- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Re: NFS Security
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-05-2001 03:06 PM
06-05-2001 03:06 PM
NFS Security
I have an HP9000 cluster running MC/ServiceGuard (SAP Edition) and I have to live with NFS, I have a couple of questions in order to see if I can use NFS in a more secure way:
1) Is there any way I can run NFS over TCP, I have read that there are patches that will solve that, but do the patches affect SAP in any way?
2) I have tried to have rpc.mountd go through /var/adm/inetd.sec to discriminate from which hosts it can receive mount requests according to the rpc.mountd man page, however rpc.mountd does not recognize option '-e' (which supposedly is the way to do it) does anybody know if there is any way I can do that?
Any help on the matter would be greatly appreciated.
Regards
Daniel Cristini
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-05-2001 06:00 PM
06-05-2001 06:00 PM
Re: NFS Security
I would give an example, but I am not at work and can't get to any of my machines easily at the moment. :)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-05-2001 06:01 PM
06-05-2001 06:01 PM
Re: NFS Security
1. In /var/adm/inetd.sec, you can add an entry for who is allowed to mount files via "mountd"
read the man pages for inetd.sec
2. Next you have alot of options for your exports file to control access. If used with /etc/netgroup, you can have very fine tuned access and easy managability, but could also build the ACL's into /etc/exports. I just use netgroups for ease in management, and other secure issues.
Read the man pages for exportfs and netgroup for more information.
This is not an easy task in a large mixed network, and should be planned carefully.
NOTE: some people are not happy with how much digging/debugging they have to do to debug security issues when clients can not connect, or the security does not work. If you have problems you may want to get the O'Reilly book "NFS and NIS Administration"
Regards,
Shannon
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-06-2001 12:00 AM
06-06-2001 12:00 AM
Re: NFS Security
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-06-2001 03:29 AM
06-06-2001 03:29 AM
Re: NFS Security
Thanks again
Daniel Cristini