RFC 2623:NFS Version 2 and Version 3 Security Issu...
RFC-Ref

AUTH


Click on the red underlined text to get to the source

... The AUTH_NONE flavor provides null authentication, that is, no authentication information ...
... The AUTH_SYS flavor provides a UNIX-style user identifier, group identifier ...
... The AUTH_DH (sometimes referred to as AUTH_DES ...
... The AUTH_DH (sometimes referred to as AUTH_DES [RFC1057]) flavor ...
... The AUTH_KERB4 flavor provides DES encrypted authentication ...


... AUTH_SYS ...
... Using the AUTH_SYS flavor of authentication, the server gets the client ...
... AUTH_DH and AUTH_KERB4 ...
... AUTH_DH and AUTH_KERB4 ...
... The AUTH_DH and AUTH_KERB4 styles of security ...
... The AUTH_DH and AUTH_KERB4 styles of security are based on a network ...
... DES encryption and public keys in the case of AUTH_DH, and DES ...
... encryption and Kerberos secret keys (and tickets) in the AUTH_KERB4 case. Again, the server and client must agree on the identity ...
... operating system independent than the user identifier and group identifier mapping in AUTH_SYS. Also, because the authentication parameters are encrypted ...
... Note that the discussion of AUTH_NONE, AUTH_SYS, AUTH_DH ...
... Note that the discussion of AUTH_NONE, AUTH_SYS, AUTH_DH, AUTH ...
... discussion of AUTH_NONE, AUTH_SYS, AUTH_DH, AUTH_KERB4, ...
... AUTH_SYS, AUTH_DH, AUTH_KERB4, and RPCSEC_GSS does not imply that the NFS ...
... be authenticated with a flavor stronger than AUTH_SYS. This is a problem because the RPCSEC_GSS protocol uses NULL for control messages ...
... accept the NULL procedure ping over AUTH_NONE and AUTH_SYS, in addition to other RPC ...
... accept the NULL procedure ping over AUTH_NONE and AUTH_SYS, in addition to other RPC security ...
... often the case that, for unattended operation in concert with an automounter [Callaghan], the AUTH_DH, AUTH_KERB4, or RPCSEC_GSS ...
... Callaghan], the AUTH_DH, AUTH_KERB4, or RPCSEC_GSS credentials ...
... NFS client will use AUTH_NONE or AUTH_SYS for the initial NFS operations used to mount a ...
... client will use AUTH_NONE or AUTH_SYS for the initial NFS operations used to mount a file system ...
... If a client uses AUTH_NONE, the server's options are the same as the above, except that AUTH_NONE carries with it no user identity ...
... client uses AUTH_NONE, the server's options are the same as the above, except that AUTH_NONE carries with it no user identity. In order to allow the request, on many operating systems ...
... attacker must still be able impersonate a user's credentials, which is simple for AUTH_SYS, but harder for AUTH_DH ...
... credentials, which is simple for AUTH_SYS, but harder for AUTH_DH, AUTH_KERB4, and RPCSEC_GSS ...
... but harder for AUTH_DH, AUTH_KERB4, and RPCSEC_GSS. ...
... flavor string name AUTH_NONE none AUTH_SYS sys ...
... AUTH_NONE none AUTH_SYS sys AUTH_DH ...
... AUTH_SYS sys AUTH_DH dh AUTH ...
... AUTH_DH dh AUTH_KERB4 krb4 ...


... number space as regular RPC security flavors like AUTH_NONE, AUTH_SYS, AUTH ...
... security flavors like AUTH_NONE, AUTH_SYS, AUTH_DH, AUTH ...
... AUTH_NONE, AUTH_SYS, AUTH_DH, AUTH_KERB4, and RPCSEC_GSS ...
... AUTH_SYS, AUTH_DH, AUTH_KERB4, and RPCSEC_GSS. The idea is that each pseudo ...
... pseudo flavor number, an ASCII string name for the flavor (for example "none" has been assigned for AUTH_NONE), and ...


... client uses a weak security flavor like AUTH_SYS to query a Version 3 MOUNT ...


... Protocol Specification Version 2", RFC 1057, June 1988. This RFC is being referenced for its description of the AUTH_DH (AUTH_DES ...
... 1057, June 1988. This RFC is being referenced for its description of the AUTH_DH (AUTH_DES) RPC security ...



Google
Web
RFC-Ref