public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
From: Jesse Pollard <jesse@cats-chateau.net>
To: "J. Bruce Fields" <bfields@fieldses.org>
Cc: Andreas Dilger <=?CP 1252?q?adilger=40clusterfs=2Ecom?=> =?CP
	1252?q?=2CS=F8ren=20Hansen?= <sh@warma.dk>,
	"Linux Kernel Mailing List" <linux-kernel@vger.kernel.org>
Subject: Re: UID/GID mapping system
Date: Fri, 12 Mar 2004 07:58:33 -0600	[thread overview]
Message-ID: <04031207583301.07660@tabby> (raw)
In-Reply-To: <20040311160245.GB18466@fieldses.org>

On Thursday 11 March 2004 10:02, J. Bruce Fields wrote:
> On Thu, Mar 11, 2004 at 08:08:31AM -0600, Jesse Pollard wrote:
> > On Wednesday 10 March 2004 17:46, Andreas Dilger wrote:
> > > If the client is trusted to mount NFS, then it is also trusted enough
> > > not to use the wrong UID.  There is no "more" or "less" safe in this
> > > regard.
> >
> > It is only trusted to not misuse the uids that are mapped for that
> > client. If the client DOES misuse the uids, then only those mapped uids
> > will be affected. UIDS that are not mapped for that host will be
> > protected.
> >
> > It is to ISOLATE the penetration to the host that this is done. The
> > server will not and should not extend trust to any uid not authorized to
> > that host. This is what the UID/GID maps on the server provide.
>
> You're making an argument that uid mapping on the server could be used
> to provide additional security; I agree.
>
> I don't believe you can argue, however, that providing uid mapping on
> the client would *decrease* security, unless you believe that mapping
> uid's on the client precludes also mapping uid's on the server.

Not really - it would be a 1:1 map... so what would be the purpose?

The problem is in the audit - the server would report a violation in
uid xxx. Which according to it's records is not used on the penetrated client
(at least not via the filesystem). Yet the administrator would report that the
uid is valid (because of a bogus local map).

Double mapping also doubles the audit complications :-)

  reply	other threads:[~2004-03-12 13:59 UTC|newest]

Thread overview: 32+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2004-03-08 19:45 UID/GID mapping system Søren Hansen
2004-03-09 16:46 ` Jesse Pollard
2004-03-09 19:28   ` Søren Hansen
2004-03-10 15:28     ` Jesse Pollard
2004-03-10 17:58       ` Søren Hansen
2004-03-10 21:41         ` Jesse Pollard
2004-03-10 22:45           ` Trond Myklebust
2004-03-11  8:29             ` Søren Hansen
2004-03-11 14:31               ` Jesse Pollard
2004-03-11 14:45                 ` Søren Hansen
2004-03-11 15:58               ` J. Bruce Fields
2004-03-11 19:41               ` Trond Myklebust
2004-03-12  8:41                 ` Søren Hansen
2004-03-11 14:10             ` Jesse Pollard
2004-03-10 23:46           ` Andreas Dilger
2004-03-11 14:08             ` Jesse Pollard
2004-03-11 16:02               ` J. Bruce Fields
2004-03-12 13:58                 ` Jesse Pollard [this message]
2004-03-12 20:08                   ` J. Bruce Fields
2004-03-15 17:17                     ` Jesse Pollard
2004-03-15 17:49               ` Andreas Dilger
     [not found]             ` <fa.ct61k6d.bm43gj@ifi.uio.no>
2004-03-11 19:40               ` Kevin Buhr
2004-03-11 23:10                 ` Jamie Lokier
2004-03-12 14:49                 ` Pavel Machek
2004-03-11  8:22           ` Søren Hansen
2004-03-11 14:18             ` Jesse Pollard
2004-03-11 14:39               ` Søren Hansen
2004-03-12 13:52                 ` Jesse Pollard
2004-03-12 15:00                   ` Søren Hansen
2004-03-15 17:05                     ` Jesse Pollard
2004-03-16  8:08                       ` Søren Hansen
2004-03-09 19:28   ` Søren Hansen

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=04031207583301.07660@tabby \
    --to=jesse@cats-chateau.net \
    --cc=bfields@fieldses.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox