Re: SSH Newbie Questions: SSH and NFS-exported user homes



On 14 Sep, 20:34, Ignoramus19284 <ignoramus19...@xxxxxxxxxxxxxxxxxxxx>
wrote:
I do that at home. It is as secure as NFS is.

Just add your public key to authorized_keys, that's all.

i

As secure as NFS is, is.... a fairly poor recommendation. It's known
as "No F***ing Security" for good reasons. It's far too easy in most
setups for a root user on an NFS client to pretend to be any other NFS
user, and gain access to the entire contents of their home directory.
This applies especailly to SSH private keys and SSH authorized_keys
files.

You'll need to think very, very carefully about how you handle keys in
such an environment.

.



Relevant Pages

  • Re: Why does openssh protocol default to 2?
    ... >> RSA/DSA keys, don't do that. ... > What would you suggest for NFS mounted home dirs as a reasonable solution? ... you then fire up an agent remotely on a trusted machine ... that if you choose to forward authentication root can hijack you ...
    (FreeBSD-Security)
  • Re: SSH Newbie Questions: SSH and NFS-exported user homes
    ... of a user - and may then help himself to ssh access as that user. ... If a user has not yet installed any keys the NFS problem is still true. ... If that remote root user can drop spare authorized_keys into the ...
    (comp.security.ssh)
  • Re: Bernstein factoring machine one year later
    ... improving the nfs. ... NIST had originally said use of 1024 bit keys is ok until ... Don Johnson ...
    (sci.crypt)
  • Re: need to get rid of french characters on login screen
    ... the canadian (french) language setting as default (when they just ... wanted plain canadian) without looking which meant some of the keys ... and log back in using the root user. ...
    (comp.sys.mac.system)
  • Re: Solaris 10, secure nfs, permission denied
    ... performed step 2a from the "How to Access a Kerberos Protected NFS ... File System as the root User" section here ... Creating a root principal is not needed for mounting a NFS share ...
    (comp.protocols.kerberos)