Re: [Hampshire] SECURE NFS ROOT ?

Top Page
Author: Dr A. J. Trickett
Date:  
To: Isaac Close, Hampshire LUG Discussion List
Subject: Re: [Hampshire] SECURE NFS ROOT ?

Reply to this message
gpg: failed to create temporary file '/var/lib/lurker/.#lk0x58015100.hantslug.org.uk.32092': Permission denied
gpg: keyblock resource '/var/lib/lurker/pubring.gpg': Permission denied
gpg: Signature made Wed Mar 4 22:43:30 2009 GMT
gpg: using DSA key 019AD0D8166C4BF0
gpg: Can't check signature: No public key
On Wednesday 04 Mar 2009, Isaac Close wrote:
> --- On Wed, 4/3/09, Dr A. J. Trickett <adam.trickett@???> wrote:
> > On Wed, 04 Mar 2009 at 09:52:57AM
> > >
> > > i'm trying to find information about some sort of 'secure'
> > > NFS-ROOT Filesystem setup. So far, i'm not having much luck.
> >
> > > I have working NFS-ROOT machines, but as you may already know
> > > NFS is not encrypted, and i can quite easily intercept packets
> > > with code of my own.
> > >
> > > So, what to do ? Do you know something ?
> >
> > You can hack NFSv3 to run over some kind of secure tunnel
> > or VPN.
>
> I did think this, although i'll have to add it to the long todo list.
>
> > Better still run NFSv4 which is better than NFSv3 anyway
> > but turn on Kerbose which makes it secure.
>
> I trust you mean Kerberos, and that sounds like a positive way forward.


I've had no problem setting up NFSv4 on Debian Etch/Lenny/Squeeze, and I've
got Kerberos working fine too, however I've had no luck yet in getting NFSv4
to work with Kerberos... I'd be very interested if hearing how you get on.

--
Adam Trickett
Overton, HANTS, UK

A man is known by the books he reads.
    --  Ralph Waldo Emerson