Digi Control документация
Remote Administration на локалния сървър
Enablement, source allowlist, enrollment, pairing и trusted clients.
Какво обхваща
- Remote Administration е disabled до explicit enable. Service, firewall source allowlist и pairing са separate controls.
- Enrollment window е time-limited, обикновено 15 minutes; fingerprints/identities се сравняват на двете страни.
- Trusted client може да бъде disabled, revoked или deleted; revoke изисква new pairing.
- Remote channel приема само allowed validated operations и няма arbitrary shell.
Как се работи
- Добавете single source host.
- Enable Remote Administration.
- Open enrollment when ready.
- Pair/compare fingerprints.
- Close enrollment.
- Review trust/allowlist.
Важни правила
- Disable е temporary; Revoke terminates trust.
- Allowlist не трябва да е по-широк от нужното.
- Всяка remote command има actor/target/contract/result/audit.