Announcement Banner
UNSOLVED

bhansen

updated

17 years ago

B

bhansen

54 Posts

0

1884

March 30th, 2010 08:00

NFS mounts security not functioning like expected.

Running NAS code 5.6.45-5, and now see where hosts can mount and read NFS exports that in the past, they could not. I have tried different entries in the allow fields for root, ro, rw, accsss, etc, what I see if any entry exists, a host not listed can still see, mount and read data on any of hte NFS exports, If I remove all entries, then no one can access the mount points. What I need to determine is how to get these locked back down so only hosts that are given access via one of the properties whether it is root, ro, rw or access and no other hosts can mount and read these exports.

  • bhansen

    54 Posts

    482

    0

    Posted March 30th, 2010 09:00

    Most of my mounts have a single entry, root access only, to a singel IP address. I have tried adding the entry to access only, still same issue, does not seem to matter as any entry seems to result in the same, host that are given access can r-w, etc, host with no access seem to be able to mount and read even though the only entry is an IP address to the root access only.

  • Rainer_EMC

    6 Operator

    •

    8645 Posts

    482

    0

    Posted March 30th, 2010 09:00

    moz-screenshot.png

  • Rainer_EMC

    6 Operator

    •

    8645 Posts

    482

    0

    Posted March 30th, 2010 09:00

    are you sure that root= is the *only* option ?

    can you post a server_export output ?

    root= alone shouldnt give you any mount access it merely modifies how UID 0 is mapped

  • Rainer_EMC

    6 Operator

    •

    8645 Posts

    482

    0

    Posted March 30th, 2010 09:00

    Hi,

    yes - combining multiple NFS export options can be a bit confusing and most of them mean that any host not specified gets read-only access

    Take a look at the "Configuring NFS on Celerra" manual - the Table 6 on page 106 specifies what exactly you get when you combine multiple options

    most customers "over-do" their export options - what you typically want is to just use access= and root=

    Rainer

    P.S.: we now also have a parameter for "NFS export hiding" - i.e. that a client who doesnt have access cant even "see" the export listed in a showmount

  • bhansen

    54 Posts

    482

    0

    Posted March 30th, 2010 10:00

    Yes, I am sure root is the only field with an entry in it.

  • Rainer_EMC

    6 Operator

    •

    8645 Posts

    482

    0

    Posted March 30th, 2010 11:00

    ok - according to the table (case 16) no optiona means that all hosts are allowed to mount read/write

    try access=host and root=host and nothing else

    that should give you what you want

  • Rainer_EMC

    6 Operator

    •

    8645 Posts

    480

    0

    Posted March 30th, 2010 11:00

    Hmmh,

    then I would suggest to open a service request - support can take a look what the export table really looks like and search if there is a bug open.

    Rainer

  • bhansen

    54 Posts

    480

    0

    Posted March 30th, 2010 11:00

    I have attempted access = IP root = IP, this option allowed the other non listed IP addresses to mount the file system

  • bhansen

    54 Posts

    480

    0

    Posted March 30th, 2010 11:00

    This setup used to work fine. Some  where, which I can only attibute to when we went to this version of Dart code, some thing changed, so where the previous settings no longer are functioning as the document states.

  • IanSchorr

    117 Posts

    410

    0

    Posted April 5th, 2010 22:00

    Did you end up finding the answer?

    Can you share what your exact access list is/was that wasn't working as expected?  Particularly one that you believe was working before the upgrade?

    I don't believe there have been any bugs lately that would affect how the export options like this are treated.

    In general the rules for access granting based on the export options have been unchanged for probably the last decade or so; so the overall logic shouldn't be different.  Having no export options should give everyone access (though no one will be able to operate as a "root" user).

    But depending on what version you upgraded from, there have been some changes/bugfixes that might change how the export options are treated in subtle ways.  And there's a couple of bugfixes since 5.6.45 to help with some export problems.  For example, in your version there is a bug where if the total length of any given export option (access=, rw=, ro=, or root=) exceeds 2048 bytes (which is the limit), then the entire option would be ignored - and depending on your access list, that might cause more access to be granted than expected.

    But for sure, in ALL releases, an export with no options should give read/write access to everyone, and an export with only an "access=" option should give access only the given hosts access.  If you were seeing something different, then something was wrong.