Re: [Freeipa-users] krb5 nfs failure between F14 freeipa server and F14 client

2010-12-06 Thread Simo Sorce
On Sat, 04 Dec 2010 10:57:13 +0100 Thomas Sailer sai...@sailer.dynip.lugs.ch wrote: Hi, after upgrading a F12 freeipa server to F14, krb5 nfs no longer works. 1) ipa-getkeytab works only very unreliably. I get the following about 4 out of 5 times: # ipa-getkeytab -s 192.168.1.2 -p

Re: [Freeipa-users] krb5 nfs failure between F14 freeipa server and F14 client

2010-12-06 Thread Thomas Sailer
On Mon, 2010-12-06 at 10:55 -0500, Simo Sorce wrote: Hi Simo, thanks for your response! We are seeing an issue with F14 DS where it has been built against opneldap libraries while we still have plugins built against mozldap. Where would that help? just for the ipa-getkeytab reliability

Re: [Freeipa-users] krb5 nfs failure between F14 freeipa server and F14 client

2010-12-06 Thread Simo Sorce
On Mon, 06 Dec 2010 18:31:37 +0100 Thomas Sailer sai...@sailer.dynip.lugs.ch wrote: On Mon, 2010-12-06 at 10:55 -0500, Simo Sorce wrote: Hi Simo, thanks for your response! We are seeing an issue with F14 DS where it has been built against opneldap libraries while we still have

Re: [Freeipa-users] krb5 nfs failure between F14 freeipa server and F14 client

2010-12-06 Thread Thomas Sailer
On Mon, 2010-12-06 at 13:35 -0500, Simo Sorce wrote: Keys are stored in ldap and asn.1 encoding is generated using ldap libraries before storing it. If that operation fails it may generate malformed entries that the KDC later can't properly decode. Which patch are you talking about? Is it

Re: [Freeipa-users] krb5 nfs failure between F14 freeipa server and F14 client

2010-12-06 Thread Simo Sorce
On Mon, 06 Dec 2010 19:43:29 +0100 Thomas Sailer sai...@sailer.dynip.lugs.ch wrote: On Mon, 2010-12-06 at 13:35 -0500, Simo Sorce wrote: Keys are stored in ldap and asn.1 encoding is generated using ldap libraries before storing it. If that operation fails it may generate malformed