[openib-general] mapping between IP address and device name
Roland Dreier
roland at topspin.com
Fri Jun 24 09:42:37 PDT 2005
Thomas> But that's totally and completely insecure. The goal of
Thomas> /etc/exports is to place at least part of the client
Thomas> authentication in the network rather than the supplied
Thomas> credentials. NFS has quite enough of a history with
Thomas> AUTH_SYS to prove the issues there. Some of the exports
Thomas> options (e.g. the *_squash ones) are specifically because
Thomas> of this.
ATS is completely insecure too, right? A client can create any old
service record in the subnet administrator's database and claim that
its GID has whatever IP address it wants.
- R.
More information about the general
mailing list