m (typo) |
No edit summary |
||
Line 1: | Line 1: | ||
= Workstation: Disable firewall = | |||
== Summary == | |||
The firewalld service will not be enabled by default in the workstation product. | |||
== Owner == | == Owner == | ||
* Name: [[User:mclasen| Matthias Clasen]] | |||
* Name: [[User: | |||
<!-- Include you email address that you can be reached should people want to contact you about helping with your change, status is requested, or technical issues need to be resolved. If the change proposal is owned by a SIG, please also add a primary contact person. --> | <!-- Include you email address that you can be reached should people want to contact you about helping with your change, status is requested, or technical issues need to be resolved. If the change proposal is owned by a SIG, please also add a primary contact person. --> | ||
* Email: | * Email: mclasen@redhat.com | ||
* Release notes owner: <!--- To be assigned by docs team [[User:FASAccountName| Release notes owner name]] <email address> --> | * Release notes owner: <!--- To be assigned by docs team [[User:FASAccountName| Release notes owner name]] <email address> --> | ||
<!--- UNCOMMENT only for Changes with assigned Shepherd (by FESCo) | <!--- UNCOMMENT only for Changes with assigned Shepherd (by FESCo) | ||
* FESCo shepherd: [[User:FASAccountName| Shehperd name]] <email address> | * FESCo shepherd: [[User:FASAccountName| Shehperd name]] <email address> | ||
--> | --> | ||
* Product: Workstation | |||
* Product: | * Responsible WG: Workstation | ||
* Responsible WG: | |||
== Current status == | == Current status == | ||
* Targeted release: [[Releases/ | * Targeted release: [[Releases/21 | Fedora 21 ]] | ||
* Last updated: | * Last updated: 2014-04-03 | ||
<!-- After the change proposal is accepted by FESCo, tracking bug is created in Bugzilla and linked to this page | <!-- After the change proposal is accepted by FESCo, tracking bug is created in Bugzilla and linked to this page | ||
Bugzilla states meaning as usual: | Bugzilla states meaning as usual: | ||
Line 58: | Line 30: | ||
== Detailed Description == | == Detailed Description == | ||
The current level of integration into the desktop and applications does not justify enabling the firewalld service by default. Additionally, the set of | |||
zones that it offers is excessive and not user-friendly. Therefore, we will disable the firewall service while we are working on a more user-friendly way | |||
to deal with network-related privacy issues. | |||
It will of course still be possible to enable the firewall manually. | |||
== Benefit to Fedora == | == Benefit to Fedora == | ||
The Workstation will boot faster, and the firewall will not interfere with sharing protocols such as DAAP, UPnP and others. | |||
== Scope == | == Scope == | ||
* Proposal owners: | * Proposal owners: | ||
* Other developers: | * Other developers: Add a Workstation-specific service configuration (preset ?) to the firewalld package that disables firewalld for the Workstation product | ||
* Release engineering: | * Release engineering: No action required | ||
* Policies and guidelines: | * Policies and guidelines: No action required | ||
== Upgrade/compatibility impact == | == Upgrade/compatibility impact == | ||
Existing systems will keep their service configuration, including the enabled-by-default firewall. | |||
== How To Test == | == How To Test == | ||
# Install the Workstation. | |||
# Log in | |||
# run systemctl status firewalld.service | |||
# expected result: the service is not active | |||
== User Experience == | == User Experience == | ||
Applications that are using sharing protocols such as DAAP or UPnP will work out of the box, without the need to tweak or disable the firewall service. | |||
== Dependencies == | == Dependencies == | ||
No dependencies. | |||
== Contingency Plan == | == Contingency Plan == | ||
* Contingency mechanism: If the firewalld service can not be disabled, install a simplified set of firewall zones, ideally just 'Home', 'Public' and 'Unknown', and ensure that networks are placed into the 'Home' zone by default | |||
* Contingency mechanism: | * Contingency deadline: F21 beta | ||
* Blocks release? No | |||
* Contingency deadline: | * Blocks product? Workstation | ||
* Blocks release? | |||
* Blocks product? | |||
== Documentation == | == Documentation == | ||
This upstream [https://bugzilla.gnome.org/show_bug.cgi?id=727580 bug] discusses improved network privacy handling. | |||
== Release Notes == | == Release Notes == | ||
The firewalld service is not enabled by default for the Workstation product. To enable it, run systemctl enable firewalld.service. | |||
[[Category:ChangeReadyForWrangler]] | |||
[[Category: | [[Category:SystemWideChange]] | ||
Revision as of 04:08, 4 April 2014
Workstation: Disable firewall
Summary
The firewalld service will not be enabled by default in the workstation product.
Owner
- Name: Matthias Clasen
- Email: mclasen@redhat.com
- Release notes owner:
- Product: Workstation
- Responsible WG: Workstation
Current status
- Targeted release: Fedora 21
- Last updated: 2014-04-03
- Tracker bug: <will be assigned by the Wrangler>
Detailed Description
The current level of integration into the desktop and applications does not justify enabling the firewalld service by default. Additionally, the set of zones that it offers is excessive and not user-friendly. Therefore, we will disable the firewall service while we are working on a more user-friendly way to deal with network-related privacy issues.
It will of course still be possible to enable the firewall manually.
Benefit to Fedora
The Workstation will boot faster, and the firewall will not interfere with sharing protocols such as DAAP, UPnP and others.
Scope
- Proposal owners:
- Other developers: Add a Workstation-specific service configuration (preset ?) to the firewalld package that disables firewalld for the Workstation product
- Release engineering: No action required
- Policies and guidelines: No action required
Upgrade/compatibility impact
Existing systems will keep their service configuration, including the enabled-by-default firewall.
How To Test
- Install the Workstation.
- Log in
- run systemctl status firewalld.service
- expected result: the service is not active
User Experience
Applications that are using sharing protocols such as DAAP or UPnP will work out of the box, without the need to tweak or disable the firewall service.
Dependencies
No dependencies.
Contingency Plan
- Contingency mechanism: If the firewalld service can not be disabled, install a simplified set of firewall zones, ideally just 'Home', 'Public' and 'Unknown', and ensure that networks are placed into the 'Home' zone by default
- Contingency deadline: F21 beta
- Blocks release? No
- Blocks product? Workstation
Documentation
This upstream bug discusses improved network privacy handling.
Release Notes
The firewalld service is not enabled by default for the Workstation product. To enable it, run systemctl enable firewalld.service.