From: James Bardin <jbardin@bu.edu>
To: nfs@lists.sourceforge.net
Subject: Re: nfs sec=krb5 on RHEL and CentOS
Date: Fri, 26 Jan 2007 12:07:45 -0500 [thread overview]
Message-ID: <45BA3561.1020902@bu.edu> (raw)
In-Reply-To: <45B94007.60609@bu.edu>
>
>> On 1/25/07, James Bardin <jbardin@bu.edu> wrote:
>>>
>>> > I'm almost there!
>>> > Between the nfs-utils patch, and the noacl option, I have my 32bit
>>> > systems working. (thanks Steve)
>>> >
>>> > On x86_64, I'm having kerberos problems (exact same config):
>>> >
>>> > rpc.gssd[4871]: handling krb5 upcall
>>> > rpc.gssd[4871]: getting credentials for client with uid xxxx for
>>> > server yyyy.bu.edu
>>> > rpc.gssd[4871]: CC file 'krb5cc_xxxx_bSULEy' being considered
>>> > rpc.gssd[4871]: CC file 'krb5cc_xxxx_bSULEy' matches name check and
>>> > has mtime of 1169750861
>>> > rpc.gssd[4871]: using FILE:/tmp/krb5cc_xxxx_bSULEy as credentials
>>> > cache for client with uid xxxx for server yyyy.bu.edu
>>> > rpc.gssd[4871]: creating context using euid xxxx (save_uid 0)
>>> > rpc.gssd[4871]: creating tcp client for server yyyy.bu.edu
>>> > rpc.gssd[4871]: WARNING: can't create rpc_clnt for server
>>> > engna1.bu.edu for user with uid xxxx: RPC: Success rpc.gssd[4871]:
>>> > WARNING: Failed to create krb5 context for user with uid xxxx for
>>> > server yyyy.bu.edu
>>> > rpc.gssd[4871]: doing error downcall
>>> >
>>> >
>>> x86_64 is working on an older version, I read the errata, and it
>>> shouldn't effect us, but something is wrong in the new ones. This is
>>> with sec=krb5.
>>> nfs-utils-1.0.6-77 causes the above problems
>>> nfs-utils-1.0.6-70 will hang on rpc.gssd
>>> nfs-utils-1.0.6-65 is working.
>>>
>>
> I don't know if it's related, but sometimes when I build an nfs-utils
> src.rpm, it dumps out saying the GSS with KRB5 support not found. If I
> try to build again, it works???
>
I've been testing on CentOS so far with the above results.
Unfortunately, the RHEL4 system for which I was testing, doesn't like
nfs-utils-1.0.6-65.
With nfs-utils-1.0.6-65, rpcgssd dies at
rpc.gssd[5626]: rpcsec_gss: in authgss_create_default()
RPC: AUTH_GSS upcall timed out.
Please check user daemon is running!
The 70 77 patchlevels both give permission denied, and the above rpcgssd
messages.
With the newest patch, I had to symlink lib/libgssapi_krb5.so ->
lib64/libgssapi_krb5.so
This a new, up2date RHEL4, all rpm versions seem to match that of the
CentOS I tested.
-jim
-------------------------------------------------------------------------
Take Surveys. Earn Cash. Influence the Future of IT
Join SourceForge.net's Techsay panel and you'll get the chance to share your
opinions on IT & business topics through brief surveys - and earn cash
http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV
_______________________________________________
NFS maillist - NFS@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/nfs
prev parent reply other threads:[~2007-01-26 17:07 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2007-01-21 22:11 nfs sec=krb5 on RHEL and CentOS james bardin
2007-01-24 11:05 ` Steve Dickson
2007-01-24 15:03 ` James Bardin
2007-01-24 20:58 ` James Bardin
2007-01-24 23:39 ` J. Bruce Fields
2007-01-25 0:14 ` james bardin
2007-01-25 19:43 ` James Bardin
2007-01-25 21:56 ` James Bardin
2007-01-25 23:14 ` Kevin Coffman
2007-01-25 23:40 ` James Bardin
2007-01-26 17:07 ` James Bardin [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=45BA3561.1020902@bu.edu \
--to=jbardin@bu.edu \
--cc=nfs@lists.sourceforge.net \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox