From: Jurjen Bokma <j.bokma-39IHFo8E5E0@public.gmane.org>
To: steve <steve-dZ4O0aZtNmBWk0Htik3J/w@public.gmane.org>
Cc: linux-cifs-u79uwXL29TY76Z2rM5mHXA@public.gmane.org
Subject: Re: Kerberized mount.cifs with SMB>1?
Date: Wed, 20 Aug 2014 19:16:44 +0200 [thread overview]
Message-ID: <53F4D7FC.8020405@rug.nl> (raw)
In-Reply-To: <1408545832.2071.6.camel-HkULYb+WTT7YCGPCin2YbQ@public.gmane.org>
On 08/20/2014 04:43 PM, steve wrote:
> On Wed, 2014-08-20 at 16:08 +0200, Jurjen Bokma wrote:
>> Hi,
>>
>> These are the commands that fail with mount error(13): Permission denied
>>
>> mount.cifs //ws.mydomain.com/ydrive /mnt/y
>> -omultiuser,sec=krb5,noexec,nosuid,vers=3.0
> Hi
> The upcall has nothing to go on. Get it working with cifs first:
>
> Who mounts the share? Add a domain user with a uid:gid key to the keytab
> and:
Hi Steve,
thanks for the advice.
I added a key for a domain user to the keytab. User has UID, GID, can
log in on both Windows and Linux, and do kinit and kgetcred. Then I did
what you advise (with cifsuser its username):
> mount.cifs //your/share /mnt -ousername=cifsuser,sec=krb5
This works, as it uses SMB1. SMB1 also works *with* all the frills. But
it fails with 2.0, 2.1 or 3.0:
mount.cifs //your/share /mnt -ousername=cifsuser,sec=krb5,vers=3.0
No significant changes: still no trace of Kerberos in Wireshark.
Is there a way to see what keys upcall is being asked for?
I would very much like to get it working with protocol version 2.0 or later.
Best Regards
Jurjen
>
> add any multiuser frills later.
> HTH,
> Steve
>
>
next prev parent reply other threads:[~2014-08-20 17:16 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-08-20 14:08 Kerberized mount.cifs with SMB>1? Jurjen Bokma
[not found] ` <53F4ABCD.5040909-39IHFo8E5E0@public.gmane.org>
2014-08-20 14:43 ` steve
[not found] ` <1408545832.2071.6.camel-HkULYb+WTT7YCGPCin2YbQ@public.gmane.org>
2014-08-20 17:16 ` Jurjen Bokma [this message]
[not found] ` <53F4D7FC.8020405-39IHFo8E5E0@public.gmane.org>
2014-10-19 19:58 ` Jurjen Bokma
[not found] ` <544417CA.3000609-39IHFo8E5E0@public.gmane.org>
2014-10-19 20:25 ` steve
[not found] ` <54441E2A.6020809-dZ4O0aZtNmBWk0Htik3J/w@public.gmane.org>
2014-10-19 20:30 ` Jurjen Bokma
[not found] ` <54441F79.7040804-39IHFo8E5E0@public.gmane.org>
2014-10-19 20:42 ` steve
[not found] ` <54442233.4090801-dZ4O0aZtNmBWk0Htik3J/w@public.gmane.org>
2014-10-19 20:48 ` Jurjen Bokma
[not found] ` <54442399.5030100-39IHFo8E5E0@public.gmane.org>
2014-10-20 16:24 ` steve
[not found] ` <54453737.7040403-dZ4O0aZtNmBWk0Htik3J/w@public.gmane.org>
2014-10-20 16:37 ` Jurjen Bokma
[not found] ` <54453A48.1050208-39IHFo8E5E0@public.gmane.org>
2014-10-20 17:09 ` Steve French
[not found] ` <CAH2r5msA2D8upKSYVUEC1ygULe9oGa2x0XR5tGeF59bSmjKa3g-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2014-10-20 17:19 ` Jurjen Bokma
2014-08-20 14:44 ` McCall, Andy (IT.PFMS)
-- strict thread matches above, loose matches on Subject: below --
2015-07-24 10:09 Noel Power
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=53F4D7FC.8020405@rug.nl \
--to=j.bokma-39ihfo8e5e0@public.gmane.org \
--cc=linux-cifs-u79uwXL29TY76Z2rM5mHXA@public.gmane.org \
--cc=steve-dZ4O0aZtNmBWk0Htik3J/w@public.gmane.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox