> After contemplating the matter for a while, I still think it is a
> serious security risk. As far as I know there is no password
> authenication involved with NFS, so you only have to a) bind to a low
> port and b) use the same UID on the client as the user that has files
> on the NFS share that you want (rw) access to.
> 
> Now, consider a malicious user, who has prepared his laptop at home,
> plugs it in to the local network, uses the same ip as one of the LTSP
> servers, runs a bad script, and in a moment every users files are gone! A
> alternative way would be booting from a customized floppy, if the thin
> clients offer that possibility.
> 
> I have only a limited understanding of security issues, but am I wrong
> here?


*** A possible solution may be to create a VPN(IPSEC) betweeen the client
and the server. Allow the home directory to be mounted only through the
VPN.




_____________________________________________________________________
Ltsp-discuss mailing list.   To un-subscribe, or change prefs, goto:
      https://lists.sourceforge.net/lists/listinfo/ltsp-discuss
For additional LTSP help,   try #ltsp channel on irc.openprojects.net

Reply via email to