* AES support for RPCSEC_GSS?
@ 2008-02-12 1:20 Quentin Godfroy
[not found] ` <20080212012007.GA6993-Gn1em/8t8udFYcqGaMRPHA@public.gmane.org>
0 siblings, 1 reply; 4+ messages in thread
From: Quentin Godfroy @ 2008-02-12 1:20 UTC (permalink / raw)
To: linux-nfs
Hi,
in all the faqs it is said that there is no working support for
anything else than DES which is a bit outdated and not secure
nowadays.
It seemed to me that there was some code in the nfs-utils which
would do some security negociation (somewhere around utils/gssd/krb5_util.c),
but the kernel had nothing to support that.
I suppose this will be the last thing to be done once the security features
are working with the three versions of NFS.
What are the missing features in this field, and would it be difficult to
add support for other encryption schemes?
Regards,
Quentin Godfroy
^ permalink raw reply [flat|nested] 4+ messages in thread[parent not found: <20080212012007.GA6993-Gn1em/8t8udFYcqGaMRPHA@public.gmane.org>]
* Re: AES support for RPCSEC_GSS? [not found] ` <20080212012007.GA6993-Gn1em/8t8udFYcqGaMRPHA@public.gmane.org> @ 2008-02-12 4:37 ` J. Bruce Fields 2008-02-13 17:01 ` Quentin Godfroy 0 siblings, 1 reply; 4+ messages in thread From: J. Bruce Fields @ 2008-02-12 4:37 UTC (permalink / raw) To: Quentin Godfroy; +Cc: linux-nfs On Tue, Feb 12, 2008 at 02:20:07AM +0100, Quentin Godfroy wrote: > in all the faqs it is said that there is no working support for > anything else than DES which is a bit outdated and not secure > nowadays. > > It seemed to me that there was some code in the nfs-utils which > would do some security negociation (somewhere around utils/gssd/krb5_util.c), > but the kernel had nothing to support that. > > I suppose this will be the last thing to be done once the security features > are working with the three versions of NFS. > > What are the missing features in this field, and would it be difficult to > add support for other encryption schemes? Kevin Coffman is working on support for AES (and other algorithms). It's mostly working at this point, so I think we'll be posting patches soon. Is there something in particular you need or want to work on? --b. ^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: AES support for RPCSEC_GSS? 2008-02-12 4:37 ` J. Bruce Fields @ 2008-02-13 17:01 ` Quentin Godfroy [not found] ` <20080213170155.GA12551-Gn1em/8t8udFYcqGaMRPHA@public.gmane.org> 0 siblings, 1 reply; 4+ messages in thread From: Quentin Godfroy @ 2008-02-13 17:01 UTC (permalink / raw) To: J. Bruce Fields; +Cc: linux-nfs On Mon, Feb 11, 2008 at 11:37:15PM -0500, J. Bruce Fields wrote: > > in all the faqs it is said that there is no working support for > > anything else than DES which is a bit outdated and not secure > > nowadays. > > > > It seemed to me that there was some code in the nfs-utils which > > would do some security negociation (somewhere around utils/gssd/krb5_util.c), > > but the kernel had nothing to support that. > > > > I suppose this will be the last thing to be done once the security features > > are working with the three versions of NFS. > > > > What are the missing features in this field, and would it be difficult to > > add support for other encryption schemes? > > Kevin Coffman is working on support for AES (and other algorithms). > It's mostly working at this point, so I think we'll be posting patches > soon. I'll be glad to try it once it is available > Is there something in particular you need or want to work on? No, not really. I find the current implementation sufficient for my needs. Maybe the server not being IPv6 compatible is not pleasing to the mind. Unfortunately my coding experience is low and probably the nfsd code is not the easy way to start. ^ permalink raw reply [flat|nested] 4+ messages in thread
[parent not found: <20080213170155.GA12551-Gn1em/8t8udFYcqGaMRPHA@public.gmane.org>]
* Re: AES support for RPCSEC_GSS? [not found] ` <20080213170155.GA12551-Gn1em/8t8udFYcqGaMRPHA@public.gmane.org> @ 2008-02-13 17:59 ` J. Bruce Fields 0 siblings, 0 replies; 4+ messages in thread From: J. Bruce Fields @ 2008-02-13 17:59 UTC (permalink / raw) To: Quentin Godfroy; +Cc: linux-nfs On Wed, Feb 13, 2008 at 06:01:56PM +0100, Quentin Godfroy wrote: > I'll be glad to try it once it is available > > > Is there something in particular you need or want to work on? > > No, not really. I find the current implementation sufficient for my needs. > Maybe the server not being IPv6 compatible is not pleasing to the mind. > Unfortunately my coding experience is low and probably the nfsd code is not > the easy way to start. I *think* the ipv6 stuff is also on track to be done by 2.6.26 or 2.6.27, but I'm not the expert there.... --b. ^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2008-02-13 17:59 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2008-02-12 1:20 AES support for RPCSEC_GSS? Quentin Godfroy
[not found] ` <20080212012007.GA6993-Gn1em/8t8udFYcqGaMRPHA@public.gmane.org>
2008-02-12 4:37 ` J. Bruce Fields
2008-02-13 17:01 ` Quentin Godfroy
[not found] ` <20080213170155.GA12551-Gn1em/8t8udFYcqGaMRPHA@public.gmane.org>
2008-02-13 17:59 ` J. Bruce Fields
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox