From: Dr Fields James Bruce <bfields@fieldses.org>
To: Jeff Layton <jlayton@redhat.com>
Cc: Trond Myklebust <trond.myklebust@primarydata.com>,
linux-nfs@vger.kernel.org,
Adamson William Andros <androsadamson@gmail.com>,
Lever Charles Edward <chuck.lever@oracle.com>,
simo@redhat.com
Subject: Re: v4.0 CB_COMPOUND authentication failures
Date: Tue, 8 Apr 2014 11:13:54 -0400 [thread overview]
Message-ID: <20140408151354.GG3882@fieldses.org> (raw)
In-Reply-To: <20140408110420.62e060ef@tlielax.poochiereds.net>
On Tue, Apr 08, 2014 at 11:04:20AM -0400, Jeff Layton wrote:
> On Tue, 8 Apr 2014 10:46:52 -0400
> Dr Fields James Bruce <bfields@fieldses.org> wrote:
>
> > On Tue, Apr 08, 2014 at 10:23:37AM -0400, Trond Myklebust wrote:
> > >
> > > On Apr 8, 2014, at 10:03, J. Bruce Fields <bfields@fieldses.org> wrote:
> > >
> > > > On Tue, Apr 08, 2014 at 09:49:03AM -0400, Jeff Layton wrote:
> > > >> On Tue, 8 Apr 2014 08:35:01 -0400
> > > >> "J. Bruce Fields" <bfields@fieldses.org> wrote:
> > > >>
> > > >>> On Tue, Apr 08, 2014 at 08:21:40AM -0400, Jeff Layton wrote:
> > > >>>> I've recently been hunting down some problems with delegation handling
> > > >>>> and have run across a problem with the client authenticates CB_COMPOUND
> > > >>>> requests. I could use some advice on how best to fix it.
> > > >>>>
> > > >>>> Specifically, check_gss_callback_principal() tries to look up the
> > > >>>> callback client and then tries to compare the ticket in it against the
> > > >>>> clp->cl_hostname:
> > > >>>>
> > > >>>> /* Expect a GSS_C_NT_HOSTBASED_NAME like "nfs@serverhostname" */
> > > >>>>
> > > >>>> if (memcmp(p, "nfs@", 4) != 0)
> > > >>>> return 0;
> > > >>>> p += 4;
> > > >>>> if (strcmp(p, clp->cl_hostname) != 0)
> > > >>>> return 0;
> > > >>>> return 1;
> > > >>>>
> > > >>>> The problem is that there is no guarantee that those hostnames will be
> > > >>>> the same. If, for instance, I mount "foo:/" and the SPN is
> > > >>>> "nfs/foo.bar.baz" that strcmp will return true, and the CB_COMPOUND
> > > >>>> request will get tossed out [1]. Ditto if I happen to mount a CNAME of the
> > > >>>> server.
> > > >>>
> > > >>> It sounds like a bug to me that the mount is succeeding without the name
> > > >>> matching.
> > > >>>
> > > >>> The security provided by krb5 is much weaker if we don't check that the
> > > >>> name provided on the commandline matches what the server authenticates
> > > >>> as.
> > > >>>
> > > >>
> > > >> The logic in gssd for this is pretty awful.
> > > >>
> > > >> It will basically trust DNS if there is no '.' in the hostname that was
> > > >> used at mount time. That'll make it take the address and
> > > >> reverse-resolve it.
> > > >
> > > > Argh, OK, I guess this is the compromise Simo made in "Avoid DNS reverse
> > > > resolution for server names (take 3)".
> > > >
> > > >> We could add yet another band-aid and make it so that DNS is never
> > > >> trusted. I'll note that for cifs, we took that route. You have to mount
> > > >> the canonical name of the server in order to use krb5.
> > > >
> > > > I wish we could do that, but I suppose it's too harsh to break
> > > > already-working fstabs. Maybe we could phase it in somehow.
> > > >
> > > >>>> Now that we try to use krb5 on the callback channel even when sec=sys
> > > >>>> is specified, this is very problematic.
> > > >>>
> > > >>> And similarly I think the attempt to opportunistically use krb5 for
> > > >>> state management should fail and fall back on auth_sys if the server's
> > > >>> name doesn't match.
> > > >>>
> > >
> > > This suggestion makes no sense to me at all. How does it help to fall back to using weak security when the strong security checks fail?
> >
> > It'd fix this particular problem.
> >
> > But, I don't know, I'm frankly confused about our security design for
> > the NFSv4 state.
> >
> > When we insist on krb5 (and checked the server name correctly), and
> > failed without it, then I feel like I understand what we're doing. Once
> > we start trying it and then falling back (as I understand happens for
> > the krb5 state in the auth_sys case) I get confused.
> >
> > > >> Like Trond pointed out, the problem is that gssd doesn't give us that
> > > >> info currently. We could change it to do that of course, but that
> > > >> basically means revving the downcall.
> > > >
> > > > It might be easier to rev the upcall so that the kernel could ask gssd
> > > > to do strict checking? Since it's just a bunch of name=value pairs it
> > > > shouldn't be a huge pain to revise.
> > >
> > > So what would trigger the kernel to ask for strict checking? Do we add a mount option that says “fail if the server doesn’t authenticate itself”? That would be hard to combine with security negotiation, since it only makes sense for RPCSEC_GSS authentication.
> >
> > I was thinking about only doing it in the state-establishment case.
> > (Since we won't know how to authenticate the callbacks in that case.)
> >
> > But that would screw up krb5 mounts, I guess, never mind.
> >
> > Using a fqdn implicitly requests strict checking so a mount option would
> > seem redundant.
> >
>
> So I guess we have two options to fix this:
>
> 1) Change gssd to require the canonical fqdn and not rely on name
> resolution. Unfortunately, I think the MIT krb5 libs will still
> canonicalize the hostnames by default, so this might not actually fix
> anything. See:
>
> http://web.mit.edu/kerberos/krb5-devel/doc/admin/princ_dns.html
>
> ...or...
>
> 2) Loosen or somehow fix the check in check_gss_callback_principal().
> One possibility might be to do a dns_resolver upcall for the host
> portion of the SPN, and then compare the address with the server's
> address. Ugly, but since we already trust DNS implicitly I guess it's
> no less secure...
I thought Kerberos wasn't supposed to require trust in DNS. So I feel
confused. Cc'ing Simo in hopes he can set us all straight.
--b.
next prev parent reply other threads:[~2014-04-08 15:13 UTC|newest]
Thread overview: 39+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-04-08 12:21 v4.0 CB_COMPOUND authentication failures Jeff Layton
2014-04-08 12:35 ` J. Bruce Fields
2014-04-08 12:42 ` Trond Myklebust
2014-04-08 12:57 ` Dr Fields James Bruce
2014-04-08 13:49 ` Jeff Layton
2014-04-08 14:03 ` J. Bruce Fields
2014-04-08 14:22 ` Jeff Layton
2014-04-08 14:41 ` Jeff Layton
2014-04-08 14:47 ` J. Bruce Fields
2014-04-08 14:23 ` Trond Myklebust
2014-04-08 14:46 ` Dr Fields James Bruce
2014-04-08 15:04 ` Jeff Layton
2014-04-08 15:13 ` Dr Fields James Bruce [this message]
2014-04-08 17:25 ` Simo Sorce
2014-04-08 17:28 ` Jeff Layton
2014-04-08 16:22 ` Trond Myklebust
2014-04-08 16:40 ` Dr Fields James Bruce
2014-04-08 17:30 ` Trond Myklebust
2014-04-08 17:55 ` Jeff Layton
2014-04-08 18:03 ` Trond Myklebust
2014-04-08 18:24 ` Jeff Layton
2014-04-08 18:45 ` Trond Myklebust
2014-04-08 18:49 ` Jeff Layton
2014-04-08 18:03 ` Dr Fields James Bruce
2014-04-08 16:44 ` Jeff Layton
2014-04-08 17:27 ` Simo Sorce
2014-04-08 17:30 ` Jeff Layton
2014-04-08 17:39 ` Frank Filz
2014-04-08 17:59 ` Jeff Layton
2014-04-08 18:06 ` Simo Sorce
2014-04-08 22:44 ` Frank Filz
2014-04-08 22:52 ` Simo Sorce
2014-04-08 23:31 ` Frank Filz
2014-04-08 18:01 ` Simo Sorce
2014-04-08 18:04 ` Jeff Layton
2014-04-08 18:08 ` Simo Sorce
2014-04-08 18:11 ` Dr Fields James Bruce
2014-04-08 18:52 ` Simo Sorce
2014-04-08 19:01 ` Trond Myklebust
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20140408151354.GG3882@fieldses.org \
--to=bfields@fieldses.org \
--cc=androsadamson@gmail.com \
--cc=chuck.lever@oracle.com \
--cc=jlayton@redhat.com \
--cc=linux-nfs@vger.kernel.org \
--cc=simo@redhat.com \
--cc=trond.myklebust@primarydata.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.