<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Secure NFS in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/secure-nfs/m-p/2700763#M932958</link>
    <description>Hi David:&lt;BR /&gt;&lt;BR /&gt;You didnot answer my question, but you gave me clearer picture about NFS security, thanks for your professional explanation, so I assigned 7 points to you, really appreciate!&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
    <pubDate>Thu, 11 Apr 2002 12:19:44 GMT</pubDate>
    <dc:creator>Victor_5</dc:creator>
    <dc:date>2002-04-11T12:19:44Z</dc:date>
    <item>
      <title>Secure NFS</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/secure-nfs/m-p/2700756#M932951</link>
      <description>How can I know whether I am using secure NFS on my 11i box? Which files I need to take a look?&lt;BR /&gt;&lt;BR /&gt;Thanks!&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 10 Apr 2002 12:33:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/secure-nfs/m-p/2700756#M932951</guid>
      <dc:creator>Victor_5</dc:creator>
      <dc:date>2002-04-10T12:33:02Z</dc:date>
    </item>
    <item>
      <title>Re: Secure NFS</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/secure-nfs/m-p/2700757#M932952</link>
      <description>Victor,&lt;BR /&gt;&lt;BR /&gt;Do you mean 'Secure RPC' ? If so, check out the following HP Manual: &lt;A href="http://docs.hp.com/cgi-bin/fsearch/framedisplay?top=/hpux/onlinedocs/B1031-90048/B1031-90048_top.html&amp;amp;con=/hpux/onlinedocs/B1031-90048/00/00/25-con.html&amp;amp;toc=/hpux/onlinedocs/B1031-90048/00/00/25-toc.html&amp;amp;searchterms=NFS%7csecure&amp;amp;queryid=20020410-065840" target="_blank"&gt;http://docs.hp.com/cgi-bin/fsearch/framedisplay?top=/hpux/onlinedocs/B1031-90048/B1031-90048_top.html&amp;amp;con=/hpux/onlinedocs/B1031-90048/00/00/25-con.html&amp;amp;toc=/hpux/onlinedocs/B1031-90048/00/00/25-toc.html&amp;amp;searchterms=NFS%7csecure&amp;amp;queryid=20020410-065840&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Good Luck!</description>
      <pubDate>Wed, 10 Apr 2002 12:52:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/secure-nfs/m-p/2700757#M932952</guid>
      <dc:creator>Robert Gamble</dc:creator>
      <dc:date>2002-04-10T12:52:37Z</dc:date>
    </item>
    <item>
      <title>Re: Secure NFS</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/secure-nfs/m-p/2700758#M932953</link>
      <description>Hi Victor:&lt;BR /&gt;&lt;BR /&gt;Check these threads:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://forums.itrc.hp.com/cm/QuestionAnswer/0,,0xe5faa14d9abcd4118fef0090279cd0f9,00.html" target="_blank"&gt;http://forums.itrc.hp.com/cm/QuestionAnswer/0,,0xe5faa14d9abcd4118fef0090279cd0f9,00.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://forums.itrc.hp.com/cm/QuestionAnswer/1,,0xb48f663ce855d511abcd0090277a778c,00.html" target="_blank"&gt;http://forums.itrc.hp.com/cm/QuestionAnswer/1,,0xb48f663ce855d511abcd0090277a778c,00.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;HTH,&lt;BR /&gt;Shiju&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 10 Apr 2002 12:54:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/secure-nfs/m-p/2700758#M932953</guid>
      <dc:creator>Helen French</dc:creator>
      <dc:date>2002-04-10T12:54:52Z</dc:date>
    </item>
    <item>
      <title>Re: Secure NFS</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/secure-nfs/m-p/2700759#M932954</link>
      <description>Victor,&lt;BR /&gt;&lt;BR /&gt; Secure NFS is not supported by HP-UX - see the following:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://docs.hp.com/cgi-bin/fsearch/framedisplay?top=/hpux/onlinedocs/B1031-90048/B1031-90048_top.html&amp;amp;con=/hpux/onlinedocs/B1031-90048/00/00/25-con.html&amp;amp;toc=/hpux/onlinedocs/B1031-90048/00/00/25-toc.html&amp;amp;searchterms=NFS%7csecure&amp;amp;queryid=20020410-070235" target="_blank"&gt;http://docs.hp.com/cgi-bin/fsearch/framedisplay?top=/hpux/onlinedocs/B1031-90048/B1031-90048_top.html&amp;amp;con=/hpux/onlinedocs/B1031-90048/00/00/25-con.html&amp;amp;toc=/hpux/onlinedocs/B1031-90048/00/00/25-toc.html&amp;amp;searchterms=NFS%7csecure&amp;amp;queryid=20020410-070235&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Although secure RPC is.&lt;BR /&gt;&lt;BR /&gt;HTH,&lt;BR /&gt;Jeff</description>
      <pubDate>Wed, 10 Apr 2002 12:56:38 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/secure-nfs/m-p/2700759#M932954</guid>
      <dc:creator>Jeff Schussele</dc:creator>
      <dc:date>2002-04-10T12:56:38Z</dc:date>
    </item>
    <item>
      <title>Re: Secure NFS</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/secure-nfs/m-p/2700760#M932955</link>
      <description>NFS is not secure *at all* on HP-UX. Avoid it. Like the plague...</description>
      <pubDate>Wed, 10 Apr 2002 20:06:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/secure-nfs/m-p/2700760#M932955</guid>
      <dc:creator>David Lodge</dc:creator>
      <dc:date>2002-04-10T20:06:04Z</dc:date>
    </item>
    <item>
      <title>Re: Secure NFS</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/secure-nfs/m-p/2700761#M932956</link>
      <description>The best way to *secure* NFS is to not run it at all, and to remove the filesets of the server.</description>
      <pubDate>Wed, 10 Apr 2002 21:41:31 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/secure-nfs/m-p/2700761#M932956</guid>
      <dc:creator>Michael Tully</dc:creator>
      <dc:date>2002-04-10T21:41:31Z</dc:date>
    </item>
    <item>
      <title>Re: Secure NFS</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/secure-nfs/m-p/2700762#M932957</link>
      <description>Having had a quick look at the threads pointed to above, I just wanted to make some points.&lt;BR /&gt;&lt;BR /&gt;1) NFS is not *secure*. I really, really mean this.&lt;BR /&gt;2) If you *need* to run it (to be honest you shouldn't have any reason to) then make sure you do the following:&lt;BR /&gt; * restrict the export as much as possible in /etc/exports (using ro, nosuid, nodev ad nauseum)&lt;BR /&gt; * make the inode of the mounted directory as high as possible.&lt;BR /&gt; * use /etc/inetd.sec to restrict requests to rpc.mountd&lt;BR /&gt;&lt;BR /&gt;You might have questions about the second recommendation, but if you understand how NFS works it makes sense; in a nutshell:&lt;BR /&gt;1. Client request permission to mount directory from rpc.mountd&lt;BR /&gt;2. Mountd checks /etc/exports to see whether it has permissions. If so it returns a file handle.&lt;BR /&gt;3. NFS client talks to NFS server to request files/meta data, *using the file handle*&lt;BR /&gt;&lt;BR /&gt;Hence, if an attacker can snarf the file handle they can access all exported information.&lt;BR /&gt;&lt;BR /&gt;Because of weaknesses in HP's NFS file handles it is relatively easy to grab a file handle - but this depends on the size of the inode of the exported directory - hence the higher up it is, the less the risk. (ie 2 is bad 56784943 is better)&lt;BR /&gt;&lt;BR /&gt;dave (NFS is evil)</description>
      <pubDate>Thu, 11 Apr 2002 09:47:44 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/secure-nfs/m-p/2700762#M932957</guid>
      <dc:creator>David Lodge</dc:creator>
      <dc:date>2002-04-11T09:47:44Z</dc:date>
    </item>
    <item>
      <title>Re: Secure NFS</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/secure-nfs/m-p/2700763#M932958</link>
      <description>Hi David:&lt;BR /&gt;&lt;BR /&gt;You didnot answer my question, but you gave me clearer picture about NFS security, thanks for your professional explanation, so I assigned 7 points to you, really appreciate!&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 11 Apr 2002 12:19:44 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/secure-nfs/m-p/2700763#M932958</guid>
      <dc:creator>Victor_5</dc:creator>
      <dc:date>2002-04-11T12:19:44Z</dc:date>
    </item>
  </channel>
</rss>

