Dell Wyse Enhanced Ubuntu Linux T50 Manual de usuario Pagina 129

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 220
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 128
Chapter 10. File Access
that NFSSTART.NCF comes before ZFDSTART.NCF. Failing to do this may result in a server with 100%
load and malfunctioning NFS.
10.2.4.3. Securing Netware NFS Services
NFS can be used with several different authentication mechanisms. The most common one is called
AUTH_SYS. This is the only mechanism supported by Netware. AUTH_SYS only provides a legitimate
authentication if the network can be secured externally, and privileged TCP/UDP ports are used.
Unfortunately, the Netware NFS server does not require that NFS requests are originating from privileged
ports. This means that any user on any host (which has been granted NFS access) can impersonate any
other user (including root). To work around this problem, the Netware filtering support can be used:
1. Type FILTCFG at the console prompt.
2. Select Configure TCP/IP Filters->Packet forwarding Filters.
3. Change status to Enabled.
4. Make sure "Deny packets in filter list" is selected.
5. Select (List of denied packets).
6. Press Insert to define a new filter.
7. Highlight the "Packet type" entry, and press Enter.
8. Press Insert to define a new packet type. It should have the following properties:
Name: nfs-unsecure
Protocol: UDP
Source ports: 1024-65535
Destination ports: 2049
Stateful filtering: Disabled
9. Press Escape, and then Enter to return to the Define Filter screen.
10. Press Escape and Enter to save the filter.
11. Repeat step 6 to 10 to add a TCP filter. In step 8, the Name should be "nfs-unsecuretcp", and the
Protocol TCP.
12. Exit FILTCFG.
10.2.4.4. UNIX Configuration
10.2.4.4.1. Assigning permissions to NFS-exported filesystems
When exporting filesystems from a Novell Netware fileserver using NFS in the Independent mode (see
Table 10-1 for the available file access mapping modes on different Netware versions), no mapping is
done from the Netware permissions to the Unix permissions. Therefore, permissions on the exported
filesystems must be set from a Linux client by running chmod as root. This can be done either manually
or automatically using tl-nds-posixuser, described in Section 9.3.4.
119
Vista de pagina 128
1 2 ... 124 125 126 127 128 129 130 131 132 133 134 ... 219 220

Comentarios a estos manuales

Sin comentarios