Lorenzo Marcantonio | 13 Jul 2012 09:32

unfsd access is broken too...

It seems it only checks posix stuffs and doesn't even setuid...

IMHO RSBAC without a working NFS implementation is almost a showstopper.

What alternatives are there? smb mounts are only for single users AFAIK

--

-- 
Lorenzo Marcantonio
Logos Srl
Picon

Re: unfsd access is broken too...

On 13/07/12 09:32, Lorenzo Marcantonio wrote:
> It seems it only checks posix stuffs and doesn't even setuid...
> 
> IMHO RSBAC without a working NFS implementation is almost a showstopper.
> 
> What alternatives are there? smb mounts are only for single users AFAIK
> 

CODA?
Lorenzo Marcantonio | 13 Jul 2012 10:03

Re: unfsd access is broken too...

On Fri, Jul 13, 2012 at 09:54:26AM +0200, Javier Juan Martínez Cabezón wrote:
> CODA?

Is that *thing* still alive? Also it completely *own* the stuff,
permission included (like AFS it implements a fs-on-fs)

--

-- 
Lorenzo Marcantonio
Logos Srl
_______________________________________________
rsbac mailing list
rsbac <at> rsbac.org
http://www.rsbac.org/mailman/listinfo/rsbac
Amon Ott | 30 Jul 2012 12:44

Re: unfsd access is broken too...

On Friday 13 July 2012 wrote Lorenzo Marcantonio:
> It seems it only checks posix stuffs and doesn't even setuid...
>
> IMHO RSBAC without a working NFS implementation is almost a showstopper.
>
> What alternatives are there? smb mounts are only for single users AFAIK

For security reasons, I strongly recommend a user space solution, no matter 
what protocol - nfsd, samba, glusterfsd, ceph daemons, ...

Amon.
--

-- 
http://www.rsbac.org - GnuPG: 2048g/5DEAAA30 2002-10-22

Gmane