Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 12 Mar 2001 18:57:53 +0100
From:      "Jose M. Alcaide" <jose@we.lc.ehu.es>
To:        security@FreeBSD.org
Subject:   NFS and kerberos?
Message-ID:  <3AAD0E21.4EDB1E4C@we.lc.ehu.es>

next in thread | raw e-mail | index | archive | help
Hello,

I want to authenticate NFS clients on an NFS server (all of them running
FreeBSD 4.3). I found that SecureRPC is not an option, but I also found
the "-kerb" flag in exports(5). However, the manpage says:

     The -kerb option specifies that the Kerberos authentication server should
     be used to authenticate and map client credentials.  This option requires
     that the kernel be built with the NFSKERB option.  The use of this option
     will prevent the kernel from compiling unless calls to the appropriate
     Kerberos encryption routines are provided in the NFS source.

I searched sys/nfs/* for NFSKERB and indeed I found some "XXX" placeholders
parenthesized by "#ifdef NFSKERB" for -I think- those calls to the Kerberos
encryption routines. Obviously the kernel cannot be compiled if NFSKERB
is #define'd.

My question is: can I use kerberos for NFS client authentication? If
I cannot, then I'll welcome any suggestions about how to share file
systems with authenticated clients.

TIA,
-- JMA
****** Jose M. Alcaide  //  jose@we.lc.ehu.es  //  jmas@FreeBSD.org ******
** "Beware of Programmers who carry screwdrivers" --  Leonard Brandwein **

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?3AAD0E21.4EDB1E4C>