[Users] Best practice for securing oVirt's NFS mounts
Prakash Surya
surya1 at llnl.gov
Tue Mar 11 17:23:19 UTC 2014
Hi,
All the documentation I've seen states that the oVirt NFS storage should
use the "all_squash,anonuid=36,anongid=36" options. Obviously this isn't
secure, so I'm curious how others have locked down their NFS storage? Is
the best option to just limit access to these NFS exports to the IP
addresses of the hypervisor nodes (and maybe the engine)? Is there a
better way to go about this?
--
Cheers, Prakash
More information about the Users
mailing list