Re: tcpwrapped rpcbind/portmap?

From: Trevor Fiatal (trevor@seven.com)
Date: 08/15/01


Message-ID: <3B79B0BA.43E3F4E@seven.com>
Date: Tue, 14 Aug 2001 16:14:02 -0700
From: Trevor Fiatal <trevor@seven.com>
To: Geoff Collis <geoff@andale.com>
Subject: Re: tcpwrapped rpcbind/portmap?

Geoff Collis wrote:
>
> As a standard part of hardening Solaris 2.6 and Solaris 7 I would normally
> replace rpcbind and portmap with Wietse's versions
> (http://ftp.porcupine.org/pub/security/index.html) so that access to these
> is controlled /etc/hosts.allow and /etc/hosts.deny files.
>
> I believe I need "rpcbind" to allow my secured host to NFS mount the NFS
> shares on my Network Appliance file servers.
>
> These programs are based on fairly old source, so should I still do this on
> Solaris 8?

I found the available rpcbind-replacement distributions to be
unreliable on Solaris 8. From the data uncovered in the debugging
process, plus a small amount of time spent examining the code,
it looks to me like a reimplementation of tcpwrappered rpcbind
for Solaris 8 will be required for it to work.

It's on my to-do list, but it could be a couple of months before
I get around to hacking the changes into the Sol8 rpcbind source,
and even then I'm not sure I could distribute the resulting
modified code.

-Trevor

-- 
Trevor Fiatal -- trevor@seven.com -- http://www.seven.com/
Co-Founder
Seven
510.967.4556 (work/mobile)  
510.401.8054 (vmail/fax)



Relevant Pages

  • tcpwrapped rpcbind/portmap?
    ... As a standard part of hardening Solaris 2.6 and Solaris 7 I would normally ... I believe I need "rpcbind" to allow my secured host to NFS mount the NFS ... controlling who is allowed to bind the RPC services on a host. ... some inventive ipfilter rules, although RPC is notoriously difficult to ...
    (Focus-SUN)
  • Re: tcpwrapped rpcbind/portmap?
    ... The lack of ACL enforcement within the stock Solaris ... rpcbind make its use problematic in a security-sensitive environment. ...
    (Focus-SUN)
  • RE: tcpwrapped rpcbind/portmap?
    ... Subject: tcpwrapped rpcbind/portmap? ... rpcbind to make sure RPC will only work with hosts on the local subnet. ... So I would like to have tcp-wrapped versions of rpcbind/portmap for Solaris ... Wouldl it be a good idea to have a "safer" rpcbind in Solaris? ...
    (Focus-SUN)
  • Re: tcpwrapped rpcbind/portmap?
    ... Subject: tcpwrapped rpcbind/portmap? ... Basically, it confirms my suspicions, that Wietse's rpcbind code ... in Solaris code. ...
    (Focus-SUN)