|
|
Subscribe / Log in / New account

A rough start for ksmbd

A rough start for ksmbd

Posted Oct 7, 2021 20:27 UTC (Thu) by ejr (subscriber, #51652)
In reply to: A rough start for ksmbd by developer122
Parent article: A rough start for ksmbd

So if any one is compromised, it opens *every* user's files by changing that local mapping.


to post comments

A rough start for ksmbd

Posted Oct 8, 2021 14:48 UTC (Fri) by bfields (subscriber, #19510) [Link]

I'm not sure I understand your threat model here.

In the absence of kerberos, the server's mostly just trusting the clients to correctly represent who's accessing the filesystem anyway.

I seem to recall one or two people making an attempt at adding this kind of mapping, and it turning out to be more complicated than expected. But that was a while ago. I wonder if any of the container work done since then would be useful here.

Anyway, there'd have to be someone willing to look into it and do the work.


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds