[Users] Best practice for securing oVirt's NFS mounts

Prakash Surya surya1 at llnl.gov
Tue Mar 11 17:23:19 UTC 2014


Hi,

All the documentation I've seen states that the oVirt NFS storage should
use the "all_squash,anonuid=36,anongid=36" options. Obviously this isn't
secure, so I'm curious how others have locked down their NFS storage? Is
the best option to just limit access to these NFS exports to the IP
addresses of the hypervisor nodes (and maybe the engine)? Is there a
better way to go about this?

-- 
Cheers, Prakash




More information about the Users mailing list