All of lore.kernel.org
 help / color / mirror / Atom feed
From: steve <steve@steve-ss.com>
To: "J. Bruce Fields" <bfields@fieldses.org>
Cc: Jim Rees <rees@umich.edu>,
	Liam Gretton <liam.gretton@leicester.ac.uk>,
	"linux-nfs@vger.kernel.org" <linux-nfs@vger.kernel.org>
Subject: Re: where can I ask user qns about nfs4?
Date: Mon, 06 Feb 2012 19:54:42 +0100	[thread overview]
Message-ID: <4F3021F2.6090607@steve-ss.com> (raw)
In-Reply-To: <20120206163945.GA29579@fieldses.org>

On 06/02/12 17:39, J. Bruce Fields wrote:
> On Sun, Feb 05, 2012 at 12:37:28PM -0500, Jim Rees wrote:
>> Liam Gretton wrote:
>>
>>    On 05/02/2012 14:16, Jim Rees wrote:
>>    >There is a a NFS wiki, and it does have kerberos setup instructions:
>>    >http://wiki.linux-nfs.org/wiki/index.php/Enduser_doc_kerberos
>>    >
>>    >The wiki has mostly been used by developers for developer info but it might
>>    >be a good thing to use it for more general info too.
>>
>>    Thanks, the problem isn't getting NFS with Kerberos to work in
>>    general, it's with AD as the KDC. It seems that NFS still only
>>    accepts DES encrypted Kerberos tickets, and these are specifically
>>    disabled in Windows Server 2008 R2.
>>
>> Wasn't that fixed recently?
> Yes, it supports some AES-based enctypes now, for example.  I wouldn't
> know a better source of the details than
>
> 	git log net/sunrpc/auth_gss/gss_krb5_*
>
> If someone wanted to summarize the situation for the wiki, go for it.
Hi
nfs with arcfour seems OK here with Samba 4. I don't think it's the 
default for AD but your windows admins may be happier with it. I think 
his is the relevant bit:

Kerberos: ENC-TS Pre-authentication succeeded -- HH3$@HH3.SITE using 
arcfour-hmac-md5
Kerberos: AS-REQ authtime: 2012-02-06T19:44:47 starttime: unset endtime: 
2012-02-07T05:44:47 renew till: 2012-02-07T19:44:47
Kerberos: Client supported enctypes: aes256-cts-hmac-sha1-96, 
aes128-cts-hmac-sha1-96, des3-cbc-sha1, arcfour-hmac-md5, des-cbc-crc, 
des-cbc-md5, des-cbc-md4, using arcfour-hmac-md5/arcfour-hmac-md5
Kerberos: Requested flags: renewable-ok
Kerberos: TGS-REQ HH3$@HH3.SITE from ipv4:192.168.1.3:45421 for 
nfs/hh3.hh3.site@HH3.SITE [canonicalize, renewable]
Kerberos: TGS-REQ authtime: 2012-02-06T19:44:47 starttime: 
2012-02-06T19:44:47 endtime: 2012-02-07T05:44:47 renew till: 20

HTH
Steve

  reply	other threads:[~2012-02-06 18:55 UTC|newest]

Thread overview: 24+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2012-02-02  6:39 where can I ask user qns about nfs4? steve
2012-02-02 10:58 ` Tigran Mkrtchyan
2012-02-02 11:33   ` nfs4 keytabs [was:Re: where can I ask user qns about nfs4]? steve
2012-02-02 13:05     ` Tigran Mkrtchyan
2012-02-02 13:29       ` steve
2012-02-02 14:56         ` steve
2012-02-02 18:57           ` Tigran Mkrtchyan
2012-02-03 17:22             ` steve
2012-02-06 13:31               ` steve
2012-02-04 20:50   ` where can I ask user qns about nfs4? Liam Gretton
2012-02-05  9:26     ` steve
2012-02-05 14:16       ` Jim Rees
2012-02-05 16:55         ` Liam Gretton
2012-02-05 17:37           ` Jim Rees
2012-02-06 16:39             ` J. Bruce Fields
2012-02-06 18:54               ` steve [this message]
2012-02-09 18:57           ` Don Riden
2012-02-09 19:33             ` steve
2012-02-10  8:19               ` steve
2012-02-10 18:40                 ` J. Bruce Fields
2012-02-10 19:13                   ` steve
2012-02-10 19:14                     ` J. Bruce Fields
2012-02-10 23:20                       ` steve
2012-02-10 20:47             ` Liam Gretton

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4F3021F2.6090607@steve-ss.com \
    --to=steve@steve-ss.com \
    --cc=bfields@fieldses.org \
    --cc=liam.gretton@leicester.ac.uk \
    --cc=linux-nfs@vger.kernel.org \
    --cc=rees@umich.edu \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.