From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail.saout.de ([127.0.0.1]) by localhost (mail.saout.de [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id sMotd8-8d2JQ for ; Fri, 28 Oct 2011 10:00:29 +0200 (CEST) Received: from v4.tansi.org (ns.km33513-03.keymachine.de [87.118.94.3]) by mail.saout.de (Postfix) with ESMTP for ; Fri, 28 Oct 2011 10:00:29 +0200 (CEST) Received: from gatewagner.dyndns.org (84-74-163-71.dclient.hispeed.ch [84.74.163.71]) by v4.tansi.org (Postfix) with ESMTPA id C64671404001 for ; Fri, 28 Oct 2011 10:00:27 +0200 (CEST) Date: Fri, 28 Oct 2011 10:00:26 +0200 From: Arno Wagner Message-ID: <20111028080025.GA20382@tansi.org> References: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: Subject: Re: [dm-crypt] encrypt NFS List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: dm-crypt@saout.de Dependst on your threat model. You could tunnel unencrypted NFS over some VPN tunnel (open VPN, e.g.). You could do a network-block-device export, whoch should be encryptable in the standard way. You could export NFS with a file in it and have that file contain an encrypted LUKS container that gets loop-mounted on the target. I am sure other options exist. So ask yourself: - What does the attacker have access to? - What can the attacker do at the access point? (With regard to his capabilities.) - Does this need to be exported to one or several targets? - Does the exporting host need access to the exported data? Arno On Thu, Oct 27, 2011 at 07:09:19PM -0400, Gary Webster wrote: > Thanks very much for the replies. > That was going to be my next question: Are there other practical ways to do > this? > > So, is ecryptfs no good, & are there any other options? > > > On Thu, Oct 27, 2011 at 7:06 PM, Roscoe wrote: > > > While I'm not confident of the quality, this would be one of the > > places ecryptfs fits into. > > > > On Fri, Oct 28, 2011 at 9:36 AM, Gary Webster wrote: > > > Hello. > > > Sorry if this is a FAQ. I've done some searching, & didn't find anything > > > concrete. > > > How/Can I encrypt an NFS mount (from the client)? > > > Thanks. > > > > > > _______________________________________________ > > > dm-crypt mailing list > > > dm-crypt@saout.de > > > http://www.saout.de/mailman/listinfo/dm-crypt > > > _______________________________________________ > dm-crypt mailing list > dm-crypt@saout.de > http://www.saout.de/mailman/listinfo/dm-crypt -- Arno Wagner, Dr. sc. techn., Dipl. Inform., CISSP -- Email: arno@wagner.name GnuPG: ID: 1E25338F FP: 0C30 5782 9D93 F785 E79C 0296 797F 6B50 1E25 338F ---- Cuddly UI's are the manifestation of wishful thinking. -- Dylan Evans If it's in the news, don't worry about it. The very definition of "news" is "something that hardly ever happens." -- Bruce Schneier