public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
* NFS4 authentification / fsuid
@ 2007-08-30 14:12 Jan Engelhardt
  2007-08-30 14:29 ` Trond Myklebust
  0 siblings, 1 reply; 32+ messages in thread
From: Jan Engelhardt @ 2007-08-30 14:12 UTC (permalink / raw)
  To: Trond Myklebust; +Cc: Linux Kernel Mailing List

Hi,


with NFS3, there is this 'root hole', i.e. any person who has a root 
account (perhaps by use of a laptop) can mount an export (let's say this 
export had the "root_squash" option), and still have a look at the user 
files, because he can locally setuid() into another user.

So I was looking for alternatives. CIFS is my favorite candidate, but it 
has a few issues right now. So does sshfs and about everything I have 
come across. Since I remember NFS4 can use KRB5 authentification, my 
question is, will the NFS(4) server process run with an fsuid equal to 
the user that authenticated?


thanks,
	Jan
-- 

^ permalink raw reply	[flat|nested] 32+ messages in thread

end of thread, other threads:[~2007-09-20  7:12 UTC | newest]

Thread overview: 32+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2007-08-30 14:12 NFS4 authentification / fsuid Jan Engelhardt
2007-08-30 14:29 ` Trond Myklebust
2007-08-30 14:32   ` Trond Myklebust
2007-08-30 14:42     ` Jan Engelhardt
2007-08-30 15:04       ` Trond Myklebust
2007-08-30 21:44         ` J. Bruce Fields
2007-09-06  8:14           ` Satyam Sharma
2007-09-06  8:29             ` Satyam Sharma
2007-09-06 15:11               ` J. Bruce Fields
2007-09-06 23:21                 ` Trond Myklebust
2007-09-06 23:32                   ` Trond Myklebust
2007-09-07 15:34                     ` J. Bruce Fields
2007-09-18 23:27                       ` Satyam Sharma
2007-09-18 23:12                 ` Satyam Sharma
2007-09-06 15:06             ` J. Bruce Fields
2007-09-06 23:30               ` Kyle Moffett
2007-09-06 23:35                 ` Trond Myklebust
2007-09-07  0:56                   ` Kyle Moffett
2007-09-07  5:14                     ` Trond Myklebust
2007-09-07  5:47                       ` Kyle Moffett
2007-09-07  6:37                         ` Bernd Eckenfels
2007-09-18 23:48                         ` Satyam Sharma
2007-09-18 23:44                     ` Satyam Sharma
2007-09-19  5:16                       ` Kyle Moffett
2007-09-19 12:16                         ` Satyam Sharma
2007-09-19 13:49                           ` Kyle Moffett
2007-09-19 14:12                             ` Satyam Sharma
2007-09-19 15:01                               ` J. Bruce Fields
2007-09-20  7:03                                 ` Satyam Sharma
2007-09-19 16:38                         ` Valdis.Kletnieks
2007-09-20  7:15                           ` Satyam Sharma
2007-08-30 15:12       ` J. Bruce Fields

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox