Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 27 May 2001 13:50:06 +0200 (CEST)
From:      "Hartmann, O." <ohartman@klima.physik.uni-mainz.de>
To:        <freebsd-questions@freebsd.org>
Subject:   NIS/YP root permission problems
Message-ID:  <Pine.BSF.4.33.0105271349410.1547-100000@klima.physik.uni-mainz.de>

next in thread | raw e-mail | index | archive | help
Dear Sirs.

Maybe my problem is trivial for some of yours, but you may offer
help to the stupid ...

We have in an scientific environment a growing server architecture.
All core systems are based on FreeBSD 4.3-STABLE. All servers belong
to a NIS/YP domain and they are under controll of one root!

Now we have a growing part of Linux users and several FreeBSD frontiers
and they wish to be their own root on their local machines. But they need
to participate on the server's filespace.
NIS/YP prevents us from running into problems when keeping UID/GID consistent
and helping to keep passwords consistent. The usual stuff, in this case.

The problem:

The 'outsiders' are their own root on their local machines, but they
mount the home directory of our institute from the main server. The problem
seems to be that if those users belong to a NIS/YP domain, they could
'su' themselfs to root on their local machines and then 'su - USER' su
to any user they mounted on by NFS on their local machine and pretend to
be another person. So they could compromise others data and so on.
Thsi is the reason why I do not want to export our filesystems to those
machines due the fact I can not prevent our servers from beeing used as
NIS/YP domain controllers from the LAN. The situation is really nasty
and I can not change anything due the fact most of the guys around here
are really not interested in those problems - but they pay me :-(

The only thing keeping systems 'secure' is to avoid exporting disks
to untrusted machines using NFS although all UNIX and Linux guys could
join the NIS/YP domain because they are on the local network.

Kerberos is a hint - but I wish to use Kerberos V and it's not in a
usable stage at this time (I can not get the MIT distribution, the new
one due the export limitations and Heimdal on FreeBSD seems to be a
little bit 'weak').

Are their any solutions to prevent other root Supervisors compromising
users on the local fileserver?

I export the appropriate filesystems by maproot=nobody:nobody, but
that prevents root from getting root access on those filesystems exported
by NFS, but if he switch to another user (due its belonging to the same
NIS/YP domain) he grants itself full permissions to access the switched
user's filespace ...

Any suggestions?

--
MfG
O. Hartmann

ohartman@klima.physik.uni-mainz.de
----------------------------------------------------------------
IT-Administration des Institut fuer Physik der Atmosphaere (IPA)
----------------------------------------------------------------
Johannes Gutenberg Universitaet Mainz
Becherweg 21
55099 Mainz

Tel: +496131/3924662 (Maschinensaal)
Tel: +496131/3924144
FAX: +496131/3923532



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.4.33.0105271349410.1547-100000>