LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-21-2015, 05:38 AM   #1
Lop3
Member
 
Registered: Aug 2013
Posts: 48

Rep: Reputation: Disabled
Question Secure network boot, Secure NFS alternative?


I'm interested in setting up multiple PC's in an office to network boot from one fileserver. To reduce maintenance I'd prefer if the clients don't have any storage of their own.

I see a huge security problem in using plain NFS for this task.
With NFS all a client needs to do is spoof it's IP and then it can read and modify the files of another client.
So this is unacceptable.

Is there some network bootable file protocol in linux that is more secure?

Another option I thought of, I can have ONE read-only root filesystem for ALL clients, and then they mount some other, secure filesystem where they each access their files. But then the question is what network filesystem protocol is secure and can be mounted remotely? SSHFS?

Ideally I don't want to encrypt the files on disk or in transit, because I don't want to increase hardware requirements.

Any ideas?

Last edited by Lop3; 07-21-2015 at 05:42 AM.
 
Old 07-21-2015, 11:55 AM   #2
smallpond
Senior Member
 
Registered: Feb 2011
Location: Massachusetts, USA
Distribution: Fedora
Posts: 4,138

Rep: Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263
Take a look at nfs v4 with Kerberos for the secure filesystem per user.

The idea of having a single root filesystem for everyone is good. Live CDs have a compressed, read-only root with a ram-based read/write overlay filesystem. You can use that as the boot image.
 
1 members found this post helpful.
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
disabling secure boot when secure boot is not an option in BIOS? chexmix Slackware 10 05-28-2015 06:13 PM
LXer: Using secure shell (ssh) for login and secure copy (scp) for data transfer on Linux LXer Syndicated Linux News 0 02-05-2015 11:00 AM
Secure alternative to 2k8 rdp server takayama Linux - Software 3 06-21-2011 10:26 AM
How secure is vsftpd? What alternative is there for more secure access? Gum Linux - Security 5 03-24-2009 05:00 PM
A more secure alternative to http reverse, matahari frenchn00b Debian 5 02-06-2008 03:55 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:38 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration