[PATCH] Force mountd(8) to a specified port.
Darren Reed
avalon at caligula.anu.edu.au
Tue Mar 2 15:24:28 PST 2004
In some mail from Bruce M Simpson, sie said:
> Hi all,
>
> I have a requirement to run NFS read-only in an Internet-facing colocation
> environment. I am not happy with packet filters alone around rpcbind, call
> me paranoid, so I just spent the last few minutes cutting this patch.
>
> As you are aware, RPC applications can be forced to listen on a known port
> through the sin/sa argument to bindresvport[_sa](). Why several Linux
> distributions have this feature yet none of the BSDs do is beyond me...
>
> Please let me know your thoughts. If there are no valid objections I plan
> to commit it.
I'm confused by your first paragraph...the primary purpose of a patch
like this would be, I imagine, to support being able to write filter
rules for your firewall with a specific port defined rather than have
to determine it after rpcbind & mountd have started.
Darren
More information about the freebsd-security
mailing list