LinuxQuestions.org
Help answer threads with 0 replies.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 04-22-2006, 03:53 AM   #1
vivek reddy
LQ Newbie
 
Registered: Jan 2006
Location: Bangalore, India
Distribution: RHEL-4, fedora core 3, SLES-9,ubuntu 5.1
Posts: 22

Rep: Reputation: 15
role of ndsd in netstorage


hey guys,

software- OES SP2 on SLES-9.

i have setup a netstorage server on the oes machine. i have given rights to a user(say "test1") to read and write to the files. no rights to delete. it works perfectly fine on a local machine. the problem arises when the user "test1" accesses the same files via NetStorage.

i have written some scripts to keep track of the users and processes that access the file on the NSS server.

on a local system the script reports the user as "test1" and the process as /sbin/cat. which looks perfectly fine.

when the same file is accessed via NetStorage the script reports the user as "root" and the process as /usr/sbin/ndsd

that log tells me that the user accessing the file is root and the process is ndsd. there are no problems as of now.

the only thing that is worrying me:
1: do we create a vunerability to external treats if "ndsd" accesses the file as root even when you are logged in as a user with limited permissions. can the user take advantage of this situation and create trouble.
2: who is this ndsd. what has this process got to do with NetStorage.

can any one post a link to the solution or answer my question please.

Sorry for this long never ending post.

 
Old 04-22-2006, 05:43 AM   #2
jschiwal
LQ Guru
 
Registered: Aug 2001
Location: Fargo, ND
Distribution: SuSE AMD64
Posts: 15,733

Rep: Reputation: 682Reputation: 682Reputation: 682Reputation: 682Reputation: 682Reputation: 682
According to this: http://www.novell.com/coolsolutions/.../1651.html#8.6
NDS is the "Netware core protocol/eDirectory"

This link also contains steps for securing the server.

The ndsd service is running a root because it is a system service, and not run directly by the user. The web server that the user uses to access the files is probably running in a chroot jail as a demoted system user.

Last edited by jschiwal; 04-22-2006 at 05:57 AM.
 
Old 04-24-2006, 12:41 AM   #3
vivek reddy
LQ Newbie
 
Registered: Jan 2006
Location: Bangalore, India
Distribution: RHEL-4, fedora core 3, SLES-9,ubuntu 5.1
Posts: 22

Original Poster
Rep: Reputation: 15
thanks a lot.

but will it compromise the security of my system or will it make it vurnerable to external threats cos we have an application using ndsd. i was just thinking of redesigning the whole arch of the application to byepass the ndsd usage.
 
Old 04-25-2006, 06:05 PM   #4
jschiwal
LQ Guru
 
Registered: Aug 2001
Location: Fargo, ND
Distribution: SuSE AMD64
Posts: 15,733

Rep: Reputation: 682Reputation: 682Reputation: 682Reputation: 682Reputation: 682Reputation: 682
If you were using Samba, for example, smbd would be running as root also. These are system services that run in the background of the server. I'm not familiar with ndsd, so I don't know if there are any security issues surrounding it. You might want to peruse security websites or mailing lists for an answer.
 
Old 04-28-2006, 08:46 AM   #5
geletine
Member
 
Registered: Apr 2005
Distribution: Slackware
Posts: 213
Blog Entries: 2

Rep: Reputation: 30
As we are on the topic of Novell NetStorage ...

How can i access my /NetStorage/Home@BC_TREE/ files via a ftp client that supports https?
I have set up to use https protocol,set my user/password, added the host name extranet.barnet.ac.uk
i had to disable verify ssl peer for it to even connect otherwise i get this error

Quote:
rtificate at depth: 2
Issuer = /C=BE/O=GlobalSign nv-sa/OU=Root CA/CN=GlobalSign Root CA
Subject = /C=BE/O=GlobalSign nv-sa/OU=Primary Secure Server CA/CN=GlobalSign Primary Secure Server CA
Error 20:unable to get local issuer certificate
I am using gftp , which fully supports https
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
xhost just works as root role Pants Linux - Software 1 02-03-2006 07:04 PM
Role Playing Server webwolf70 Linux - Games 0 09-17-2005 04:06 PM
Linux Support role? venkat_bommireddipal Linux - Certification 1 09-15-2005 02:31 PM
Another bash question (I'm on a role :p) lowpro2k3 Programming 7 03-28-2005 11:12 PM
What's the role of ##*. ? Rex_chaos Linux - General 1 04-29-2002 09:54 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 01:45 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration