Re: NFS4 authentification / fsuid

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: J. Bruce Fields
Date: Thursday, August 30, 2007 - 8:12 am

On Thu, Aug 30, 2007 at 04:42:33PM +0200, Jan Engelhardt wrote:

The server will run with an fsuid equal to the user that authenticated,
you're correct.  So if you require krb5 access on an export, then nfs
access to a file on the export should be permitted only on rpc's that
are authenticated using credentials of a user with permission to access
the file.

Trond's pointing out that when you give the client your krb5 credentials
you're trusting it to do only what you tell it to with them.  You have
to trust the client's kernel at the very least, and also root on that
client, for the forseeable future.

--b.
-
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
NFS4 authentification / fsuid, Jan Engelhardt, (Thu Aug 30, 7:12 am)
Re: NFS4 authentification / fsuid, Trond Myklebust, (Thu Aug 30, 7:29 am)
Re: NFS4 authentification / fsuid, Trond Myklebust, (Thu Aug 30, 7:32 am)
Re: NFS4 authentification / fsuid, Jan Engelhardt, (Thu Aug 30, 7:42 am)
Re: NFS4 authentification / fsuid, Trond Myklebust, (Thu Aug 30, 8:04 am)
Re: NFS4 authentification / fsuid, J. Bruce Fields, (Thu Aug 30, 8:12 am)
Re: NFS4 authentification / fsuid, J. Bruce Fields, (Thu Aug 30, 2:44 pm)
Re: NFS4 authentification / fsuid, Satyam Sharma, (Thu Sep 6, 1:14 am)
Re: NFS4 authentification / fsuid, Satyam Sharma, (Thu Sep 6, 1:29 am)
Re: NFS4 authentification / fsuid, J. Bruce Fields, (Thu Sep 6, 8:06 am)
Re: NFS4 authentification / fsuid, J. Bruce Fields, (Thu Sep 6, 8:11 am)
Re: NFS4 authentification / fsuid, Trond Myklebust, (Thu Sep 6, 4:21 pm)
Re: NFS4 authentification / fsuid, Kyle Moffett, (Thu Sep 6, 4:30 pm)
Re: NFS4 authentification / fsuid, Trond Myklebust, (Thu Sep 6, 4:32 pm)
Re: NFS4 authentification / fsuid, Trond Myklebust, (Thu Sep 6, 4:35 pm)
Re: NFS4 authentification / fsuid, Kyle Moffett, (Thu Sep 6, 5:56 pm)
Re: NFS4 authentification / fsuid, Trond Myklebust, (Thu Sep 6, 10:14 pm)
Re: NFS4 authentification / fsuid, Kyle Moffett, (Thu Sep 6, 10:47 pm)
Re: NFS4 authentification / fsuid, Bernd Eckenfels, (Thu Sep 6, 11:37 pm)
Re: NFS4 authentification / fsuid, J. Bruce Fields, (Fri Sep 7, 8:34 am)
Re: NFS4 authentification / fsuid, Satyam Sharma, (Tue Sep 18, 4:12 pm)
Re: NFS4 authentification / fsuid, Satyam Sharma, (Tue Sep 18, 4:27 pm)
Re: NFS4 authentification / fsuid, Satyam Sharma, (Tue Sep 18, 4:44 pm)
Re: NFS4 authentification / fsuid, Satyam Sharma, (Tue Sep 18, 4:48 pm)
Re: NFS4 authentification / fsuid, Kyle Moffett, (Tue Sep 18, 10:16 pm)
Re: NFS4 authentification / fsuid, Satyam Sharma, (Wed Sep 19, 5:16 am)
Re: NFS4 authentification / fsuid, Kyle Moffett, (Wed Sep 19, 6:49 am)
Re: NFS4 authentification / fsuid, Satyam Sharma, (Wed Sep 19, 7:12 am)
Re: NFS4 authentification / fsuid, J. Bruce Fields, (Wed Sep 19, 8:01 am)
Re: NFS4 authentification / fsuid, Valdis.Kletnieks, (Wed Sep 19, 9:38 am)
Re: NFS4 authentification / fsuid, Satyam Sharma, (Thu Sep 20, 12:03 am)
Re: NFS4 authentification / fsuid, Satyam Sharma, (Thu Sep 20, 12:15 am)