All of lore.kernel.org
 help / color / mirror / Atom feed
* RFC rpc.gssd enhancement
@ 2016-11-28 18:37 Lukas Hejtmanek
  2016-11-29 18:37 ` Steve Dickson
  2016-11-29 20:04 ` Olga Kornievskaia
  0 siblings, 2 replies; 18+ messages in thread
From: Lukas Hejtmanek @ 2016-11-28 18:37 UTC (permalink / raw)
  To: linux-nfs

Hello,

would it be acceptable to add an option for rpc.gssd to use host keytab if
user's kerberos ticket is not available?

Consider the following scenario:
1) machine has NFS mounted /home using kerberos authentication
2) user logs in, sshd creates krb ticket ($HOME/.k5login needs to be world
readable to allow kerberized access, e.g., using kerberos ticket)
3) user stays logged in and krb ticket expires
4) kinit to renew ticket produces strange error because $HOME is not
accessible and a new ticket is not created.

So, I think in this case, I would like to see rpc.gssd uses host keytab while
user's ticket is not available, which maps to nobody/nogroup, but kinit should
succeed. 

Or are there any other options if one is using kerberized homes only?

-- 
Lukáš Hejtmánek

^ permalink raw reply	[flat|nested] 18+ messages in thread

end of thread, other threads:[~2016-12-08 21:58 UTC | newest]

Thread overview: 18+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2016-11-28 18:37 RFC rpc.gssd enhancement Lukas Hejtmanek
2016-11-29 18:37 ` Steve Dickson
2016-11-29 18:48   ` Lukas Hejtmanek
2016-11-29 19:28     ` Steve Dickson
2016-12-02 11:41       ` Lukas Hejtmanek
     [not found]         ` <CAHVgHyU6LQak3O4ybR0H3whWCKUdfz2bxLvEGi9uFM1EX+e=Eg@mail.gmail.com>
2016-12-02 14:00           ` Fwd: " Andy Adamson
     [not found]           ` <20161202134638.4ghyb5wnnwata4ec@ics.muni.cz>
2016-12-02 14:23             ` Andy Adamson
2016-12-02 14:28               ` Lukas Hejtmanek
2016-12-02 15:09                 ` Andy Adamson
2016-12-08 12:36                   ` Lukas Hejtmanek
2016-12-08 13:18                     ` Andy Adamson
2016-12-08 13:23                       ` Lukas Hejtmanek
2016-12-08 13:40                         ` Andy Adamson
2016-12-08 21:11                     ` Olga Kornievskaia
2016-12-08 21:22                       ` Lukas Hejtmanek
2016-12-08 21:50                         ` Olga Kornievskaia
2016-12-08 21:58                           ` Olga Kornievskaia
2016-11-29 20:04 ` Olga Kornievskaia

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.