LinuxQuestions.org
Help answer threads with 0 replies.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 01-21-2019, 09:14 AM   #1
QuantumSmeggingCheese
LQ Newbie
 
Registered: Mar 2018
Posts: 3

Rep: Reputation: Disabled
root kerberos ticket expires and causes issues at user logon


Hi all,

I have a number of Centos (6.x) servers running in a SLURM (current ver) cluster.
I have joined the centos boxes to an Windows domain via sssd and enabled AD logins and that all works great
Next i used the 'krb5' and 'multiuser' mount option to mount the users home dir on a remote (windows) file server. again, great.

The users folders get created at 1st logon, and the only persistent error is the .XAuthority file won't create 1st login, but does 2nd - i'm guessing something is happening in the wrong order. no big.

But. The Big issue, is that mount line is in fstab,
Hi, I have a number of Centos (6.x) servers running in a SLURM (current ver) cluster.
I have joined the centos boxes to an Windows domain via sssd and enabled AD logins and that all works great
Next i used the krb mount option to mount the users home dir on a remote (windows) file server. again, great.

The users folders get created at 1st logon, and the only persistent error is the .XAuthority file won't create 1st login, but does 2nd - i'm guessing something is happening in the wrong order.

But. The Big issue, is that mount line is in fstab, Hi, I have a number of Centos (6.x) servers running in a SLURM (current ver) cluster.
I have joined the centos boxes to an Windows domain via sssd and enabled AD logins and that all works great
Next i used the krb mount option to mount the users home dir on a remote (windows) file server. again, great.

The users folders get created at 1st logon, and the only persistent error is the .XAuthority file won't create 1st login, but does 2nd - i'm guessing something is happening in the wrong order.

But. The Big issue, is that mount line is in fstab,
Code:
\\FQDN\homes /mnt/homes  cifs multiuser,suid,rw,user,exec,sec=krb5,cluid=$USER 0 0
This works and the user has all the correct permissions, and the dir gets created etc. But.... Only if root's kerberos ticket is still valid.

I can 100% repeat this issue an if i hop on the box and su and kinit the ticket is created and users logon without error. if the ticket has expired, the process that creates the home folder, errors out. as it (presumably running as root) can't access the mount point.


The only think i can think of is some kind of self replenishing kerberos ticket, but that is clearly security madness?

Its taken a ton of googling to get it this far! but now the info has dried up and i'm now well up a certain creek!

Hopefully someone here has the words of wisdom google is hiding from me.
 
Old 01-21-2019, 11:51 PM   #2
/dev/random
Member
 
Registered: Aug 2012
Location: Ontario, Canada
Distribution: Slackware 14.2, LFS-current, NetBSD 6.1.3, OpenIndiana
Posts: 319

Rep: Reputation: 112Reputation: 112
Why not just kinit in Cron for root? Just make sure no one can access the ticket.
 
Old 01-22-2019, 05:56 AM   #3
QuantumSmeggingCheese
LQ Newbie
 
Registered: Mar 2018
Posts: 3

Original Poster
Rep: Reputation: Disabled
sorry if i'm missing the point here, but won't kinit wrapped in cron just renew not re-issue the ticked until its maximum renew-time has expired ie 7 days?
i'm not familiar with how i get root's password safely into a cron job, some sort of creds file presumably, thats why i was asking here!

TA
 
Old 01-23-2019, 04:37 AM   #4
QuantumSmeggingCheese
LQ Newbie
 
Registered: Mar 2018
Posts: 3

Original Poster
Rep: Reputation: Disabled
*UPDATE*

This may well be not a problem after all...

I was simulating the windows {file}server using a virtualbox VM, which as it was running on my laptop, got turned off at the end of the day.....(where is the foot-in-mouth emoji on here??)

looks like it a case of "if the server is on, the ticket gets renewed" Doh.

Thanks to all that looked at this and thought about it.

Cheers.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
NFSv4 and Kerberos with user's ticket. arizonagroovejet Linux - General 1 11-11-2013 05:01 AM
Automounting Windows Share using user's kerberos ticket 0ddba11 Linux - Server 18 01-12-2011 09:33 AM
pam_krb5 won't retrieve a kerberos ticket Thakowbbery Conectiva 1 01-10-2007 05:20 AM
Mounting network shares using kerberos ticket dlbuhl Linux - Networking 0 12-19-2006 10:53 AM
Samba Kerberos Ticket sindri Linux - Software 0 11-24-2004 01:10 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 08:58 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration