Re: [k]nfsd, nfs and security questions

Thomas Roessler (roessler@guug.de)
Wed, 3 Dec 1997 10:42:14 +0100


On December 02 1997, Alan Cox wrote:

> MD5 is far more interesting because you can keep an MD5
> key/user cache via a user space keyserver and use MD5
> signed NFS to do user level security. Or even a primitve
> "passord" scheme for per user MD5 signed NFS. MD5 appears
> to be both patent free and exportable (its a signing
> system not crypto)

Any reason not to use SHA1 instead? It seems to be widely
preferred over MD5 now. Apart of that, you don't seem to
be talking about confidentiality of NFS transfers.
Certainly, getting authentication and integrity is a big
win over the present situation, but... ;)

tlr

-- 
Thomas Roessler · 74a353cc0b19 · dg1ktr · http://home.pages.de/~roessler/
   1280/593238E1 · AE 24 38 88 1B 45 E4 C6  03 F5 15 6E 9C CA FD DB