- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - Linux
- >
- Re: root_squash
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-07-2009 04:30 AM
тАО05-07-2009 04:30 AM
can someone explain pls root_squash parameter from Network File System (NFS)?
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-07-2009 04:48 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-07-2009 05:34 AM
тАО05-07-2009 05:34 AM
Re: root_squash
root_squash - Requests from root clients are mapped to the nobody user and group ID so they will only have file privileges associated with other
Please also check below for more details info
http://www.linuxsecurity.com/content/view/117705/171/
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-07-2009 06:20 AM
тАО05-07-2009 06:20 AM
Re: root_squash
/nfs/box 192.168.0.0/24(rw,no_wdelay,root_squash,insecure_locks,anonuid=1025,anongid=100)
I mount from the nfs client without problems.
But if I have in /etc/exports root_squash on the server than I cannot write via nfs client on the nfs server.
If I change to no_root_squash then I can write.
What's the problem?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-07-2009 10:12 AM
тАО05-07-2009 10:12 AM
Re: root_squash
This is a security feature. If the NFS server shares a filesystem that contains executables (e.g. /usr) and an unauthorized person gets root access on the NFS client host, without the root_squash feature the user could replace any binary in the server's filesystem with a SUID root binary of his/her own design.
If s/he can then make any user (or even a cron job) on the server to run his/her tampered executable, that executable can easily give him/her unauthorized root access on the server too.
MK
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-07-2009 10:54 AM
тАО05-07-2009 10:54 AM
Re: root_squash
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-07-2009 04:39 PM
тАО05-07-2009 04:39 PM
Re: root_squash
My understanding is root_squash controls whether root can mount an NFS share as root or not.
By default as a security measure you can not mount an NFS share remotely as root. The reason is the local sharing system can not guarantee or know the security level of the client.
An insecure host could mount a share and the sharing system can be exploited.
SEP
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-11-2009 07:31 AM
тАО05-11-2009 07:31 AM