Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 30 Jan 2001 18:42:50 -0700 (MST)
From:      "Geoffrey T. Falk" <gtf@cirp.org>
To:        freebsd-security@FreeBSD.org
Subject:   Re: nfsd lacks support for tcp_wrapper
Message-ID:  <200101310142.SAA15008@h-209-91-79-2.gen.cadvision.com>
In-Reply-To: <Pine.BSF.4.32.0101302048060.89689-100000@taygeta.dbai.tuwien.ac.at>

next in thread | previous in thread | raw e-mail | index | archive | help
On 31 Jan, Gerald Pfeifer wrote:
> Unless we completely missed something, nfsd does lack support for
> tcp_wrapper, doesn't it?
> 
> As NFS is a rather critical security-wize this seems like a big omission.


IP filters are always better than TCP wrappers. NFS should only be used
behind a good firewall anyways.

If you are paranoid about IP and DNS spoofing on the local network,
don't use plain NFS...

Geoffrey




To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?200101310142.SAA15008>