Linux NFS development
 help / color / mirror / Atom feed
From: James Bardin <jbardin@bu.edu>
To: nfs@lists.sourceforge.net
Subject: Re: nfs sec=krb5 on RHEL and CentOS
Date: Fri, 26 Jan 2007 12:07:45 -0500	[thread overview]
Message-ID: <45BA3561.1020902@bu.edu> (raw)
In-Reply-To: <45B94007.60609@bu.edu>

>
>> On 1/25/07, James Bardin <jbardin@bu.edu> wrote:
>>>
>>> > I'm almost there!
>>> > Between the nfs-utils patch, and the noacl option, I have my 32bit
>>> > systems working. (thanks Steve)
>>> >
>>> > On x86_64, I'm having kerberos problems (exact same config):
>>> >
>>> > rpc.gssd[4871]: handling krb5 upcall
>>> > rpc.gssd[4871]: getting credentials for client with uid xxxx for
>>> > server yyyy.bu.edu
>>> > rpc.gssd[4871]: CC file 'krb5cc_xxxx_bSULEy' being considered
>>> > rpc.gssd[4871]: CC file 'krb5cc_xxxx_bSULEy' matches name check and
>>> > has mtime of 1169750861
>>> > rpc.gssd[4871]: using FILE:/tmp/krb5cc_xxxx_bSULEy as credentials
>>> > cache for client with uid xxxx for server yyyy.bu.edu
>>> > rpc.gssd[4871]: creating context using euid xxxx (save_uid 0)
>>> > rpc.gssd[4871]: creating tcp client for server yyyy.bu.edu
>>> > rpc.gssd[4871]: WARNING: can't create rpc_clnt for server
>>> > engna1.bu.edu for user with uid xxxx: RPC: Success rpc.gssd[4871]:
>>> > WARNING: Failed to create krb5 context for user with uid xxxx for
>>> > server yyyy.bu.edu
>>> > rpc.gssd[4871]: doing error downcall
>>> >
>>> >
>>> x86_64 is working on an older version, I read the errata, and it
>>> shouldn't effect us, but something is wrong in the new ones. This is
>>> with sec=krb5.
>>> nfs-utils-1.0.6-77 causes the above problems
>>> nfs-utils-1.0.6-70 will hang on rpc.gssd
>>> nfs-utils-1.0.6-65 is working.
>>>
>>
> I don't know if it's related, but sometimes when I build an nfs-utils 
> src.rpm, it dumps out saying the GSS with KRB5 support not found. If I 
> try to build again, it works???
>


I've been testing on CentOS so far with the above results. 
Unfortunately, the RHEL4 system for which  I was testing, doesn't like 
nfs-utils-1.0.6-65.
With nfs-utils-1.0.6-65, rpcgssd dies at
rpc.gssd[5626]: rpcsec_gss: in authgss_create_default()
RPC: AUTH_GSS upcall timed out.
Please check user daemon is running!

The 70 77 patchlevels both give permission denied, and the above rpcgssd 
messages.
With the newest patch, I had to symlink lib/libgssapi_krb5.so -> 
lib64/libgssapi_krb5.so

This a new, up2date RHEL4, all rpm versions seem to match that of the 
CentOS I tested.


-jim


-------------------------------------------------------------------------
Take Surveys. Earn Cash. Influence the Future of IT
Join SourceForge.net's Techsay panel and you'll get the chance to share your
opinions on IT & business topics through brief surveys - and earn cash
http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV
_______________________________________________
NFS maillist  -  NFS@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/nfs

      reply	other threads:[~2007-01-26 17:07 UTC|newest]

Thread overview: 11+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2007-01-21 22:11 nfs sec=krb5 on RHEL and CentOS james bardin
2007-01-24 11:05 ` Steve Dickson
2007-01-24 15:03   ` James Bardin
2007-01-24 20:58   ` James Bardin
2007-01-24 23:39     ` J. Bruce Fields
2007-01-25  0:14       ` james bardin
2007-01-25 19:43         ` James Bardin
2007-01-25 21:56           ` James Bardin
2007-01-25 23:14             ` Kevin Coffman
2007-01-25 23:40               ` James Bardin
2007-01-26 17:07                 ` James Bardin [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=45BA3561.1020902@bu.edu \
    --to=jbardin@bu.edu \
    --cc=nfs@lists.sourceforge.net \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox