From: "François Valenduc" <francois.valenduc@skynet.be>
To: Kevin Coffman <kwc@umich.edu>
Cc: "J. Bruce Fields" <bfields@fieldses.org>, linux-nfs@vger.kernel.org
Subject: Re: nfs and kerberos authentification problem.
Date: Thu, 04 Sep 2008 21:38:34 +0200 [thread overview]
Message-ID: <48C0393A.5090503@skynet.be> (raw)
In-Reply-To: <4d569c330809041231wcbddde8w419968280de9e39a-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
Kevin Coffman a =E9crit :
> On Thu, Sep 4, 2008 at 2:59 PM, J. Bruce Fields <bfields@fieldses.org=
> wrote:
> =20
>> On Thu, Sep 04, 2008 at 08:53:09PM +0200, Fran=E7ois Valenduc wrote:
>> =20
>>> It's my home directory, so it has normal permission for such a dire=
ctory:
>>> drwxrwsr-x 77 francois francois 4,0K sep 4 20:43 francois/
>>> =20
>> So everybody has permission to read that directory--OK, that shouldn=
't
>> be a problem.
>>
>> =20
>>> I don't think there is someting strange with this. I start running =
out
>>> of ideas to get it working. I have reenabled nfs4 (which I also tri=
ed)
>>> and it give the same problem. In order to do that, I off course cha=
nged
>>> the exports file like this;
>>> =20
>>> /export/francois
>>> ordi-francois(nohide,rw,root_squash,no_subtree_check,sec=3Dsys:krb5=
)
>>> =20
>> Let's just pick nfsv3 and stick with it; both nfsv3 and nfsv4 should
>> work, and switching between the two just complicates the debugging.
>>
>> What does your mount commandline look like?
>>
>> Could you get a network trace? Just start
>>
>> tcpdump -s0 -wtmp.pcap
>>
>> then attempt the mount, then after it fails kill tcpdump and send me
>> tmp.pcap.
>>
>> --b.
>> =20
>
> This may be a stupid question, but can you access the mount using
> auth_sys? As I think I said before, it looks like the Kerberos part
> is working. (Unless there are errors on the client side from
> rpc.gssd.)
>
> =20
I finally found a solution to the problem. It seems that it's needed to=
=20
compile both NFS v3 and v4 server support to make kerberos support=20
working. I find that a bit strange, but with this kernel configuration,=
=20
it is working fine. I find that a bit strange since I export the=20
filesystem as NFS3.
Should we consider this as a bug ? I am running kernel 2.6.26.3.
Thanks a lot for your patience,
=46ran=E7ois
next prev parent reply other threads:[~2008-09-04 19:38 UTC|newest]
Thread overview: 21+ messages / expand[flat|nested] mbox.gz Atom feed top
2008-09-03 18:19 nfs and kerberos authentification problem François Valenduc
2008-09-03 20:12 ` Kevin Coffman
[not found] ` <4d569c330809031312p3515f4d8id9cbec94d871e058-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2008-09-04 16:45 ` François Valenduc
2008-09-04 16:56 ` J. Bruce Fields
2008-09-04 17:31 ` François Valenduc
2008-09-04 17:33 ` J. Bruce Fields
2008-09-04 17:41 ` François Valenduc
2008-09-04 17:49 ` J. Bruce Fields
2008-09-04 17:58 ` François Valenduc
2008-09-04 18:39 ` J. Bruce Fields
2008-09-04 18:53 ` François Valenduc
2008-09-04 18:59 ` J. Bruce Fields
2008-09-04 19:31 ` Kevin Coffman
[not found] ` <4d569c330809041231wcbddde8w419968280de9e39a-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2008-09-04 19:38 ` François Valenduc [this message]
2008-09-04 19:40 ` J. Bruce Fields
2008-09-04 19:41 ` J. Bruce Fields
2008-09-04 19:56 ` François Valenduc
2008-09-05 18:36 ` François Valenduc
2008-09-05 18:57 ` François Valenduc
2008-09-05 21:26 ` J. Bruce Fields
2008-09-05 21:23 ` J. Bruce Fields
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=48C0393A.5090503@skynet.be \
--to=francois.valenduc@skynet.be \
--cc=bfields@fieldses.org \
--cc=kwc@umich.edu \
--cc=linux-nfs@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.