LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-24-2012, 05:01 PM   #1
BASHCuresCancer
LQ Newbie
 
Registered: Jan 2008
Posts: 19

Rep: Reputation: 0
NFS4 + Kerberos: how does server know username


As far as I can tell, to mount a NFS4 mount with kerberos, the only thing that is needed is one principal:

nfs/HOSTNAME@REALM

How does the NFS server know the username/uid of the individual users? The AUTH_SYSTEM mechanism of NFS passes the uid on the request to the NFS server.
 
Old 10-25-2012, 06:44 AM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
the user session will already have a kerberos ticket, so that is passed to the server.
 
Old 10-26-2012, 04:27 AM   #3
mikey99
Member
 
Registered: Nov 2008
Location: UK
Distribution: RHEL, Fedora
Posts: 68

Rep: Reputation: 12
...plus, you will not be using AUTH_SYS for kerberos authentication. You will be using RPCSEC_GSS
instead, forcing the clients to mount using the sec=krb5 mount option.

Mike.
 
Old 10-26-2012, 09:25 AM   #4
BASHCuresCancer
LQ Newbie
 
Registered: Jan 2008
Posts: 19

Original Poster
Rep: Reputation: 0
I agree that the users ticket will be passed to the server. How does the server then find the principal name? via the kerberos server? In wireshark I don't see the principal name with the ticket.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Problems with nfs4 + kerberos camerabambai Slackware 1 02-05-2012 06:17 AM
ssh and kerberos error: Server not found in Kerberos database Felipe Linux - Server 1 01-17-2011 03:12 AM
nfs4 - mount.nfs4: access denied by server while mounting edwin11 Linux - Networking 1 12-07-2010 10:06 AM
Can't mount nfs4 directories with Kerberos auth on CentOS 5 pinkunicorn Linux - General 0 10-19-2010 09:55 AM
NFS4 & Kerberos: All Files/Directories Owned by nobody:nogroup ... sancho Linux - Networking 1 12-19-2007 12:55 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:22 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration