All of lore.kernel.org
 help / color / mirror / Atom feed
From: James Bardin <jbardin@bu.edu>
To: nfs@lists.sourceforge.net
Subject: Re: nfs sec=krb5 on RHEL and CentOS
Date: Fri, 26 Jan 2007 12:07:45 -0500	[thread overview]
Message-ID: <45BA3561.1020902@bu.edu> (raw)
In-Reply-To: <45B94007.60609@bu.edu>

>
>> On 1/25/07, James Bardin <jbardin@bu.edu> wrote:
>>>
>>> > I'm almost there!
>>> > Between the nfs-utils patch, and the noacl option, I have my 32bit
>>> > systems working. (thanks Steve)
>>> >
>>> > On x86_64, I'm having kerberos problems (exact same config):
>>> >
>>> > rpc.gssd[4871]: handling krb5 upcall
>>> > rpc.gssd[4871]: getting credentials for client with uid xxxx for
>>> > server yyyy.bu.edu
>>> > rpc.gssd[4871]: CC file 'krb5cc_xxxx_bSULEy' being considered
>>> > rpc.gssd[4871]: CC file 'krb5cc_xxxx_bSULEy' matches name check and
>>> > has mtime of 1169750861
>>> > rpc.gssd[4871]: using FILE:/tmp/krb5cc_xxxx_bSULEy as credentials
>>> > cache for client with uid xxxx for server yyyy.bu.edu
>>> > rpc.gssd[4871]: creating context using euid xxxx (save_uid 0)
>>> > rpc.gssd[4871]: creating tcp client for server yyyy.bu.edu
>>> > rpc.gssd[4871]: WARNING: can't create rpc_clnt for server
>>> > engna1.bu.edu for user with uid xxxx: RPC: Success rpc.gssd[4871]:
>>> > WARNING: Failed to create krb5 context for user with uid xxxx for
>>> > server yyyy.bu.edu
>>> > rpc.gssd[4871]: doing error downcall
>>> >
>>> >
>>> x86_64 is working on an older version, I read the errata, and it
>>> shouldn't effect us, but something is wrong in the new ones. This is
>>> with sec=krb5.
>>> nfs-utils-1.0.6-77 causes the above problems
>>> nfs-utils-1.0.6-70 will hang on rpc.gssd
>>> nfs-utils-1.0.6-65 is working.
>>>
>>
> I don't know if it's related, but sometimes when I build an nfs-utils 
> src.rpm, it dumps out saying the GSS with KRB5 support not found. If I 
> try to build again, it works???
>


I've been testing on CentOS so far with the above results. 
Unfortunately, the RHEL4 system for which  I was testing, doesn't like 
nfs-utils-1.0.6-65.
With nfs-utils-1.0.6-65, rpcgssd dies at
rpc.gssd[5626]: rpcsec_gss: in authgss_create_default()
RPC: AUTH_GSS upcall timed out.
Please check user daemon is running!

The 70 77 patchlevels both give permission denied, and the above rpcgssd 
messages.
With the newest patch, I had to symlink lib/libgssapi_krb5.so -> 
lib64/libgssapi_krb5.so

This a new, up2date RHEL4, all rpm versions seem to match that of the 
CentOS I tested.


-jim


-------------------------------------------------------------------------
Take Surveys. Earn Cash. Influence the Future of IT
Join SourceForge.net's Techsay panel and you'll get the chance to share your
opinions on IT & business topics through brief surveys - and earn cash
http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV
_______________________________________________
NFS maillist  -  NFS@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/nfs

      reply	other threads:[~2007-01-26 17:07 UTC|newest]

Thread overview: 11+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2007-01-21 22:11 nfs sec=krb5 on RHEL and CentOS james bardin
2007-01-24 11:05 ` Steve Dickson
2007-01-24 15:03   ` James Bardin
2007-01-24 20:58   ` James Bardin
2007-01-24 23:39     ` J. Bruce Fields
2007-01-25  0:14       ` james bardin
2007-01-25 19:43         ` James Bardin
2007-01-25 21:56           ` James Bardin
2007-01-25 23:14             ` Kevin Coffman
2007-01-25 23:40               ` James Bardin
2007-01-26 17:07                 ` James Bardin [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=45BA3561.1020902@bu.edu \
    --to=jbardin@bu.edu \
    --cc=nfs@lists.sourceforge.net \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.