Re: Access control for a NFS server

Jacob Bresciani <[email protected]>
Newsgroups gmane.comp.security.linux
Message-ID <[email protected]>
Three quick idea's off the top of my head

1.) switch to NFS4 or AFS (Andrew File System) for kerb based 
authentication for mounts.
2.) 802.1x for network port/VLAN authentication. ( 
http://web.uvic.ca/wireless/whatis.htm for a decent description )
3.) strip the shielding off the power-cords

the last one may have some legal repercussions

-------

Jacob Bresciani
Systems Analyst
Electrical and Computer Engineering
University of Alberta
Bus: (780) 492-7368
Fax: (780) 492-1811
[email protected]

On 19-Jul-04, at 9:59 AM, Tobias Edler wrote:

Hi !
As i read a lot of competent postings on this list, maybe one of you can
adwise me on this qustion.

How can i make sure nobody unplugs a worstation, plugs in a laptop, uses
the workstation's MAC, mounts /home from the nfs server, and does evil
things to the homedirs ?
Like, verify some hostkey or something ?

Regards, Tobias

-- 
________ This message is made of 100 % recycled electrons
\..|     PGP Key: www.stud.uni-goettingen.de/~s242275/pgpkey.pub     (o_
.\.|--   Jabber:  te_linuxguru at jabber.fsinf.de            (o  (o  //\
..\|____ ICQ:     124557012                                  (/)_(/)_V_/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.