LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 10-23-2010, 02:00 AM   #1
LMW
Member
 
Registered: Oct 2010
Location: Russia / USA
Distribution: Arch Linux
Posts: 36

Rep: Reputation: 2
Using Active Directory as KDC for NFSv4


Greetings!

I have AD DS installed on Windows Server 2008 R2. Also, I've got SLES 10.3 as NFSv4 server, which will allow remote users to mount their /home partitions. What I need, is NFSv4 w/Kerberos. As AD server already has integrated Kerberos server, I need SLES to authenticate in it.
Everything works good, but when it comes to svcgssd service activation, I receive an error.

Here's the log:

/usr/sbin/rpc.svcgssd -f
ERROR: GSS-API: error in gss_acquire_cred(): Miscellaneous failure - No principal in keytab matches desired name
unable to obtain root (machine) credentials
do you have a keytab entry for nfs/<your.host>@<YOUR.REALM> in /etc/krb5.keytab?

Earlier, I've created proper (well, I think it's a proper one) keytab. AD user was created and then, on Windows server, following ktpass command was executed:
ktpass -princ nfs/hostname.domain.com@DOMAIN.COM -mapuser DOMAIN\username -pass xxxxxxx -ptype KRB5_NT_PRINCIPAL -out krb5.keytab

Then, the resulting krb5.keytab file was put on SLES server, but still I receive the same error.

That's what "klist -k /etc/krb5.keytab" shows:
Keytab name: FILE:/etc/krb5.keytab KVNO Principal
------------ 8 nfs/ip-10-243-1-2.domain.com@DOMAIN.COM

Domain name was changed due to security measures =) But it appears to be right.

What can cause such problem?

Thank you.
 
Old 10-23-2010, 10:04 PM   #2
LMW
Member
 
Registered: Oct 2010
Location: Russia / USA
Distribution: Arch Linux
Posts: 36

Original Poster
Rep: Reputation: 2
What if hostname -fqdn show hostname.ec2.internal? That VPS in located in Amazon EC2. Modifying keytab that way: "ktpass -princ nfs/ip-10-243-1.ec2.internal@DOMAIN.COM -mapuser DOMAIN\nfs10 -pass XXXXXX -ptype KRB5_NT_PRINCIPAL -out krb5.keytab" didn't held though. Maybe I should modify /etc/krb5.conf somehow, but I don't have any ideas.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Username & Password Sync Fedora Directory and Microsoft Active Directory karnac01 Fedora 4 07-19-2010 12:51 AM
Active Directoy Kerberos migration into Linux KDC satish.lx Linux - Server 2 08-01-2009 06:31 PM
Slackware 12 NFSv4 directory error onebuck Slackware 0 07-09-2007 08:44 AM
Fedora Directory Server sync Active Directory paul_mat Linux - Networking 8 03-08-2007 10:51 AM
Active Directory User Cannot Write to Samba Home Directory jonwatson Linux - Networking 2 12-19-2006 12:40 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 12:03 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration