Hi All,
It has been a while since I have posted as FOG is working beautifully for us at the moment. I have actually been able to look at some proactive things like security on our infrastructure. This brings me to the point of this post.
As a disclaimer, I am far from a security guru. In fact, I’m quite new to it. I am using a penetration testing solution to try to start figuring some of this stuff out. During my testing on the FOG server here, a few things popped up as critical/high level warnings. I was spooked at first but then I noticed that anything that was flagged had to do with the /images NFS Share.
The first flag was for “NFS Exported Share Information Disclosure”, basically saying that the /images share could be mounted by scanning the host. I figure this is like this so any host can pull from this share during capture/deployment. If this is the case, I am fine with it. If I screwed something up a while back with permissions and left a gaping hole in the security of this server, I’d like to find the best practice for setting permissions for this share. Ideally it would be moderately secure but (very importantly) still be able to image indiscriminately throughout our network. I can provide more info if needed, but I appreciate any input.
The second flag is also related to the /images NFS Share. This one also points to a permissions issue. “The NFS share is user mountable”
I appreciate the help guys and keep up the good work!