home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.sys.sun.admin
- Path: sparky!uunet!utcsri!geac!censor!comspec!noweh.com!georgn
- From: georgn@noweh.com (Georg S. Nikodym)
- Subject: Re: rdate caused NFS problems on audit directory
- In-Reply-To: rjq@phys.ksu.edu's message of 9 Dec 92 21:16:39 GMT
- Message-ID: <GEORGN.92Dec16000734@idcrisis.noweh.com>
- Sender: georgn@noweh.com (Georg S. Nikodym)
- Organization: Noweh Software, Mississauga, CANADA
- References: <1g5nnnINN2no@moe.ksu.ksu.edu>
- Date: Wed, 16 Dec 1992 05:07:36 GMT
- Lines: 38
-
- In article <1g5nnnINN2no@moe.ksu.ksu.edu> rjq@phys.ksu.edu (Rob Quinn) writes:
-
- Last night I was adjusting the time on my NFS clients with a script
- that rsh's to each and runs 'rdate bohr' (bohr is my main server). I
- had just adjusted the time on bohr, and I don't think any of the clients
- had their time adjusted more than a few minutes. Immediatly I started
- getting NFS errors from the clients and mail. Here's part of my syslog
- showing what happened to one machine:
- [error messages deleted...]
-
- Using 'showfh' I found that the NFS error was referring to
- /etc/security/audit/bohr/files/19921207054007.not_terminated.boltzman.
- The security partitions are mounted with secure NFS from bohr. 'error 5' is
- EIO, I/O error.
- [more stuff deleted for brevity...]
-
- So, can anyone detail the sequence of what happened here? Does secure nfs
- use a timestamp, that I invalidated when I changed the time? Why did the
- warning messages come from the users on the consoles, and not root?
-
- While I won't attempt to detail the sequence of events, I will answer
- questions about secure RPC/NFS. Yes, it does rely on timestamping.
- An encrypted timestamp and window get packaged into each RPC request.
- A server receiving a timestamp that is earlier than previous ones will
- barf. Using rdate in a secure NFS environment is a Bad Idea(TM).
- Investigate other things like ntp that synchronize clocks by skewing
- will probably solve your problems.
-
- For some information on how secure NFS works, I believe you'll find a
- description in the Answerbook. If you don't have that, you can find
- basically the same thing in a white paper on the subject that you can
- get by anon FTP from opcom.sun.ca.
-
- --
- Georg S. Nikodym - (416) 272-5198 / 720-4729
- Noweh Software - Mississauga, Ontario, CANADA
- UUCP: {comspec.com, lsuc.on.ca, uunet.ca}!noweh!georgn
- RFC822: georgn@noweh.COM
-