On Tue, 20 Mar 2001, Austad, Jay wrote:

> rsync is another option, however, with rsync if someone does compromise your
> webserver, they are going to have a better chance of getting a shell on your
> tape server if you have rsync set up to do it's thing automatically, because
> the .known_hosts file for sshd on the tape server will allow the webserver
> to login with no password.  Even if you use an account that has a shell of
> /bin/false, it's not the most comforting thought in the world.

My understanding of the suggestion was to set up another Linux box inside
the network that would be backed up via the BackupExec agent. The
inside-the-firewall box would rsync nightly with the Web server via ssh. Do
I have that straight.

-Tim

--
Tim Wilson      | Visit Sibley online:         | Check out:
Henry Sibley HS | http://www.isd197.k12.mn.us/ | http://www.zope.org/
W. St. Paul, MN |                              | http://slashdot.org/
wilson at visi.com |   <dtml-var pithy_quote>     | http://linux.com/