Re: Access control for a NFS server

Ben Nelson <[email protected]>
Newsgroups gmane.comp.security.linux
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Tobias Edler wrote:
| Hi !
| As i read a lot of competent postings on this list, maybe one of you can
| adwise me on this qustion.
|
| How can i make sure nobody unplugs a worstation, plugs in a laptop, uses
| the workstation's MAC, mounts /home from the nfs server, and does evil
| things to the homedirs ?
| Like, verify some hostkey or something ?
|
| Regards, Tobias
|

One option might be to require users to establish a VPN connection to
the NFS server in order to access the NFS shares.  This would require
authentication and has the added benefit of encryption.  Check out
Openswan (www.openswan.org) for a Linux VPN end-point.

- --Ben
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQFA/T8f3cL8qXKvzcwRAkIWAJ9Az+8L6cB1WOFwRDkRRgvLKYZPiACdHIB6
ZwI6mTDDZJ6xWKaRPouCXTw=
=M9+Q
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.