JavaScript is required to for searching.
Skip Navigation Links
Exit Print View
Oracle® ZFS Storage Appliance Security Guide
Oracle Technology Network
Library
PDF
Print View
Feedback
search filter icon
search icon

Document Information

Oracle ZFS Storage Appliance Security Overview

Initial installation

Physical Security

Administrative Model

ZFSSA Users

Access Control Lists (ACL)

Storage Area Network (SAN)

Data Services

NFS Authentication and Encryption Options

Security Modes

Kerberos Types

iSCSI

RADIUS Support

Server Message Block (SMB)

Active Directory (AD) Domain Mode Authentication

Workgroup Mode Authentication

Local Groups and Privileges

Administrative Operations via the Microsoft Management Console (MMC)

Virus Scan

Delay Engine for Timing Attacks

Data Encryption on the Wire

File Transfer Protocol (FTP)

Hypertext Transfer Protocol (HTTP)

Network Data Management Protocol (NDMP)

Remote Replication

Shadow Migration

SSH File Transfer Protocol (SFTP)

Trivial File Transfer Protocol (TFTP)

Directory Services

System Settings

Remote Administrative Access

Logs

More Information

Documentation Mapping

NFS Authentication and Encryption Options

NFS shares are allocated with AUTH_SYS RPC authentication by default. You can also configure them to be shared with Kerberos security. Using AUTH_SYS authentication, the client’s UNIX uid and gid are passed unauthenticated on the network by the NFS server. This authentication mechanism is easily defeated by anyone with root access on a client therefore it is best to use one of the other available security modes.

Additional access controls can be specified on a per share basis to allow or disallow access to the shares for specific hosts, DNS domains,or networks.

Security Modes

Security modes are set on per-share basis . The following list describes the available Kerberos security settings.

Combinations of Kerberos types may also be specified in the security mode setting. The combination security modes let clients mount with any Kerberos types listed.

Kerberos Types