Linux NFS development
 help / color / mirror / Atom feed
* NFSv4 cross-realm support
@ 2014-07-02 17:42 Jaap Winius
  2014-07-07 12:36 ` Andy Adamson
  0 siblings, 1 reply; 5+ messages in thread
From: Jaap Winius @ 2014-07-02 17:42 UTC (permalink / raw)
  To: linux-nfs

Hi folks,

Recently I've been working on cross-realm support to give my own MIT 
Kerberos realm, UMRK.NL, access to the services of a realm that I manage. 
All systems involved run Debian wheezy. So far, SSH, OpenLDAP, OpenAFS 
and Dovecot IMAP are all working properly this way, but NFSv4 with 
sec=krb5i is not; I keep getting "Permission denied" when attempting to 
read or write to any file or directory that is not globally accessible.

When the log output verbosity for rpc.gssd and rpc.svcgssd is increased 
about as far as it will go (-vvvvv), little is different when things go 
wrong, other than this one line produced by rpc.svcgssd on the server:

  nss_gss_princ_to_ids: Local-Realm 'UMRK.NL': NOT FOUND

However, even that seems a bit misleading, because the log output for 
rpc.idmapd (with Verbosity = 5) shows that the user and group IDs for my 
account are being identified properly.

Should I prepare a bug report for this issue, or does cross-realm support 
for NFSv4 require something extra?

Thanks,

Jaap


^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2014-07-08  1:33 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2014-07-02 17:42 NFSv4 cross-realm support Jaap Winius
2014-07-07 12:36 ` Andy Adamson
2014-07-07 16:23   ` Jaap Winius
2014-07-07 21:24     ` Andy Adamson
2014-07-08  1:33       ` Jaap Winius

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox