LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Go Back   LinuxQuestions.org > Forums > Enterprise Linux Forums > Linux - Enterprise
User Name
Password
Linux - Enterprise This forum is for all items relating to using Linux in the Enterprise.

Notices


Reply
  Search this Thread
Old 05-19-2016, 01:24 PM   #1
jdelaporte
LQ Newbie
 
Registered: Jun 2014
Posts: 8

Rep: Reputation: Disabled
Should I combine or separate IdM/FreeIPA and NFS file server?


I am migrating my domain off of NIS/NFS to FreeIPA/NFS or FreeIPA/SMB, if I can figure out how to make that work.

Should my IPA authentication server also be my file server, or should it be separate? There are strange sudoer trusts required to create home directories on a remote server in an IPA/IdM domain.

I add hundreds of users with a tight turnaround every 2-3 months, so I need something that works consistently without a lot of interaction.
 
Old 06-09-2016, 03:01 PM   #2
tshikose
Member
 
Registered: Apr 2010
Location: Kinshasa, Democratic Republic of Congo
Distribution: RHEL, Fedora, CentOS
Posts: 525

Rep: Reputation: 95
Hi,

You do not need to have separate servers.
To my knowledge, you do not need "strange sudoer trusts" to create home directories on a the remote servers. You can configure you server so home directory get created at user creation.

Regards,

Last edited by tshikose; 06-10-2016 at 01:00 AM. Reason: typo
 
Old 06-09-2016, 11:49 PM   #3
jdelaporte
LQ Newbie
 
Registered: Jun 2014
Posts: 8

Original Poster
Rep: Reputation: Disabled
NFS, autofs, and kerberos principals

Okay, so I have an IPA realm set up, using external DNS. I built an NFS server, joined it to the realm, and added the nfs service principle and keytab to the IPA server. I created the exports file and configured my firewall for NFS. I set up automount maps on the IPA server (the maps are in /etc/auto.master and auto.direct, and the automap "keys" have been added to IPA realm).

I am having trouble with the IPA server not mounting the exports from the NFS server...it mounts the root export with the mount command, but not the additional exports below the root. When I use the 'mount' command from the IPA server, the NFS server log says that it authenticated a request to mount, but the IPA server says it was denied access. I am trying to use NFSv4 with krp5p (preferably). I got sec=sys running for a while, but then that stopped working while I was trying to get the kerberos realm authentication working. I haven't gotten automount maps working across the net yet (although I did get autofs working on the NFS server itself).

Do I need to have IPA realm users added before I can (auto)mount NFS shares? I do not have any IPA users configured yet beside the default admin. How do I (auto)mount a share using a kerberos ticket rather than just as root user?

Do I need to have HBAC rules or service principals added for clients of services? Do I need a service principal keytab on every NFS client machine?

Do I need to have HBAC rules or service principals added for users, so they can access NFSv4 shares (krb5*) mounted with autofs?

Pardon me if some of these questions seem clueless. This is my first deep dive into the IPA/IdM realm...it'll click eventually.
 
  


Reply

Tags
nfs mount network, smb


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Generate certificate for vCenter on FreeIPA server javid.alizade Linux - Virtualization and Cloud 1 11-04-2015 11:24 AM
Configure red hat 7 server idm without a replica server erj Linux - Security 1 11-11-2014 01:50 AM
Freeipa server configuration fails during settingup CA / pki pix9 Linux - Server 2 06-04-2014 12:14 AM
Freeipa vs Samba4 : will Redhat dump freeipa in favor of Samba4? exodius Linux - Enterprise 1 12-16-2013 02:16 AM

LinuxQuestions.org > Forums > Enterprise Linux Forums > Linux - Enterprise

All times are GMT -5. The time now is 12:23 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration