2.2 Make it sure that ports 88 and 749 has opened at the firewall. Restart the firewall.
2.3 Create Kerberos Principals:

Execute kadmin command on the client console. Add the principal to the keytab file as follows for NFS :

Raw

[root@client ~]# kadmin
Authenticating as principal root/admin@EXAMPLE.COM with password.
Password for root/admin@EXAMPLE.COM:
kadmin: ktadd -e des-cbc-crc:normal nfs/client.example.com

Configuring kerberos for NFSv4 (Assuming that NFSv4 has been installed on the server), on the kerberos (i.e NFSv4) server :

3.1 Create the necessary entries in /etc/exports. First, create an NFSv4 mount point. I would suggest /export. Next bind the real path to the NFSv4 mount point. In this example, we want to export the /data directory. We create /export/data for NFSv4 and mount /data there.

Raw

[root@server /]# mkdir -m 1777 /export
[root@server /]# mkdir /export/data
[root@server /]# mount -n --bind /data /export/data

3.2 Add the following lines in the /etc/exports file :

Raw

/export      gss/krb5(sync,rw,fsid=0,insecure,no_subtree_check,anonuid=65534,anongid=65534)
/export/data gss/krb5(sync,rw,nohide,insecure,no_subtree_check,anonuid=65534,anongid=65534)

3.3 Modify /etc/idmapd.conf and it\\\’ll look like :

Raw

[root@server /]# cat /etc/idmapd.conf
[General]

Verbosity = 0
Pipefs-Directory = /var/lib/nfs/rpc_pipefs
Domain = example.com

[Mapping]

Nobody-User = nfsnobody
Nobody-Group = nfsnobody

[Translation]
Method = nsswitch

3.4 Make the value of SECURE_NFS to yes in /etc/sysconfig/nfs. To enable secure NFS, you must add the following line to /etc/sysconfig/nfs :

Raw

SECURE_NFS=yes

After the restart the NFS servers, the environment is able to work properly using Kerberos authentication and RPCSEC_GSS.

Testing :

On client machine issue the following command to mount the exporting directory of the server :

Raw

# mount -t nfs4 -o sec=krb5 server.example.com:/ /mnt/my_nfs_mount_point

Now create the files inside the /data directory on the server and view the files inside /mnt directory on the client machine.

Note : NFS daemons looks like on the server :

Raw

[root@server /]# service nfs status
rpc.svcgssd (pid 8974) is running...
rpc.mountd (pid 8994) is running...
nfsd (pid 8991 8990 8989 8988 8987 8986 8985 8984) is running...
rpc.rquotad (pid 8979) is running...

根源

By default NFS clients and servers use the AUTH_SYS protocol to authenticate users.
AUTH_SYS is defined in RPC v2 (http://www.ietf.org/rfc/rfc1831.txt) to allocate a 4 bit value to group memberships, hence the 16 groups limitation.
But since v4, NFS can use a different authentication protocol such as RPCSEC_GSS which supports more groups.

診斷步驟

The following considerations can help to debug problems with the above setup.

Are hosts properly resolved via DNS or /etc/hosts?

Are the expected principals in the keytab? This can be verified with klist -ke.

Are the required services running on client and server?

Have the services been restarted?

Are the required modules loaded? In some cases rpcsec_gss_krb5 was not loaded automatically on RHEL5.

Is showmount -e <server> from the client showing the exports?

It might be useful to configure rpc.gssd for more verbosity, set RPCGSSDARGS=-vvv in /etc/sysconfig/nfs and restart the service.

For nfs debugging execute echo 32767 > /proc/sys/sunrpc/nfs_debug.

更多關于云服務器域名注冊,虛擬主機的問題,請訪問三五互聯官網:m.shinetop.cn

贊(0)
聲明:本網站發(fā)布的內容(圖片、視頻和文字)以原創(chuàng)、轉載和分享網絡內容為主,如果涉及侵權請盡快告知,我們將會在第一時間刪除。文章觀點不代表本網站立場,如需處理請聯系客服。郵箱:3140448839@qq.com。本站原創(chuàng)內容未經允許不得轉載,或轉載時需注明出處:三五互聯知識庫 » 【LINUX】怎樣配置 NFSv4 with kerberos 自動認證

登錄

找回密碼

注冊

主站蜘蛛池模板: 中文字幕av无码免费一区| 亚洲人成色99999在线观看| 欧美精品一产区二产区| 日本黄色三级一区二区三区| 免费黄色大全一区二区三区| 人人做人人澡人人人爽| 国产成人精品无码片区在线观看| 国产不卡一区二区三区视频 | 污网站在线观看视频| 99久久无色码中文字幕| 熟女蜜臀av麻豆一区二区| 国产婷婷精品av在线| 国产日韩精品欧美一区灰 | 欧美xxxx做受欧美.88| 亚洲欧美日韩愉拍自拍美利坚| 湾仔区| 清纯唯美经典一区二区| 国产精品自在线拍国产手青青机版| 亚洲国产精品成人无码区| 国产亚洲精品中文字幕| 日韩精品亚洲国产成人av| 精品无码一区在线观看| 亚洲av永久无码精品天堂久久| 自拍亚洲综合在线精品| 秋霞鲁丝片av无码少妇| 美女一区二区三区亚洲麻豆| 亚洲欧洲日韩精品在线| 99久久亚洲精品无码毛片| 国产女人18毛片水真多1| 久久精品国产福利一区二区| 国产精品久线在线观看| 激情综合网五月婷婷| 亚洲性线免费观看视频成熟| 激情综合网激情五月我去也| 放荡的少妇2欧美版| 蜜臀av一区二区精品字幕| 国产精品免费看久久久| 国产成人AV国语在线观看| 国产成人高清在线重口视频| 中文字幕在线日韩一区| 亚洲中文字幕av天堂|