I'm running all the shares from a Windows 7 PC so SMBv1 should still be used, but maybe some security update has disabled it?
SMBv1 and older (CIFS) is marked as "deprecated" since June 2013:
https://blogs.technet.microsoft.com...-planning-to-get-rid-of-this-old-smb-dialect/
"Deprecation" means: Not yet removed, but marked for removal in a later release. Avoid its use.
Microsoft encourages admins to disable SMBv1 for security reasons (
https://redmondmag.com/articles/2017/05/18/more-advice-on-disabling-windows-smb-1.aspx ) but hasn't
yet disabled or removed it from any Windows or Windows Server version.
So yes, SMBv1 should still be active on your desktop PC, unless you manually disabled it.
The NFS shares are handled by haneWIN NFS Server, NFS3 is in use right now since that is the highest level it supports.
NFS up to NFS3 comes with
absolutely no security at all (under realistic home use cases) and it can not even be activated (It simply does not exist).
NFS3 works in the following way:
It exports
all files below a certain starting point to
any machine matching a specific IP(v4)(-range).
Ownership (root, user1, user2, ...) and file modes (755, 644, ...) are exported 1:1, where in fact user information is exchanged by numeric user id and not the user name.
That means if machine A grants machines B, C, D, ... access to files, they will be accessible for users on B, C, D in exactly the same way as they would on A.
That means the roots of B, C, D are allowed to do really everything to any file/directory on A, no matter who owns them there.
It also means that e.g. user 1000 on C owns any files/directories owned by user 1000 on A, even if user 1000 on A is "snoopy" while it is "mickeymouse" on C.
The "security" of NFS up to NFS3 was based on the assumption (or fact at that time in the
eighties), that networks are administrated centrally. A network using NFS would maintain a central user data base synced with all machines (or even kept centrally when using dumb terminals), so that user 1000 would really be "snoopy" on
all machines and "mickeymouse" would be 1001 on
all machines and nobody else but a real admin would be "root" anywhere. Nobody would bring in "alien" machines into the network.
Nothing of this is true nowadays, your NAS administrates its users independently from your desktop PC, your Raspberry Pi, your E2 box. Any of these machines will have its own root with more or less security against privilege escalation.
Most people will let in friends' smartphones or tablets of which they have no control about the user configuration.
As a matter of fact, security is entirely disabled on E2 boxes, you can log into a terminal session as root without even a password ...
So as soon as any "higher" device exports files/directories to an E2 box, everybody on that E2 box (
incl. whoever pwned it) also has full unrestricted access to any exported files on that higher machine, as everybody is root on E2.
To put it simple: An NFS3 server
exports files/directories and
imports the (in)security concept of the weakest client.
That's why I strongly discourage setting up an NFS3 server on any "valuable" machine (Desktop PC, NAS, ...).
You can however comparable safely
import NFS3 exports of the E2 box to such machines using the noexec option, as E2 can not lose any security anymore, it's already 100% insecure.
Short:
1. Don't set up NFS3 servers anywhere
2. Freely use the NFS3 shares of E2 boxes on other machines, but preferably with "noexec" so that files on the E2 box can never be executed on the clients.
Nevertheless, if I have SMBv2 shares on the PC, I should be able to access them by entering all the necessary information without using Network browser? At least the NFS share does work but cannot be seen with the browser. A similar NFS share on my NAS shows up just nice.
Yes.
You can add all types of shares manually to your E2 box using all the options that Linux offers, not being restricted to the small subset which the network browser supports.
I don't know about OpenViX, but at least OpenATV will even backup and restore those manually configured shares on couch flash.
To manually add shares to your E2 box:
1. Make sure you have not added any share using the network browser (They are stored in some non-system config, which would cause E2 to overwrite your system config on every start)
2. Add the shares to /etc/auto.network (For autofs mount) or /etc/fstab (For permanent mount, not recommended for SMB shares on Windows systems)
Example entries for my shares on OpenATV:
/etc/auto.network
Code:
Wohnzimmer -fstype=cifs,vers=3.02,sec=ntlmsspi,rw,user=root,pass=MYPASS ://vuduo2/Harddisk
Arbeitszimmer -fstype=cifs,vers=3.02,sec=ntlmsspi,rw,user=root,pass=MYPASS ://vusolo2se/Harddisk
Testbox -fstype=cifs,vers=3.02,sec=ntlmsspi,rw,user=root,pass=MYPASS ://vusolo2/Harddisk
Dokus -fstype=cifs,vers=3.02,sec=ntlmsspi,ro,user=Ziggy\ SpaceRat,pass=MYPASS ://NAS/Dokus
Filme -fstype=cifs,vers=3.02,sec=ntlmsspi,ro,user=Ziggy\ SpaceRat,pass=MYPASS ://NAS/Filme
Porn -fstype=cifs,vers=3.02,sec=ntlmsspi,ro,user=Ziggy\ SpaceRat,pass=MYPASS ://NAS/Porn
TV-Serien -fstype=cifs,vers=3.02,sec=ntlmsspi,ro,user=Ziggy\ SpaceRat,pass=MYPASS ://NAS/TV-Serien
As you can see here,
- I'm using SMBv3.02 (Introduced with Windows 8.1 / Windows Server 2012 R2; 3.1.1 as used by Windows 10 / Windows Server 2016 is not supported by all but the very latest Linux kernels) instead of SMBv1 which Linux would default to: vers=3.02
Note:
OpenViX 5.0.x, OpenATV 6.0, ... support vers=2.0 at most when they are the server, only images built from oe-a 4.1 on machines with more than 64MB of flash already support SMBv3 (E.g. OpenATV 6.1, OpenDroid 6.4, ...), so if vers=3.02 fails with some shares, try vers=2.0 for them.
- I'm using sec=ntlmsspi
ntlmsspi is the minimum (!) security for current Mac OS shares.
The default value varied over time (= Linux kernel versions) and Network Browser only tries the default.
You should try in this order:
ntlmsspi,ntlmv2i,ntlmssp,ntlmv2,ntlmi,ntlm
Options that will likely not work in OpenViX 5.0.x (All kernels missing CIFS_UPCALL): krb5i,krb5
- Ziggy\ SpaceRat
The \ "escapes" the space character between "Ziggy" and "SpaceRat". Windows usernames are likely to contain whitespaces, as they usually consist of christian name + surname.
So if the Windows user is "John Doe", you would add "John\ Doe" here.
I haven't played around with Windows servers using "online" (SkyDrive based) accounts yet. You will probably need to put the email here, but I do not know if you then need the PIN (if set) or the password as password.
- //vuduo2 , //vusolo2 , ...
Note that I put the server name in here, not the IP(v4) as Network Browser would.
Multiple benefits:
- Shares work even if the machines have dynamic IPs (Mine get static ones via DHCPv4, SLAAC and partly DHCPv6, but it would work with dynamic assignment as well)
- Entries are simply more readable, as you see the true server here and not its obfuscation by some numeric IP address
- Shares work over IPv6 if available (and will continue to work as people migrate from IPv4-only over Dual Stack to IPv6 in the future)