<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[CARP and user privilege]]></title><description><![CDATA[<p dir="auto">Hello, all!</p>
<p dir="auto">I am in the middle of my first CARP setup.  The one thing that I noticed was Remote System Username, if you want to sync configuration settings.</p>
<p dir="auto">Security is a biggie in my company, and exposing a(nother) user that seems to require admin privileges doesn't seem very secure.</p>
<p dir="auto">Does anyone know the minimum privileges required for the user that can sync configuration between pfsense installation?</p>
<p dir="auto">Thanks ahead for your assistance.</p>
]]></description><link>https://forum.netgate.com/topic/74257/carp-and-user-privilege</link><generator>RSS for Node</generator><lastBuildDate>Sun, 15 Mar 2026 17:32:10 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/74257.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 02 Oct 2014 14:59:26 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to CARP and user privilege on Tue, 07 Oct 2014 15:29:40 GMT]]></title><description><![CDATA[<p dir="auto">Thank you for your reply.</p>
<p dir="auto">I am still not sure of the statement about having the distinctive interface - is there a way to bind a user to login only through specific interfaces, that I am unaware of?  As far as I see, a configured user can login through any allowed interface.</p>
<p dir="auto">HTTPS is good for encrypting the traffic, but exposing the system to yet another full admin user is what I need to secure.</p>
<p dir="auto">If a configured user can login through any interface, it would be nice to know what minimum privileges are needed for the CARP user.</p>
<p dir="auto">Thanks ahead of time for your replies.</p>
]]></description><link>https://forum.netgate.com/post/488071</link><guid isPermaLink="true">https://forum.netgate.com/post/488071</guid><dc:creator><![CDATA[jjavier]]></dc:creator><pubDate>Tue, 07 Oct 2014 15:29:40 GMT</pubDate></item><item><title><![CDATA[Reply to CARP and user privilege on Tue, 07 Oct 2014 12:14:01 GMT]]></title><description><![CDATA[<p dir="auto">Hi!</p>
<p dir="auto">If you use a distinct interface for FW sync as it's suggested there will be no security issue with a user who have admin privileges.</p>
<p dir="auto">Furthermore if you have your WebConfigurator set to use HTTPS protocol the sync communication is also encrypted.</p>
]]></description><link>https://forum.netgate.com/post/488032</link><guid isPermaLink="true">https://forum.netgate.com/post/488032</guid><dc:creator><![CDATA[viragomann]]></dc:creator><pubDate>Tue, 07 Oct 2014 12:14:01 GMT</pubDate></item></channel></rss>