Next Previous Contents

9. NFS

While NFS is very convenient for installing diskless machines, it provides almost no security. Data is transmitted unencrypted and authorization is solely based on the identity of IP addresses. Anybody who can forge ethernet packets, has full access over any data that is available via NFS. While there are protocol extension that try to address these shortcomings, I am not aware of any solution for Linux based machines. This means, you have to assume that all exported filesystems are freely read- and writeable. Bear this in mind when deciding which data you intend to export.


Next Previous Contents