, used as network entry points or as staging for lateral movement within the network.
I wonder whether another option might be acceptable other than upgrading or shutting down the node: perhaps the node could be placed into isolation, like was done in the past for Docker nodes that allowed end users to sudo. Or, related, a vlan containing perhaps a handful of nodes and its own NFS share, which I believe is how the lab networks are currently set up. I expect this would be unpalatable to the end users for nodes used for general purpose, but might wind up being a less painful path forward for nodes dedicated to legacy custom applications. Just a thought, as I don't have authority over these nodes.
Gordon
Hi All,
Consistent with Broad Information Systems Acceptable Use policy(Section 6.4), it is important that we continue running on supported platforms. We are reaching out to you one last time about the following RHEL6 hosts that need to get upgraded, as limited vendor maintenance support ended November 2020. Since we have not heard from you in more than six months, we are planning to shut down
these hosts in 30 days (4/21/2022).
Please refer to SN Ticket INC0232068 for more details and let us know if you have any questions or concerns.
Hosts:
cga-kras
voki
muon
vgdac1
fbdev
cga03
Thanks
Team Devnull
BITS - Broad Institute