我有 nfsserver 和 nfsclient 机器。
在 nfsserver 上:
# cat /etc/exports
/export gss/krb5p(rw,sync,fsid=0,no_subtree_check,crossmnt)
/export/home gss/krb5p(rw,sync,no_subtree_check)
在 nfsclient 上它安装成功:
# mount -vvv -t nfs4 -o sec=krb5p nfsserver:/home /homex
mount: fstab path: "/etc/fstab"
mount: mtab path: "/etc/mtab"
mount: lock path: "/etc/mtab~"
mount: temp path: "/etc/mtab.tmp"
mount: UID: 0
mount: eUID: 0
mount: spec: "nfsserver:/home"
mount: node: "/homex"
mount: types: "nfs4"
mount: opts: "sec=krb5p"
mount: external mount: argv[0] = "/sbin/mount.nfs4"
mount: external mount: argv[1] = "nfsserver:/home"
mount: external mount: argv[2] = "/homex"
mount: external mount: argv[3] = "-v"
mount: external mount: argv[4] = "-o"
mount: external mount: argv[5] = "rw,sec=krb5p"
mount.nfs4: timeout set for Tue Apr 30 13:03:13 2013
mount.nfs4: trying text-based options 'sec=krb5p,addr=10.10.10.100,clientaddr=10.10.10.101'
nfsserver:/home on /homex type nfs4 (rw,sec=krb5p)
但我只能以 root 身份访问此目录。普通用户可获得:
$ ls /homex
ls: cannot access /homex: Permission denied
$ df /homex
df: `/homex': Permission denied
df: no file systems processed
我打开了两端(nfsserver、nfsclient)的所有 NFS 调试,但当rpcdebug
普通用户尝试访问已挂载的目录时,我在 nfsclient 上看到的唯一内容是:
Apr 30 12:51:19 nfsclient kernel: [ 5896.339330] NFS: permission(0:13/917551), mask=0x24, res=-13
Apr 30 12:51:32 nfsclient kernel: [ 5909.182185] NFS: revalidating (0:13/917551)
Apr 30 12:51:32 nfsclient kernel: [ 5909.189372] nfs_revalidate_inode: (0:13/917551) getattr failed, error=-13
那么 nfsserver 端就什么都没有了(甚至用 tcpdump 嗅探时也没有网络流量)。
文件权限似乎没有问题:
# ls -ld /homex
drwxr-xr-x 3 root root 4096 Apr 5 18:15 /homex
# ls -l /homex
total 4
drwxr-xr-x 6 mike mike 4096 Apr 29 13:48 mike
# df /homex
Filesystem 1K-blocks Used Available Use% Mounted on
nfsserver:/home
20640384 1390208 18201600 8% /homex
用户 mike 在两台机器上具有相同的 UID。
答案1
Kerberized NFS(任何)都需要 Kerberos 票证。如果您希望用户能够在没有票证的情况下访问 NFS,则gss
必须使用安全性较低的安全级别。sys
让用户在登录时获取票证会更好。可以使用sssd
或pam_krb5
作为身份验证堆栈的一部分pam
,也可以通过凭证委托ssh
(即GSSAPIAuthentication yes
和GSSAPIDelegateCredentials
)。
答案2
因此用户在获取 Kerberos 票证后即可访问 NFS 挂载kinit
。