NFS mounts security not functioning like expected.
Running NAS code 5.6.45-5, and now see where hosts can mount and read NFS exports that in the past, they could not. I have tried different entries in the allow fields for root, ro, rw, accsss, etc, what I see if any entry exists, a host not listed can still see, mount and read data on any of hte NFS exports, If I remove all entries, then no one can access the mount points. What I need to determine is how to get these locked back down so only hosts that are given access via one of the properties whether it is root, ro, rw or access and no other hosts can mount and read these exports.
Most of my mounts have a single entry, root access only, to a singel IP address. I have tried adding the entry to access only, still same issue, does not seem to matter as any entry seems to result in the same, host that are given access can r-w, etc, host with no access seem to be able to mount and read even though the only entry is an IP address to the root access only.
yes - combining multiple NFS export options can be a bit confusing and most of them mean that any host not specified gets read-only access
Take a look at the "Configuring NFS on Celerra" manual - the Table 6 on page 106 specifies what exactly you get when you combine multiple options
most customers "over-do" their export options - what you typically want is to just use access= and root=
Rainer
P.S.: we now also have a parameter for "NFS export hiding" - i.e. that a client who doesnt have access cant even "see" the export listed in a showmount
This setup used to work fine. Some where, which I can only attibute to when we went to this version of Dart code, some thing changed, so where the previous settings no longer are functioning as the document states.
Can you share what your exact access list is/was that wasn't working as expected? Particularly one that you believe was working before the upgrade?
I don't believe there have been any bugs lately that would affect how the export options like this are treated.
In general the rules for access granting based on the export options have been unchanged for probably the last decade or so; so the overall logic shouldn't be different. Having no export options should give everyone access (though no one will be able to operate as a "root" user).
But depending on what version you upgraded from, there have been some changes/bugfixes that might change how the export options are treated in subtle ways. And there's a couple of bugfixes since 5.6.45 to help with some export problems. For example, in your version there is a bug where if the total length of any given export option (access=, rw=, ro=, or root=) exceeds 2048 bytes (which is the limit), then the entire option would be ignored - and depending on your access list, that might cause more access to be granted than expected.
But for sure, in ALL releases, an export with no options should give read/write access to everyone, and an export with only an "access=" option should give access only the given hosts access. If you were seeing something different, then something was wrong.
bhansen
54 Posts
482
0
Posted March 30th, 2010 09:00
Most of my mounts have a single entry, root access only, to a singel IP address. I have tried adding the entry to access only, still same issue, does not seem to matter as any entry seems to result in the same, host that are given access can r-w, etc, host with no access seem to be able to mount and read even though the only entry is an IP address to the root access only.