ruleqa zones: SSH access and risk of intrusion

From: John Hardin
Date: Mon Dec 05 2011 - 16:30:42 GMT
To: SpamAssassin Developers list


One thing I noticed while troubleshooting the recent ruleqa problems on
the zone VMs was the number of failed SSH logins to random and system
accounts. I was contemplating putting in explicit DenyUsers for the
various system accounts, but I was a little reluctant to do system-level
stuff like that without infra involvement.

Should we (ask infra to) put something like fail2ban on the zones boxes,
and add explicit DenyUsers for the existing system accounts (like

More generally: how autonomous are we the SA devs in administration of the
zone VMs?

I was reminded by this:

