[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: openbsd yp security



> In an environment using YP and NFS mounted homes, would it be simple to
> masquerade as another uid??  If the server has nothing to do with
> authenticating, yet trusts the client to report it's uid correctly...
> that seems pretty dodgy!!

Which is why to some people NFS is an acronym for "No File Security".
There are some implementation of NFS that require authentication via
a Kerberos ticket or a public key before a client can access an
exported file system.  Don't think any of those are supported by
OpenBSD, though.

David S.



Visit your host, monkey.org