From owner-freebsd-hackers@freebsd.org Mon Nov 16 15:57:15 2015 Return-Path: Delivered-To: freebsd-hackers@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 491E3A30376 for ; Mon, 16 Nov 2015 15:57:15 +0000 (UTC) (envelope-from slw@zxy.spb.ru) Received: from mailman.ysv.freebsd.org (mailman.ysv.freebsd.org [IPv6:2001:1900:2254:206a::50:5]) by mx1.freebsd.org (Postfix) with ESMTP id 30FCC128F for ; Mon, 16 Nov 2015 15:57:15 +0000 (UTC) (envelope-from slw@zxy.spb.ru) Received: by mailman.ysv.freebsd.org (Postfix) id 2CA69A30374; Mon, 16 Nov 2015 15:57:15 +0000 (UTC) Delivered-To: hackers@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 1240EA30370 for ; Mon, 16 Nov 2015 15:57:15 +0000 (UTC) (envelope-from slw@zxy.spb.ru) Received: from zxy.spb.ru (zxy.spb.ru [195.70.199.98]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id BE486128E for ; Mon, 16 Nov 2015 15:57:14 +0000 (UTC) (envelope-from slw@zxy.spb.ru) Received: from slw by zxy.spb.ru with local (Exim 4.86 (FreeBSD)) (envelope-from ) id 1ZyM9X-000IKm-2v; Mon, 16 Nov 2015 18:57:11 +0300 Date: Mon, 16 Nov 2015 18:57:11 +0300 From: Slawa Olhovchenkov To: Rick Macklem Cc: hackers@freebsd.org Subject: Re: NFSv4 details and documentations Message-ID: <20151116155710.GB31314@zxy.spb.ru> References: <9BC3EFA2-945F-4C86-89F6-778873B58469@cs.huji.ac.il> <20151115152635.GB5854@kib.kiev.ua> <3AEC67FD-2E67-4EF9-9D46-818ABF3D8118@cs.huji.ac.il> <661673285.88370232.1447682409478.JavaMail.zimbra@uoguelph.ca> <20151116141433.GA31314@zxy.spb.ru> <1489367909.88538127.1447688459383.JavaMail.zimbra@uoguelph.ca> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <1489367909.88538127.1447688459383.JavaMail.zimbra@uoguelph.ca> User-Agent: Mutt/1.5.24 (2015-08-30) X-SA-Exim-Connect-IP: X-SA-Exim-Mail-From: slw@zxy.spb.ru X-SA-Exim-Scanned: No (on zxy.spb.ru); SAEximRunCond expanded to false X-BeenThere: freebsd-hackers@freebsd.org X-Mailman-Version: 2.1.20 Precedence: list List-Id: Technical Discussions relating to FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 16 Nov 2015 15:57:15 -0000 On Mon, Nov 16, 2015 at 10:40:59AM -0500, Rick Macklem wrote: > Slawa Olhovchenkov wrote: > > On Mon, Nov 16, 2015 at 09:00:09AM -0500, Rick Macklem wrote: > > > > > There is a vfs operation called VFS_SYSCTL(). This isn't implemented on > > > the current NFS client. It was implemented on the old one, but only for > > > NFS locking events and I didn't understand what needed to be done, so I > > > didn't do it. > > > > Rick, I am try to play with NFSv4 and Kerberos and see lack of > > documentation. For example, nowhere documented that access to NFSv4 > > mount do by NFSv3 rules. I.e. I need have /etc/exports with TWO lines: > > > > V4: /NFS -sec=krb5i > > /NFS -sec=krb5i > > > > W/o second lines I got 10020 error (for NFSv4 mount). > > > Well, "man exports" does try and say this (and I've reworded it several times), > but it is confusing. In simple terms, the "V4:" line does not export any file system > and needs to be added to whatever you export via other lines. As I read this: adding '/NFS 127.0.0.1' is enough and secured. But this is wrong: not only exported, access control too. May be for NFS guru this is trivia, but for ordinary users this is confused. > > What current status Kerberos support in NFS client/server? I found > > many posts and wiki pages about lack some functionality, but also see > > many works from you. > > > The main limitation (which comes from the fact that the RPCSEC_GSS implementation > is version 1) is that it expects to use DES, which requires "weak authentication" > to be enabled. Although parts about adding patches for initiator credentials no longer > applies, this is still fairly useful. Hmm, I am have setup Kerberized NFS w/o "weak authentication" to be enabled, with mounted as 'nfsv4,intr,soft,sec=krb5i,allgssname,gssname=root'. What is requred DES in RPCSEC_GSS? (for me as user, how I can see what broken? some commands don't working or something else?) > https://code.google.com/p/macnfsv4/wiki/FreeBSD8KerberizedNFSSetup Yes, I am talk about this. > Anyone willing to improve/update this is more than welcome to do so. (I, personally, > haven't set up a Kerberized NFS for a couple of years and I hate fiddling with it. > When something isn't working, isolating the problem can be very difficult.) Yes, I am already see it. > Good luck with it, rick > ps: I put it on google as a wiki so anyone could update it, but I don't think > anyone ever has. As I recall, anyone with a google login can update it. > > > Can you give some examples for kerberoized setup, with support cron > > jobs? > > _______________________________________________ > > freebsd-hackers@freebsd.org mailing list > > https://lists.freebsd.org/mailman/listinfo/freebsd-hackers > > To unsubscribe, send any mail to "freebsd-hackers-unsubscribe@freebsd.org" > >