Linux NFS development
 help / color / mirror / Atom feed
* Trouble with multiple kerberos ticket caches
@ 2025-05-02 17:29 Orion Poplawski
  2025-05-06 19:54 ` Orion Poplawski
  0 siblings, 1 reply; 8+ messages in thread
From: Orion Poplawski @ 2025-05-02 17:29 UTC (permalink / raw)
  To: linux-nfs@vger.kernel.org

[-- Attachment #1: Type: text/plain, Size: 1064 bytes --]

One of our users is struggling with multiple kerberos ticket caches impacting
access to NFS sec=krb5 mounts.

Because home directories are NFS mounted, we use GSSAPI auth to forward a
ticket.  But then we need to kinit to have a long-term renewable ticket.

But we seem to be seeing that new ssh connections which create a new ticket
cache break access to the NFS mounts, resulting in "permission denied" or
"Stale file handle" messages.  Switching back to a renewable ticket cache
seems to resolve the issue.

Any suggestions?  Is this expected?  I would have thought that the nfs access
would work with any valid ticket.

NAME="AlmaLinux"
VERSION="8.10 (Cerulean Leopard)"
nfs-utils-2.3.3-59.el8.x86_64
4.18.0-553.50.1.el8_10.x86_64

-- 
Orion Poplawski
he/him/his  - surely the least important thing about me
Manager of IT Systems                      720-772-5637
NWRA, Boulder Office                  FAX: 303-415-9702
3380 Mitchell Lane                       orion@nwra.com
Boulder, CO 80301                 https://www.nwra.com/


[-- Attachment #2: S/MIME Cryptographic Signature --]
[-- Type: application/pkcs7-signature, Size: 4087 bytes --]

^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2025-05-12 15:46 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2025-05-02 17:29 Trouble with multiple kerberos ticket caches Orion Poplawski
2025-05-06 19:54 ` Orion Poplawski
2025-05-07 16:57   ` Daniel Kobras
2025-05-07 17:39     ` Orion Poplawski
2025-05-09 13:21       ` Daniel Kobras
2025-05-09 19:55         ` Trouble with kerberos encryption types Orion Poplawski
2025-05-09 21:03           ` Orion Poplawski
2025-05-12 15:46             ` Daniel Kobras

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox