Re: Question on current state of sec=krb5* integration in cifs.ko
Volker Lendecke <[email protected]>
| Newsgroups | gmane.linux.file-systems.cifs |
|---|---|
| Organization | SerNet GmbH, Goettingen, Germany |
| Message-ID | <[email protected]> |
On Fri, Oct 23, 2009 at 11:55:12AM -0400, Jeff Layton wrote: > Yes, much... > > NFS (well, RPC actually) sends credentials with every call, so if you > destroy the creds, then the client and server will tend to pick up on > that fact rather quickly. With CIFS the credentials are just used to > establish a "session". After that, krb5 doesn't really come into play > very much (at least until you have to reconnect). It's not *as* bad as it sounds security-wise, SMB signing attempts to provide integrity, and the Samba extensions for SMB encryption (Jeff: Hint...! :-)) would provide confidentiality. Volker _______________________________________________ linux-cifs-client mailing list [email protected] https://lists.samba.org/mailman/listinfo/linux-cifs-client
signature.asc
(application/pgp-signature, 197 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iEYEARECAAYFAkrh03sACgkQbsgDfmnSbra6RACbB/Utiq1CwATPqCyW733XVCYz EqEAn3dnYj3plOjmZm1Bpa9trD8ss3C4 =a8y7 -----END PGP SIGNATURE-----