Subject Re: [ib-support] article: Securing Firebird Installation For Linux Shared Hosting
Author Edwin Pratomo
Steven Haryanto wrote:
>
> http://steven.haryan.to/writings/securing-firebird-hosting/
>
> this is the result of some research done by a complete newbie (which is
> yours truly :-) while trying to setup firebird for shared hosting. i'm
> really hoping for some feedback so i can improve the guide.

Very interesting and well-written. Seems like you're more an advanced
newbie! :-)

Maybe you'd want to add in Step 4 (blocking remote users) about secure
tunneling in case a client wants to connect remotely. Several ways to
accomplish this are by using zebedee (a tutorial already published in
ibphoenix), ssh, or as you wrote in a local magazine here, using
stunnel.

Some people also use /etc/hosts.(deny|allow) to restrict remote
connections, though I haven't tried that myself. Seems like fb is built
with libwrap.

Setting limit on maximum memory used by ibserver is also one thing
missing from the article.

--
rgds,
Edwin