5.1 Security Considerations for Implementers

The DFS: Namespace Management Protocol allows any user to establish a connection to the RPC server. The protocol uses the underlying RPC Protocol to retrieve the identity of the caller that made the method call, as specified in [MS-RPCE] section 3.3.3.4.3. Clients SHOULD create an authenticated RPC connection. Servers SHOULD use this identity to perform method-specific access checks.<150>