We would recommend opening an SR; NFS and Kerberos can be difficult to troubleshoot. It is entirely possible that you are hitting this bug, but best to contact support. Anything in log files that shows the write denial?
In "messages" we found this: 2015-04-10T10:19:42+02:00 <0.5> Easyone-1(id1) /boot/kernel.amd64/kernel: [svc_rpcsec_gss.c:842](pid 1274="nfsd")(tid=100174) Failed lookup for oleh@NFIT.AU.DK, error 2, returning unknown credentials.
oleh is the user and NFIT.AU.DK the Kerberos realm, which is correct - also the case.
mounting with sec=krb5 works, ls -l shows correct owner and group, but I can't access files and directories with no access for other. Files created are owned by nobody.
Is this issue is still unresolved in OpenFS 7.2.1.1?
mattashton1
93 Posts
1
March 2nd, 2015 11:00
Hi Henrik,
We would recommend opening an SR; NFS and Kerberos can be difficult to troubleshoot. It is entirely possible that you are hitting this bug, but best to contact support. Anything in log files that shows the write denial?
Cheers,
Matt
Henrik_Ravn
17 Posts
0
March 3rd, 2015 01:00
Hi Matt
Ok - made a SR to EMC this morning.
And nothing found in the log files (/var/log/nfs.log).
Regards
Henrik
Henrik_Ravn
17 Posts
0
April 10th, 2015 01:00
Not getting somewhere with the SR.
In "messages" we found this:
2015-04-10T10:19:42+02:00 <0.5> Easyone-1(id1) /boot/kernel.amd64/kernel: [svc_rpcsec_gss.c:842](pid 1274="nfsd")(tid=100174) Failed lookup for oleh@NFIT.AU.DK, error 2, returning unknown credentials.
oleh is the user and NFIT.AU.DK the Kerberos realm, which is correct - also the case.
saschafrey
5 Posts
0
January 10th, 2016 12:00
We're experiencing the same or a similar issue.
OneFS 7.2.1.1 with OpenLDAP server and MIT KDC:
mounting with sec=krb5 works, ls -l shows correct owner and group, but I can't access files and directories with no access for other. Files created are owned by nobody.
Is this issue is still unresolved in OpenFS 7.2.1.1?
saschafrey
5 Posts
0
January 11th, 2016 03:00
Thank you Julien,
This command did the trick. It's now working fine.