3.3 KiB
Open issues
As of 2026-07-16 (live scan on koopa). No secrets.
I-2026-07-16-01 — firewalld: Nym ports on koopa unverified
| Severity | high (for public Nym reachability) |
| Host | koopa |
| Status | open |
VeciGate DNATs 1789/tcp+udp, 1790/tcp, 51822/udp → koopa.
Without matching firewalld allow rules on koopa, traffic dies on the host.
Agent could not run firewall-cmd (sudo password required).
# on koopa (with sudo)
sudo firewall-cmd --permanent --add-port=1789/tcp
sudo firewall-cmd --permanent --add-port=1789/udp
sudo firewall-cmd --permanent --add-port=1790/tcp
sudo firewall-cmd --permanent --add-port=51822/udp
sudo firewall-cmd --reload
sudo firewall-cmd --list-ports
I-2026-07-16-02 — Nym node not bonded / not in public explorers
| Severity | medium (visibility on the Nym network) |
| Host | koopa (koopa-nym) |
| Status | open |
Container is running (mixnode); API on 9080 answers.
Without a bond in the Nym wallet the node typically does not show up in Harbour Master / network explorers (unlike Tor after ORPort publish).
See also: configs/nym/PUBLIC-LISTING.md.
Logs: WARN validator.nymtech.net/api/.../refresh-described → 404 (API path/version; node still runs mixmode).
Identity key (public): 55gPqeyHHj4CwpVZXLEQy9MjSvVTVXM8t2pMmNCH2MsW
I-2026-07-16-03 — podman-restart.service enabled, inactive this session
| Severity | low (until reboot is tested) |
| Host | koopa (user hernani) |
| Status | open / expected until reboot |
systemctl --user is-enabled podman-restart = enabled,
is-active = inactive (oneshot; has not run this boot session).
After reboot:
systemctl --user is-active podman-restart.service
podman ps -a --filter should-start-on-boot=true --format '{{.Names}} {{.Status}}'
I-2026-07-16-04 — Stray container kind_taussig
| Severity | low (hygiene) |
| Host | koopa |
| Status | open |
Container Up ~5 days: kind_taussig (debian:bookworm-slim), one-off wallet/DEB test script, restart=no, not a production name.
Candidate to stop/remove when logs are no longer needed:
podman stop kind_taussig
podman rm kind_taussig
I-2026-07-16-05 — Old exited Podman containers (clutter)
| Severity | low (hygiene) |
| Host | koopa |
| Status | open |
Several Exited containers (months/years old), e.g. pensive_dubinsky,
hardcore_edison, taler-exchange-no-network, debian00, …
No autostart; only clutter podman ps -a.
Optional cleanup: podman container prune (exited only, after review).
I-2026-07-16-06 — Nym HTTP API listens on *:9080
| Severity | low–medium (attack surface) |
| Host | koopa |
| Status | open (as configured in compose) |
ss shows *:9080 (rootlessport). No VeciGate DNAT for 9080.
Usually not reachable from WAN without NAT; reachable from LAN.
Optional harden: publish only 127.0.0.1:9080:8080 in compose.
Not an issue (scan)
- All production
should-start-on-bootcontainers Up - No failed user units
- Taler ports 9010–9015 respond (401/302 OK)
- Linger=yes, container-* units enabled