"Robert G. Brown" <[EMAIL PROTECTED]> writes:
> Once upon a time, running NFS in a LAN that wasn't controlled at the
> port level was basically openly inviting anyone that could plug into a
> wired port to have open access to all exported files, and I'm not sure
> that has fundamentally changed as to change it would be very difficult.

NFSv4 changes the security situation a bunch, but it is not widely
implemented and deployed. One can also use IPSec with NFSv3 --
appropriate IPSec policies will assure that you get reasonable
security, at the price of some performance because of the crypto.


Perry
-- 
Perry E. Metzger                [EMAIL PROTECTED]
_______________________________________________
Beowulf mailing list, [email protected]
To change your subscription (digest mode or unsubscribe) visit 
http://www.beowulf.org/mailman/listinfo/beowulf

Reply via email to