All of lore.kernel.org
 help / color / mirror / Atom feed
From: "J. Bruce Fields" <bfields@fieldses.org>
To: Helge Bahmann <hcb@chaoticmind.net>
Cc: nfs@lists.sourceforge.net
Subject: Re: lockd and krb5
Date: Sun, 19 Nov 2006 12:40:30 -0500	[thread overview]
Message-ID: <20061119174030.GA15608@fieldses.org> (raw)
In-Reply-To: <200611191831.58047.hcb@chaoticmind.net>

On Sun, Nov 19, 2006 at 06:31:57PM +0100, Helge Bahmann wrote:
> Am Freitag, 17. November 2006 19:44 schrieben Sie:
> > On Fri, Nov 17, 2006 at 09:22:40AM +0100, Helge Bahmann wrote:
> > > > > > Is the KDE startup that often triggers this at initial login, or at
> > > > > > some other time?
> > > > >
> > > > > seems completely erratic; it happens both at initial login as well as
> > > > > second login (after successful logout, but before credentials
> > > > > expire); if there is any regularity at all then it seems that initial
> > > > > login seems more likely to succeed
> > > >
> > > > Is the filesystem exported under both secuirty flavors (krb5 and sys),
> > > > with the export options otherwise the same?
> > >
> > > it is exported to the following clients:
> > > *(ro,all_sqash,fsid=9)
> > > test.client.for.auth_unix(rw,sync,fsid=9)
> > > gss/krb5(rw,sync,fsid=9)
> >
> > Do you see the same problems if your exports all have the same options?
> > E.g.
> >
> > 	*(rw,sync,fsid=9)
> > 	gss/krb5(rw,sync,fsid=9)
> 
> this seems kind of pointless because then I would be exporting the whole 
> filesystem with "sys" security which is exactly what I want to avoid

I agree; but knowing whether you can reproduce the same problem with the
above configuration might help determine where exactly the bug is.

(Unfortunately, though, there's a known problem here: since the lockd
client always uses auth_sys, locking will not work on a client that
doesn't have auth_sys access to the export.  I'm not sure yet what the
right fix is for that problem.)

> but AFAIC remember the server had an active export entry with sys
> security for the test machine with the exact same options as for
> gss/krb5, only "world" export was marked ro,all_squash during the gss
> test

Yes, I'm not sure why that didn't work.

> but I will make sure to include this when I try to capture traffic
> logs next week

Thanks.--b.

-------------------------------------------------------------------------
Take Surveys. Earn Cash. Influence the Future of IT
Join SourceForge.net's Techsay panel and you'll get the chance to share your
opinions on IT & business topics through brief surveys - and earn cash
http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV
_______________________________________________
NFS maillist  -  NFS@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/nfs

  reply	other threads:[~2006-11-19 17:40 UTC|newest]

Thread overview: 9+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2006-11-16 10:37 lockd and krb5 Helge Bahmann
2006-11-16 14:21 ` Kevin Coffman
2006-11-16 16:02   ` Helge Bahmann
2006-11-16 16:27     ` J. Bruce Fields
2006-11-17  8:22       ` Helge Bahmann
2006-11-17 18:44         ` J. Bruce Fields
2006-11-19 17:31           ` Helge Bahmann
2006-11-19 17:40             ` J. Bruce Fields [this message]
2006-11-17 11:38       ` Helge Bahmann

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20061119174030.GA15608@fieldses.org \
    --to=bfields@fieldses.org \
    --cc=hcb@chaoticmind.net \
    --cc=nfs@lists.sourceforge.net \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.