You are not logged in.
Hi all,
I am a freebsd user (sysadmin to be more precise) for the last 7 years, and I use archlinux in the client machines for the student-labs of the university department I work for (I am a relatively new user to arch-linux, but I have many years of experience with unix and other linux-distros). I have setup a solaris nfs4 server, and try to mount its share in my arch-linux clients using sec=krb5. nfs-utils and nfsidmap are installed in my clients as well as rpcbind.
# uname -a
Linux linuxclient.example.com 2.6.30-ARCH #1 SMP PREEMPT Fri Jul 31 18:10:38 UTC 2009 i686 Intel(R) Xeon(R) CPU E5310 @ 1.60GHz GenuineIntel GNU/Linux
I followed the article of nfs4 arch-wiki to prepare my clients, but whenever I try to mount the exported filesystem I get the following error:
# mount -tnfs4 -orw,sec=krb5 solaris.example.com:/export/homes /mnt
mount.nfs4: an incorrect mount option was specified
If I remove krb5 and place sys instead, it works fine. Nevertheless, this is not what I need, since I want nfs to be kerberized. My /etc/krb5.conf is ok, kinit works fine.
In /etc/rc.conf, I have:
DAEMONS=(syslog-ng network netfs crond sshd openntpd rpcbind nfs-common)
In /etc/conf.d/nfs-common.conf, I have:
NEED_IDMAPD="yes"
I would appreciate if someone could explain to me what I am doing wrong, since it seems that krb5 is not recognized by mount.nfs4 (as I said before, it works fine with sec=sys).
The exported filesystem is with sec=krb5, and I am able to mount it with my freebsd client.
Thank you all in advance.
Last edited by mamalos (2010-03-01 15:42:03)
Offline
I searched my logs, and in the /var/log/everything.log I found the lines:
Feb 25 19:17:05 linuxclient kernel: gss_create: Pseudoflavor 390003 not found!
Feb 25 19:17:05 linuxclient kernel: RPC: Couldn't create auth handle (flavor 390003)
which appear whenever I run the mount command.
I don't know if that helps, but... (I googled it quickly (very quickly), but found nothing useful)
Offline
More light on the issue:
I had to change my /etc/host in order for mount command to "resolve" my hostname "correctly" (as far as kerberos was concerned). To be more precise, when I ran gssd with more verbose output, I realized that gssd was trying to retrieve a key for nfs/localhost.localdomain from my kdc, instead of nfs/linuxclient.example.com. Hence I changed /etc/hosts to give this hostname first and it worked. (no unknown option error any more)
So, this time when I ran:
# mount -t nfs4 solaris.example.com:/export/homes /mnt -o sec=krb5
mount.nfs4: Broken pipeand rpc.gssd died. (ps axuw wouldn't show this process any more)
In /var/log/deamon.log I got:
Feb 26 19:33:26 linuxclient rpc.idmapd[2233]: New client: 12
Feb 26 19:33:26 linuxclient rpc.gssd[2241]: handling gssd upcall (/var/lib/nfs/rpc_pipefs/nfs/clnt12)
Feb 26 19:33:26 linuxclient rpc.gssd[2241]: handle_gssd_upcall: 'mech=krb5 uid=0 '
Feb 26 19:33:26 linuxclient rpc.gssd[2241]: handling krb5 upcall (/var/lib/nfs/rpc_pipefs/nfs/clnt12)
Feb 26 19:33:26 linuxclient rpc.gssd[2241]: process_krb5_upcall: service is '<null>'
Feb 26 19:33:26 linuxclient rpc.gssd[2241]: Full hostname for 'solaris.example.com' is 'solaris.example.com'
Feb 26 19:33:26 linuxclient rpc.gssd[2241]: Full hostname for 'linuxclient.example.com' is 'linuxclient.example.com'
Feb 26 19:33:26 linuxclient rpc.gssd[2241]: Failed to find root/linuxclient.example.com@EXAMPLE.COM in keytab FILE:/etc/krb5.keytab (null) while getting keytab entry for 'root/linuxclient.example.com@EXAMPLE.COM'
Feb 26 19:33:26 linuxclient rpc.gssd[2241]: Success getting keytab entry for 'nfs/linuxclient.example.com@EXAMPLE.COM'
Feb 26 19:33:26 linuxclient rpc.idmapd[2233]: New client: 13
Feb 26 19:33:26 linuxclient rpc.idmapd[2233]: Opened /var/lib/nfs/rpc_pipefs/nfs/clnt12/idmap
Feb 26 19:33:26 linuxclient rpc.gssd[2241]: Successfully obtained machine credentials for principal 'nfs/linuxclient.example.com@EXAMPLE.COM' stored in ccache 'FILE:/tmp/krb5cc_machine_EXAMPLE.COM'
Feb 26 19:33:26 linuxclient rpc.gssd[2241]: INFO: Credentials in CC 'FILE:/tmp/krb5cc_machine_EXAMPLE.COM' are good until 1267241606
Feb 26 19:33:26 linuxclient rpc.gssd[2241]: using FILE:/tmp/krb5cc_machine_EXAMPLE.COM as credentials cache for machine creds
Feb 26 19:33:26 linuxclient rpc.gssd[2241]: using gss_krb5_ccache_name to select krb5 ccache FILE:/tmp/krb5cc_machine_EXAMPLE.COM
Feb 26 19:33:26 linuxclient rpc.gssd[2241]: creating context using fsuid 0 (save_uid 0)
Feb 26 19:33:26 linuxclient rpc.gssd[2241]: creating tcp client for server solaris.example.com
Feb 26 19:33:26 linuxclient rpc.gssd[2241]: DEBUG: port already set to 2049
Feb 26 19:33:26 linuxclient rpc.gssd[2241]: creating context with server nfs@solaris.example.com
Feb 26 19:33:26 linuxclient rpc.idmapd[2233]: Stale client: 13
Feb 26 19:33:26 linuxclient rpc.idmapd[2233]: -> closed /var/lib/nfs/rpc_pipefs/nfs/clnt13/idmap
Feb 26 19:33:26 linuxclient rpc.idmapd[2233]: Stale client: 12
Feb 26 19:33:26 linuxclient rpc.idmapd[2233]: -> closed /var/lib/nfs/rpc_pipefs/nfs/clnt12/idmap
In order to restart nfs-common I had to pkill rpc.idmapd, and then execute /etc/rc.d/nfs-common start, otherwise it refused to start/restart.
More info about my configuration:
# ktutil list
FILE:/etc/krb5.keytab:
Vno Type Principal Aliases
1 des-cbc-md5 nfs/linuxclient.example.com@EXAMPLE.COM
1 des-cbc-md4 nfs/linuxclient.example.com@EXAMPLE.COM
1 des-cbc-crc nfs/linuxclient.example.com@EXAMPLE.COM
1 aes256-cts-hmac-sha1-96 nfs/linuxclient.example.com@EXAMPLE.COM
1 des3-cbc-sha1 nfs/linuxclient.example.com@EXAMPLE.COM
1 arcfour-hmac-md5 nfs/linuxclient.example.com@EXAMPLE.COM
# klist
Credentials cache: FILE:/tmp/krb5cc_0
Principal: mamalos@EXAMPLE.COM
Issued Expires Principal
Feb 26 19:19:00 Feb 27 05:19:00 krbtgt/EXAMPLE.COM@EXAMPLE.COM
# cat /etc/idmapd.conf:
[General]
Verbosity = 3
Pipefs-Directory = /var/lib/nfs/rpc_pipefs
Domain = example.com
[Mapping]
Nobody-User = nobody
Nobody-Group = nobody
[Translation]
Method = nsswitchsolaris exports its filesystem with:
# share -F nfs /export/homes -osec=krb5
# cat /etc/dfs/sharetab
/export/homes - nfs sec=krb5,rw
# ktutil
ktutil: rkt /etc/krb5/krb5.keytab
ktutil: l
slot KVNO Principal
---- ---- ---------------------------------------------------------------------
1 1 nfs/solaris.example.com@EXAMPLE.COM
2 1 nfs/solaris.example.com@EXAMPLE.COM
3 1 nfs/solaris.example.com@EXAMPLE.COM
4 1 nfs/solaris.example.com@EXAMPLE.COM
5 1 nfs/solaris.example.com@EXAMPLE.COM
6 1 nfs/solaris.example.com@EXAMPLE.COMAnybody help?
Offline
Guys?
any news? anybody an answer or a hint? I would be really grateful! ![]()
Offline
That's not very constructive but :
I have exactly the same problem.
My server run on gentoo and use MIT kerberos implementation.
My client is on archlinux and use Heimdal...
Offline
akira86,
I installed my nfs server on FreeBSD and changed my clients to Ubuntu, and now everything works. Archlinux was segfaulting with the same settings.
The function that was segfaulting had to do with MIT (?!?!). I think there must be some issue with the gss library (if I remember correctly) that contains MIT code despite the fact that all packages I installed were from Heimdal.
I didn't have time to look more into it, since now my configuration works.
Last edited by mamalos (2010-10-29 08:31:47)
Offline