public inbox for linux-nfs@vger.kernel.org
 help / color / mirror / Atom feed
From: raini-9HxftnAiGddWk0Htik3J/w@public.gmane.org
To: nfs@lists.sourceforge.net
Subject: Re: [NFS] NFS/krb and batch jobs - doable?
Date: Fri, 9 Oct 2009 10:05:25 -0700	[thread overview]
Message-ID: <9fc711a4c6b4682ba847cd51ca62f86d.squirrel@webmail.rainiday.com> (raw)
In-Reply-To: <f99e65f7b2fe66fc32dee931fd6bd525.squirrel-2RFepEojUI30fF+2cCIZ11aTQe2KTcn/@public.gmane.org>

>> No, gssd (the client side daemon) will search /tmp for anything that
>> looks like a credcache for the right user, verify that it is a
>> credcache and then pick the one with the latest TGT expiration.
>
>> You're correct that NFS ignores $KRB5CCNAME. It uses the above (less
>> than optimal) heuristic instead.
>
> Thanks for explaining this Jeff - this does accord with what I see - which
> of course leaves my batch job system unpredictable.
>
>> Probably doable, but not trivial. IIRC, the kernel tracks credentials
>> by uid. You'd need to determine some way to split that up so that each
>> "session" has separate credentials. Once you do that, you'll have to
>> have the kernel pass enough info to the upcall for it to determine what
>> credcache it should use and modify gssd to use the new info accordingly.
>
> Just to be clear - you mean doable to a coder who might like to improve on
> gssd/kernel credential separation, rather than a non-coding sysadmin who
> needs with work within the current NFS/gssd framework?
>



------------------------------------------------------------------------------
Come build with us! The BlackBerry(R) Developer Conference in SF, CA
is the only developer event you need to attend this year. Jumpstart your
developing skills, take BlackBerry mobile applications to market and stay 
ahead of the curve. Join us from November 9 - 12, 2009. Register now!
http://p.sf.net/sfu/devconference
_______________________________________________
NFS maillist  -  NFS@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/nfs
_______________________________________________
Please note that nfs@lists.sourceforge.net is being discontinued.
Please subscribe to linux-nfs@vger.kernel.org instead.
    http://vger.kernel.org/vger-lists.html#linux-nfs


      parent reply	other threads:[~2009-10-09 17:06 UTC|newest]

Thread overview: 20+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2009-10-09 15:15 [NFS] NFS/krb and batch jobs - doable? raini-9HxftnAiGddWk0Htik3J/w
     [not found] ` <c8e974302190b867ad8ea49d8158f1db.squirrel-2RFepEojUI30fF+2cCIZ11aTQe2KTcn/@public.gmane.org>
2009-10-09 16:16   ` Jeff Layton
     [not found]     ` <20091009121602.5ec86dfb-9yPaYZwiELC+kQycOl6kW4xkIHaj4LzF@public.gmane.org>
2009-10-09 16:53       ` raini-9HxftnAiGddWk0Htik3J/w
     [not found]         ` <1c358fde92c49215d84129a1bfe2c6ec.squirrel-2RFepEojUI30fF+2cCIZ11aTQe2KTcn/@public.gmane.org>
2009-10-10 13:00           ` Jeff Layton
     [not found]             ` <20091010090039.4dfd1dfb-9yPaYZwiELC+kQycOl6kW4xkIHaj4LzF@public.gmane.org>
2009-10-13 15:28               ` raini-9HxftnAiGddWk0Htik3J/w
     [not found]                 ` <ee56329e7d86a3e4b15001a39bb7e14a.squirrel-2RFepEojUI30fF+2cCIZ11aTQe2KTcn/@public.gmane.org>
2009-10-13 15:44                   ` Jeff Layton
     [not found]                     ` <20091013114441.2882c8b9-9yPaYZwiELC+kQycOl6kW4xkIHaj4LzF@public.gmane.org>
2009-10-13 15:51                       ` Kevin Coffman
2009-10-13 16:56                         ` Trond Myklebust
2009-10-13 17:27                           ` Jeff Layton
     [not found]                             ` <20091013132701.72927b4d-9yPaYZwiELC+kQycOl6kW4xkIHaj4LzF@public.gmane.org>
2009-10-13 17:51                               ` Trond Myklebust
2009-10-13 18:03                                 ` Jeff Layton
2009-10-14 16:47                                   ` raini
2009-10-14 17:12                                     ` Trond Myklebust
2009-10-14 18:19                                     ` Kevin Coffman
2009-10-13 15:59                     ` raini
2009-10-13 17:31                       ` Jeff Layton
2009-10-13 17:52                         ` Jeff Layton
2009-10-14 17:00                         ` raini
2009-10-14 17:21                           ` Jeff Layton
     [not found]     ` <f99e65f7b2fe66fc32dee931fd6bd525.squirrel@webmail.rainiday.com>
     [not found]       ` <f99e65f7b2fe66fc32dee931fd6bd525.squirrel-2RFepEojUI30fF+2cCIZ11aTQe2KTcn/@public.gmane.org>
2009-10-09 17:05         ` raini-9HxftnAiGddWk0Htik3J/w [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=9fc711a4c6b4682ba847cd51ca62f86d.squirrel@webmail.rainiday.com \
    --to=raini-9hxftnaigddwk0htik3j/w@public.gmane.org \
    --cc=nfs@lists.sourceforge.net \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox