linux-nfs.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* question about nfs4 with krb5 behavior
@ 2011-01-10 19:55 Roman Shtylman
  2011-01-10 20:35 ` Jeff Layton
  2011-01-10 20:48 ` Kevin Coffman
  0 siblings, 2 replies; 7+ messages in thread
From: Roman Shtylman @ 2011-01-10 19:55 UTC (permalink / raw)
  To: linux-nfs

I have setup nfs4 with krb5 server and successfully mounted a client. Two 
people can log into the client box and both access their respective shares and 
not each other's. However, when one user (who lets say has root privs) uses 
root to become the second user (using su) then that user can now access the 
info of the user he became.

I was under the impression that this should not be possible as the tickets for 
access should still be tied to the first user they logged in as. Is this true? 
Or do I have an error in my setup?

Process:
Login as user A
(User B logs into the machine from another terminal)
sudo su B (to become user B on the machine)
<can now edit files which belong to B>

If User B does not login before user A becomes user B, user A is not able to 
edit user B's files even after he becomes user B.

Kernel version: 2.6.32-24

any clarification on behavior would be appreciated.

cheers,
~Roman

^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2011-01-11  0:47 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2011-01-10 19:55 question about nfs4 with krb5 behavior Roman Shtylman
2011-01-10 20:35 ` Jeff Layton
2011-01-10 20:45   ` Roman Shtylman
2011-01-10 20:54     ` Kevin Coffman
2011-01-10 20:56     ` Trond Myklebust
2011-01-11  0:38     ` Daniel.Muntz
2011-01-10 20:48 ` Kevin Coffman

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).