Linux NFS development
 help / color / mirror / Atom feed
* Secure NFSv4 mounts and daemons
@ 2015-01-14 23:12 Ralph Zack
  2015-01-16  9:06 ` Paul van der Vlis
  2015-01-16 23:11 ` Anthony Messina
  0 siblings, 2 replies; 5+ messages in thread
From: Ralph Zack @ 2015-01-14 23:12 UTC (permalink / raw)
  To: linux-nfs

Hi all,

I have a number of NFSv4 shares which should only be accessible after
successful authentication, for which reason they are exported with
sec=krb5p. However, this method requires the user to obtain a kerberos
ticket to access files on the share, which is fine for regular users but
causes issues for daemons which are not kerberos-aware.

What is the common way to handle this problem? It can hardly be the only
solution to patch each service to obtain a ticket at startup. Please
correct me if I'm wrong, but I could not find any mechanism besides
kerberos that provides encryption and authentication for NFS shares. I'd
be fine with authentication on a host level, I mainly want to ensure
that only trusted machines can accesses these shares and that all
traffic is encrypted. Without the overhead of establishing a VPN
connection between client and server, in case anyone was going to
suggest that ;)

Cheers,

Ralph


^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2015-01-17 12:27 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2015-01-14 23:12 Secure NFSv4 mounts and daemons Ralph Zack
2015-01-16  9:06 ` Paul van der Vlis
2015-01-16 21:36   ` Benjamin Coddington
2015-01-17 11:53     ` Ralph Zack
2015-01-16 23:11 ` Anthony Messina

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox