Re: [Freeipa-users] IPA and NFSv4 with krb5 security

2016-07-01 Thread Joanna Delaporte
Which services actually need to be running for Kerberized NFS? On the server and client sides? What needs to be enabled? When I go through the list in the RHEL 7 Domain Auth guide (p 271), I cannot get rpcsvcgssd.service to start. It doesn't give any errors when I send it a start command, but

Re: [Freeipa-users] IPA and NFSv4 with krb5 security

2016-06-30 Thread Youenn PIOLET
Hi, First questions (sorry if it's obvious): - Do you have a valid token on the client? (obtained with kinit) - Did you import the keytab for NFS service on the server? - Did you put "domain = yourdomain.tld" in your NFS server config file? On your client? - Depending on your (ipa? nfs?) version

[Freeipa-users] IPA and NFSv4 with krb5 security

2016-06-30 Thread Joanna Delaporte
I need some pointers for getting NFSv4 to use krb5 authorization in my IPA realm. My realm is new. I have just migrated some users from an NIS domain to the IPA realm. The numerical UIDs and GIDs do not all match. I set up NFS server and client, and automaps using the recommended methods in the