Re: Ldap authentication and NFS mounts



linuxnewbie1234 wrote:

The problem is that in Linux, the root of each machine can just do "su"
to become whatever other user, and see the home of whatever other user
from the MacOsX fileserver mount! This is not what we want.

Remove su from the machine (bad idea IMHO).
I don't see the point in worry about that, if you worry that users will
single user boot, then password protect the boot loader.


Note that for now we were only able to do the mount of the homes in
linux machines *statically*, that is, with an entry in fstab which
mounts all the homes together, and not user-by-user at the moment of
login. Is our vulnerability only caused by this or it would exist anyway?

If you export /home, then you get everything, you would need to export
each user directory by themselves and then rewrite the login manager to
mount the remote directory to the local, but your fstab would get quite
big the more users you would have.

I do not see the problem, if you want to lock out other users from a
users home directory, then change the privileges so that only the user
in question can access it (chmod 700 /home/*), keep in mind that the
file system used in Linux (Mac OSX, Unix) are made for multiuser usage
in mind.

--

//Aho
.



Relevant Pages

  • Re: Mobile phone auctions - are they always this much hassle?
    ... to mount such a seemingly persistent campaign in here. ... Please try to bear in mind that the rest of us are still here on Planet ... I've not done anything in that thread to suggest I'm 'busy tracking down the ...
    (uk.people.consumers.ebay)
  • Re: OT: Time for a new computer
    ... Just bear in mind that *nothing* is assembled for you. ... You have to mount ... the motherboard, buy and install a CPU fan... ...
    (rec.gambling.poker)
  • Re: OT: Time for a new computer
    ... Just bear in mind that *nothing* is assembled for you. ... You have to mount ... the motherboard, buy and install a CPU fan... ...
    (rec.gambling.poker)
  • Re: Too much protection?
    ... I have it in mind that some ... > Windows product (Perhaps even something Microsoft) will mount the ...
    (comp.lang.pascal.delphi.misc)
  • Re: fat32 not supported by FC1?
    ... > That's the message I get mounting a win 98 formatted partition. ... > mount: fs type fat32 not supported by kernel ... "Beyond the senses is the mind, and beyond the mind is the reason, ...
    (Fedora)