LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-09-2005, 09:53 PM   #1
Retrievil_Knievil
Member
 
Registered: Mar 2004
Location: Stavanger, Norway
Distribution: Gentoo, Slackware/SLAX, Knoppix, CentOS, IPCop & DSL
Posts: 138

Rep: Reputation: 21
Secure file sharing and roaming profile


Hi all,

I am currently setting up a "trial-environment" at home, attempting to set up a office-type network with obsolete equipment and Linux. This is producing a couple of grey hairs, but has proven to be a very educational experience.

My question is this:

To achieve full functionality in file sharing with maximum security, which protocol/option should I choose? I have tried some of the types that are standard, but have actually landed on ftp for now, since it is the easiest to configure and can be accessed from outside my smoothwall without configuring anything I havn't done before..

Is there any "perfect solution" out there?

My desire is to mount network shares at boot-time, this will give me plenty of ways to configure what I need. But this has to be done securely, and must be done on a user-level security basis.

All input is appreciated!
 
Old 01-10-2005, 10:36 AM   #2
doc.nice
Member
 
Registered: Oct 2004
Location: Germany
Distribution: Debian
Posts: 274

Rep: Reputation: 34
how about using nfs (which can deny root access over network) and a nis server (was: sun Yellow pages YP),
the nis can "copy" your passwd file, so the uids are in sync and then you can access your network mounted /home/...
but please don't ask difficult problems, since I've just started experimenting with that.
google for "HOWTO nis", this will bring a lot of info...

hth,
Flo
 
Old 03-19-2008, 10:09 AM   #3
Retrievil_Knievil
Member
 
Registered: Mar 2004
Location: Stavanger, Norway
Distribution: Gentoo, Slackware/SLAX, Knoppix, CentOS, IPCop & DSL
Posts: 138

Original Poster
Rep: Reputation: 21
The final solution

Hi,

Would just like to say that after two+ years of using different experimental solutions, I wound up using a combination of SSH, rsync and home made scripts to keep a single NFS repository up-to-date at each office location.

So far the process has been running smoothly, but to run this in a large environment, I would have to spend a lot of time on rights management to make sure no-one overwrites anything. As long as this is small enough to keep an eye on, all I need is the backups once in a while...

The main reason for doing this is security. This leaves nothing but SSH open, and I can use SSH to forward other ports to my current location if I choose.
 
Old 03-19-2008, 10:52 AM   #4
beadyallen
Member
 
Registered: Mar 2008
Location: UK
Distribution: Fedora, Gentoo
Posts: 209

Rep: Reputation: 36
Probably a bit late now, but did you try ShFS? From what I can tell, it would be able to do everything you wanted, especially with a well configured sshd.conf on the server. If you have tried it and it's not suitable, I'd be interested in knowing why not.

Cheers
 
Old 03-19-2008, 02:03 PM   #5
internetSurfer
Member
 
Registered: Jan 2008
Location: w3c
Distribution: Slackware 12 Zenwalk 5.2
Posts: 71

Rep: Reputation: 16
Have you ever looked at: FreeNAS
 
Old 03-21-2008, 07:18 AM   #6
Retrievil_Knievil
Member
 
Registered: Mar 2004
Location: Stavanger, Norway
Distribution: Gentoo, Slackware/SLAX, Knoppix, CentOS, IPCop & DSL
Posts: 138

Original Poster
Rep: Reputation: 21
shfs and FreeNAS

Hi,

I tried shfs, but it does not build against newer kernels than 2.6.19...?

FreeNAS is a standalone OS, is it not? Looked interesting, but I imagine Webmin on my server would give me the same (and more) when it comes to secure sharing/sync and web-based configuration.

Anyway, the only thing I was going for was a as-secure-as-possible way to share and synchronize my files, for now I am sticking with ssh/rsync and my scripts, but if shfs gets an update (or the kernel, for all I know, I have no idea why it does not build against the newer kernels, but I assume there is a good reason), I will look into it again.

I have also made some shortcuts on my desktop which gives me quick and easy access to the files directly if I should need it, and can have more control over password management if I do it manually. I am using keychain on some machines, but many of them are too publicly available for this to be a solution.
 
Old 03-24-2008, 02:07 AM   #7
Retrievil_Knievil
Member
 
Registered: Mar 2004
Location: Stavanger, Norway
Distribution: Gentoo, Slackware/SLAX, Knoppix, CentOS, IPCop & DSL
Posts: 138

Original Poster
Rep: Reputation: 21
I am thinking about checking out the shfs-fuse package though, anyone here have any experience with it?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
non roaming profile on a roaming profile system fieldyweb Linux - Newbie 1 10-03-2005 12:27 PM
Roaming profile permissions.. Ateo Linux - Networking 3 12-24-2004 05:00 PM
Samba - Roaming profile problem wimdeg Linux - Software 3 11-03-2003 06:24 AM
Samba - Roaming Profile problem wimdeg Linux - Software 0 11-02-2003 03:39 PM
Roaming Profile Problem with Samba JoshT Linux - Networking 0 01-15-2003 01:52 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:14 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration