LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 03-05-2015, 04:26 PM   #1
afasoas
LQ Newbie
 
Registered: Oct 2012
Location: UK
Distribution: Ubuntu, Lubuntu
Posts: 16

Rep: Reputation: Disabled
NFS, Kerberos and VPN


Hi,

I hope posting this topic on this board is acceptable. I can see there are possibly two others in which it is also a logical fit.

In short, I have kerberised NFS shares which work fine on my local network. But over VPN it is a different matter.

The shares are hosted on Ubuntu Server 14.04.1 using NFS4. The Ubuntu Server is also the KRB5 KDC.

The clients have the following Kerberos Principals:
host/host.domain@KRB.REALM
etc.

When I'm connected direct to the network, hosts get their domain name via dhcp. Away from home and connected via VPN they don't and consequently Kinit fails with:

"kinit: Cannot determine realm for host (principal host/hostname@)".

I'm figuring I either need to tweak the kerberos configuration or change the way hosts get their FQDNs?

Any pointers would be appreciated.
Thanks
 
Old 03-06-2015, 05:32 PM   #2
dijetlo
Senior Member
 
Registered: Jan 2009
Location: RHELtopia....
Distribution: Solaris 11.2/Slackware/RHEL/
Posts: 1,491
Blog Entries: 2

Rep: Reputation: Disabled
As long as internal DNS is advertising your KDCs, (normally domain controllers) it shouldn't be a problem, they should pick up the DNS pointer at the gateway on their first service query.
You have to make sure they sync on the local NTP at the gateway or the KDC is not going to grant them TGTs (it wont even answer the request for a TGT and you get a similar error) because their timestamp and the KDCs' timestamp are separated by a value greater than the KDCs drift parameter. Or you could reset the KDCs drift parameter some ginormous number and hope for the best, but that kind of defeats the purpose of using Kerberos in the first place.
Check local time on one of the failing supplicants with the KDCs local time.

You can try locking them all into the same ntp.pool but that only works if the client remains in contact for it's intermittent syncs with the pool, as soon as it doesn't (somebody turns off their computers, for example) you'll have a repeat of the same issue until they do.

Last edited by dijetlo; 03-06-2015 at 05:35 PM.
 
1 members found this post helpful.
Old 03-09-2015, 08:25 AM   #3
afasoas
LQ Newbie
 
Registered: Oct 2012
Location: UK
Distribution: Ubuntu, Lubuntu
Posts: 16

Original Poster
Rep: Reputation: Disabled
Thank you for that dijetlo. That gives me a few pointers as to what/where the problem might be.
A
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
NFS 4 with kerberos mount by principal linuxmonster Linux - Security 2 04-20-2014 08:07 PM
Ubuntu Server - 10.04.03 - NFS export with Kerberos (MIT) - NFS Won't Start tekkon7 Linux - Server 2 11-07-2011 09:53 AM
NFS / Kerberos issue Akegata Linux - Server 2 06-10-2009 05:08 AM
nfs + kerberos linux 2 coglioni Linux - General 0 05-03-2007 03:36 AM
NFS and Kerberos schreiter Linux - Server 0 03-01-2007 06:53 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 02:21 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration