Sun Microsystems, Inc.  Oracle System Handbook - ISO 7.0 May 2018 Internal/Partner Edition
   Home | Current Systems | Former STK Products | EOL Systems | Components | General Info | Search | Feedback

Asset ID: 1-72-2137942.1
Update Date:2016-05-20
Keywords:

Solution Type  Problem Resolution Sure

Solution  2137942.1 :   Oracle ZFS Storage Appliance: Why can clients mount /export and see shares they do not have permission to access?  


Related Items
  • Sun ZFS Storage 7320
  •  
  • Oracle ZFS Storage ZS3-BA
  •  
  • Sun Storage 7210 Unified Storage System
  •  
  • Oracle ZFS Storage ZS3-2
  •  
  • Oracle ZFS Storage ZS3-4
  •  
  • Sun Storage 7410 Unified Storage System
  •  
  • Sun ZFS Storage 7420
  •  
  • Oracle ZFS Storage ZS4-4
  •  
  • Sun Storage 7310 Unified Storage System
  •  
  • Sun Storage 7110 Unified Storage System
  •  
  • Sun ZFS Storage 7120
  •  
Related Categories
  • PLA-Support>Sun Systems>DISK>ZFS Storage>SN-DK: ZS
  •  




In this Document
Symptoms
Cause
Solution


Created from <SR 3-12551935571>

Applies to:

Oracle ZFS Storage ZS3-2 - Version All Versions to All Versions [Release All Releases]
Oracle ZFS Storage ZS3-4 - Version All Versions to All Versions [Release All Releases]
Oracle ZFS Storage ZS4-4 - Version All Versions to All Versions [Release All Releases]
Oracle ZFS Storage ZS3-BA - Version All Versions to All Versions [Release All Releases]
Sun Storage 7110 Unified Storage System - Version All Versions to All Versions [Release All Releases]
7000 Appliance OS (Fishworks)

Symptoms

 A client is allowed to mount /export and view all shares presented by the appliance, even those to which it does not have access.

 

Cause

In the ZFS Storage Appliance Management interface under the NFS service there is a setting for "Mount visibility".

 

In the Browser User Interface (BUI) this is under  Configuration > Services > NFS

 

This setting can be seen in the Command Line Interface (CLI) using:

zfssa:> configuration services nfs get mount_visibility
mount_visibility = full

 

Solution

The Mount visibility property lets you limit the availability of information about share access lists and remote mounts from NFS clients.

Setting this to "Restricted" restricts access such that a client can see only the shares which it is allowed to access.

Setting this to "Full" allows all clients to see shares regardless of their access permissions.

Oracle ZFS Storage Appliance Administration Guide, NFS Properties

 

Before changing this parameter make sure you are aware of any possible impacts this will have on your environment.

 


Attachments
This solution has no attachment
  Copyright © 2018 Oracle, Inc.  All rights reserved.
 Feedback