Re: [Hampshire] SECURE NFS ROOT ?

Top Page

Reply to this message
Author: Dr A. J. Trickett
Date:  
To: Stuart Sears
CC: Hants LUG
Subject: Re: [Hampshire] SECURE NFS ROOT ?
On Thu, 05 Mar 2009 at 10:49:59AM +0000, Stuart Sears wrote:
> Dr A. J. Trickett wrote:
> > On Wednesday 04 Mar 2009, Isaac Close wrote:
> >> --- On Wed, 4/3/09, Dr A. J. Trickett <adam.trickett@???> wrote:
> >>> On Wed, 04 Mar 2009 at 09:52:57AM
> > I've had no problem setting up NFSv4 on Debian Etch/Lenny/Squeeze, and I've
> > got Kerberos working fine too, however I've had no luck yet in getting NFSv4
> > to work with Kerberos... I'd be very interested if hearing how you get on.
>
> Which steps did you go through?
>
> IME it really depends on which principal versions you have extracted.
> (certainly on RHEL it does, anyway).
>
> I've had this working - but when you do your ktadd you need to only
> extract the des3-cbc-md5 version of the nfs principals for each of your
> clients and the server.


I can't remember what I did in the end, I tried lots of things an
non of them worked. I'll try again and let you know what I did and
found.

> You do have NFS and host principals for each machine, extracted on that
> machine, correct?
> nfs/host.name@REALM
> host/host.name@REALM


--
Adam Trickett
Overton, HANTS, UK

The Politician is an acrobat: he keeps his balance by saying
the opposite of what he does.
    -- Maurice Barres