Avatar of sunhux
sunhux asked on

Weaknesses & mitigations for using NFS on Solaris

In one apps project, they requested to use NFS (Netw File Share)  on Solaris:
My concern is
a) unlike Windows which can have Windows firewall to restrict who can access the NFS share
    (ie endpoint firewall), Solaris are not known to have its own endpoint firewall
b) NFS traffic are not encrypted, correct?
c) NFS authentication is weak?  : Pls elaborate in what way?

What are the mitigations we can put in place if the apps team still wants it?
OS Security* vulnerabilitySecurity

Avatar of undefined
Last Comment
robocat

8/22/2022 - Mon
robocat

NFS was not very secure in version 2 and 3.  This is why it got a bad name.

NFSv4 has lots of security features, but they are not enabled by default:

- kerberos authentication allows for secure authentication and integration with AD
- nfsv4 traffic can optionally be encrypted
- nfs shares can be exported to a limited set of hosts
- nfsv4 allows ACLs.

NFSv4 can be a bit of a challenge to set up, but when done correctly it can be very secure.  However it is still recommended not to expose it directly to the internet but over a VPN if needed for remote sites.
ASKER
sunhux

Thanks.

>kerberos authentication allows for secure authentication and integration with AD
In our case, we're on Solaris, so it won't be AD integration: will it still use Kerberos authentication?
ASKER
sunhux

And with NFSv4, can we enable encryption for data in motion & data at rest??
Experts Exchange is like having an extremely knowledgeable team sitting and waiting for your call. Couldn't do my job half as well as I do without it!
James Murphy
ASKER CERTIFIED SOLUTION
robocat

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
See how we're fighting big data
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question
ASKER
sunhux

Can  "Data in Motion" ie when copying to/from  NFSv4 be encrypted?
SOLUTION
Log in to continue reading
Log In
Sign up - Free for 7 days
Get an unlimited membership to EE for less than $4 a week.
Unlimited question asking, solutions, articles and more.