NFS Support for Linux Integrity Measurement Architecture

NFS Support for Linux Integrity Measurement Architecture

Linux Foundation via YouTube Direct link

NFS Support for the Linux Integrity Measurement Architecture Chuck Lever, Oracle Corporation

1 of 9

1 of 9

NFS Support for the Linux Integrity Measurement Architecture Chuck Lever, Oracle Corporation

Class Central Classrooms beta

YouTube videos curated by Class Central.

Classroom Contents

NFS Support for Linux Integrity Measurement Architecture

Automatically move to the next video in the Classroom when playback concludes

  1. 1 NFS Support for the Linux Integrity Measurement Architecture Chuck Lever, Oracle Corporation
  2. 2 NFS with Integrity Measurement
  3. 3 Some storage servers do not have a user execution environment (e.g., filers) Storage servers and clients may run different operating systems with different semantics • Filesystems on storage server m…
  4. 4 Extend envelope of protection from NFS server to end users on NFS clients • Enable installation of IMA-protected executables from NFS clients Enable appraisal policy on an NFS client to be different …
  5. 5 transport via NFS - Corruption of IMA metadata is detected when signature is verified - Corruption of file content is detected when it is appraised
  6. 6 supported by NFS protocol - NFSv4 ACLs are not the same as POSIX ACLS - NFS protocol would need to expose the list of protected attributes and FS UUID
  7. 7 How do we decide if the specified extension is effective complete? - When will prototype implementation be ready to merge upstream? • Is performance a consideration? • Is IMA offload an interesting u…
  8. 8 Whine about legacy technologies! - Kerberized NFS, NFSv4 ID mapping and ACLS Throw tomatoes at new topics! - NFS support for capabilities and other LSM
  9. 9 LINUX SECURITY SUMMIT

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.