LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-02-2005, 09:15 AM   #1
phonecian
Member
 
Registered: Jul 2003
Location: Au
Distribution: SLES8, centOS 3.5 & 4 servers, xandros desktops
Posts: 95

Rep: Reputation: 15
nfs question


I'm not sure if this question belongs here or in the Networking forum. I'm sorry if its in the wrong forum.

After running rkhunter on a (CentOS 3.5) file server I responded to one of its complaints by dropping support for SSH V1. I was surprised next when the nfs connections to clients were all broken. I was unaware the NFS service relies on SSH. However,when I reinstated SSH V1 support the NFS connections came back up again. So apparently it does.

I was surprised because I thought NFS was a plain text protocol without any security. Could someone explain for me how NFS uses SSH?
Thanks
 
Old 10-02-2005, 10:48 AM   #2
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
I've seen NFS tunneling through SSH, but I 'm not aware of any distros that use NFS encryption/tunneling by default. Could you explain in more detail the steps you took to disable SSH v1 support. Also, take a look at the output of ps aux and see how sshd is running (ps aux | grep sshd). With ssh tunneling you'll see it running with the port forwarding options.
 
Old 10-02-2005, 05:37 PM   #3
phonecian
Member
 
Registered: Jul 2003
Location: Au
Distribution: SLES8, centOS 3.5 & 4 servers, xandros desktops
Posts: 95

Original Poster
Rep: Reputation: 15
Yes the steps I took were to stop SSH1 by removing protocol 1 from the line in /etc/ssh/sshd_config below
#Port 22
#Protocol 2,1
That seems to have been sufficient to break nfs

The output of ps aux | grep sshd (after restoring ssh1) is
[root@lance netadmin]# ps aux | grep sshd
root 1668 0.0 0.1 3664 516 ? S Oct02 0:00 /usr/sbin/sshd
root 5725 0.0 0.2 4244 772 pts/0 S 08:14 0:00 vi sshd_config
root 5800 0.0 0.2 3672 660 pts/2 S 08:18 0:00 grep sshd

Thanks
 
Old 10-02-2005, 09:34 PM   #4
stickman
Senior Member
 
Registered: Sep 2002
Location: Nashville, TN
Posts: 1,552

Rep: Reputation: 53
Per chance did you restart networking on the server without unmounting the NFS volumes on the clients first?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Simple NFS question mazzo Linux - Newbie 2 07-11-2005 07:50 AM
NFS question xushi Solaris / OpenSolaris 1 05-15-2005 05:02 AM
NFS question sassman Linux - Networking 4 11-17-2004 12:24 PM
NFS Client question def1014 Linux - Networking 0 07-22-2003 03:02 PM
nfs question jaysan Linux - Networking 1 05-04-2001 07:29 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:00 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration