Berend De Schouwer wrote:

>>>*** A possible solution may be to create a VPN(IPSEC) betweeen the client
>>>and the server. Allow the home directory to be mounted only through the
>>>VPN.
>>>
>>A very good solution and one that is not too hefty to implement. 
>> However, how to you store "securely" the secret keys for each 
>>workstation?  The only way that I can think of a solution for this is to 
>>have local storage in some form on the thin-client workstation.
>>
>
>The etherboot bootprom?
>
Hmm.  Interesting.  I wasn't thinking of that as a solution (didn't know 
you might be able to do it that way).  I was thinking primarily of 
Compact Flash or the like as local storage.

>  Its not perfect (you can read it back, if you
>can steal the chip or card.)
>
This is a given.  If you steal someones hard drive, then you will have 
access to their data (unless they have encrypted the filesystem and not 
stored the passphrase on it anywhere).

>  The mkinitrd already allows ip=rom or
>somesuch, so maybe the TFTP kernel can grab a key that way.
>
I would see this as being even more insecure than local storage. 
 Someone can simply sniff the traffic for the ENCRYPTION key being sent 
to the client IN THE CLEAR.  Right?

Or am I missing something?

-- 
Jason A. Pattie
[EMAIL PROTECTED]



_____________________________________________________________________
Ltsp-discuss mailing list.   To un-subscribe, or change prefs, goto:
      https://lists.sourceforge.net/lists/listinfo/ltsp-discuss
For additional LTSP help,   try #ltsp channel on irc.openprojects.net

Reply via email to