From mboxrd@z Thu Jan 1 00:00:00 1970 From: simo Subject: Re: [RFC/PATCH] cifs.upcall: use kernel.provided principal name if available Date: Mon, 12 Sep 2011 10:00:47 -0400 Message-ID: <1315836047.22877.313.camel@pico.li.ssimo.org> References: <1315322512-10652-1-git-send-email-martin.wilck@ts.fujitsu.com> <1315322794-10725-1-git-send-email-martin.wilck@ts.fujitsu.com> <20110906121017.7ce0018b@tlielax.poochiereds.net> <4E673D6F.90606@ts.fujitsu.com> <20110907090321.2196de8f@tlielax.poochiereds.net> <1315431768.22110.4.camel@obed> <4E686D69.9090503@ts.fujitsu.com> <1315467589.22110.55.camel@obed> <4E68BACD.2020403@ts.fujitsu.com> <1315486914.541.14.camel@obed> <4E68BF73.2090707@ts.fujitsu.com> <1315488187.541.16.camel@obed> <4E68EEAE.2090102@ts.fujitsu.com> <20110909093736.082f0ea4@corrin.poochiereds.net> <4E6DCA86.8020707@ts.fujitsu.com> <20110912094114.4e7f2b8e@corrin.poochiereds.net> Mime-Version: 1.0 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: 7bit Cc: Martin Wilck , "linux-cifs-u79uwXL29TY76Z2rM5mHXA@public.gmane.org" , "samba-technical-w/Ol4Ecudpl8XjKLYN78aQ@public.gmane.org" , Martin Wilck , Andrew Bartlett To: Jeff Layton Return-path: In-Reply-To: <20110912094114.4e7f2b8e-4QP7MXygkU+dMjc06nkz3ljfA9RmPOcC@public.gmane.org> Sender: linux-cifs-owner-u79uwXL29TY76Z2rM5mHXA@public.gmane.org List-ID: On Mon, 2011-09-12 at 09:41 -0400, Jeff Layton wrote: > On Mon, 12 Sep 2011 11:01:58 +0200 > Martin Wilck wrote: > > > > For the record, I'm not 100% opposed to adding something like this as a > > > workaround. What would probably be better would be a way for someone to > > > specify the SPN in the mount options. The kernel could then pass that > > > to the upcall and we wouldn't need to trust this string from the > > > server. Admins would of course need to know what SPN to put in there > > > however. Something like: > > > > > > -o spn=cifs/otherhostname.example.com > > > > Sounds good. In our AD environment, an admin can do > > > > ldapsearch "(cn=$COMPUTERNAME)" serviceprincipalname > > > > to get the supported principal name(s). > > > > If that's the standard mechanism that windows machines use to determine > this, we could consider doing something similar in cifs.upcall. Maybe > add a new command-line option that tells it to query a particular LDAP > server with krb5 auth to determine this? No Windows clients do not rely on that. It's a mixture of dscracknames RPC and the KDC doing canonicalization on its own IIRC. Simo. -- Simo Sorce Samba Team GPL Compliance Officer Principal Software Engineer at Red Hat, Inc.