Re: [Freeipa-users] Using Automount for NFS

2011-07-13 Thread Rob Crittenden

McDougall, Ryan P. [mcry0...@stcloudstate.edu] wrote:

Would anyone be able to give me an example of how to configure autofs
with the fstab, or tell me where I went wrong? I am having trouble
getting things to work. The main thing is that the permissions don’t
seem to be correct for the home directories that we are creating for
users, because when a user logs in, their home directory will be
created, but it will say permission denied when it will try to change
directory to it. The weird thing is then, they start in root, but then
they can change to their home directory then. Any help would be appreciated!

I attached sanitized versions of our configuration files.

Thanks,

Ryan McDougall


Maybe the SELinux context is not correct. Is the ownership otherwise ok? 
Can you look in /var/log/audit/audit.log on the client machine to see if 
an AVC is raised?


Also, can you see if you have the oddjob-mkhomedir package installed on 
the client?


thanks

rob

___
Freeipa-users mailing list
Freeipa-users@redhat.com
https://www.redhat.com/mailman/listinfo/freeipa-users


[Freeipa-users] Using Automount for NFS

2011-07-12 Thread McDougall, Ryan P. [mcry0...@stcloudstate.edu]
Would anyone be able to give me an example of how to configure autofs with the 
fstab, or tell me where I went wrong? I am having trouble getting things to 
work. The main thing is that the permissions don't seem to be correct for the 
home directories that we are creating for users, because when a user logs in, 
their home directory will be created, but it will say permission denied when it 
will try to change directory to it. The weird thing is then, they start in 
root, but then they can change to their home directory then. Any help would be 
appreciated!

I attached sanitized versions of our configuration files.

Thanks,

Ryan McDougall


#
# Define default options for autofs.
#
# MASTER_MAP_NAME - default map name for the master map.
#
#MASTER_MAP_NAME=auto.master
#
# TIMEOUT - set the default mount timeout (default 600).
#
TIMEOUT=300
#
# NEGATIVE_TIMEOUT - set the default negative timeout for
#failed mount attempts (default 60).
#
#NEGATIVE_TIMEOUT=60
#
# MOUNT_WAIT - time to wait for a response from umount(8).
#  Setting this timeout can cause problems when
#  mount would otherwise wait for a server that
#  is temporarily unavailable, such as when it's
#  restarting. The defailt of waiting for mount(8)
#  usually results in a wait of around 3 minutes.
#
#MOUNT_WAIT=-1
#
# UMOUNT_WAIT - time to wait for a response from umount(8).
#
#UMOUNT_WAIT=12
#
# BROWSE_MODE - maps are browsable by default.
#
BROWSE_MODE=no
#
# MOUNT_NFS_DEFAULT_PROTOCOL - specify the default protocol used by
#  mount.nfs(8). Since we can't identify
#  the default automatically we need to
#  set it in our configuration. This will
#  only make a difference for replicated
#  map entries as availability probing isn't
#  used for single host map entries.
#
#MOUNT_NFS_DEFAULT_PROTOCOL=3
MOUNT_NFS_DEFAULT_PROTOCOL=4
#
# APPEND_OPTIONS - append to global options instead of replace.
#
#APPEND_OPTIONS=yes
#
# LOGGING - set default log level none, verbose or debug
#
#LOGGING=none
#
# Define base dn for map dn lookup.
#
# Define server URIs
#
# LDAP_URI - space seperated list of server uris of the form
#proto://server[/] where proto can be ldap
#or ldaps. The option can be given multiple times.
#Map entries that include a server name override
#this option.
#
#This configuration option can also be used to
#request autofs lookup SRV RRs for a domain of
#the form proto:///[domain dn]. Note that a
#trailing / is not allowed when using this form.
#If the domain dn is not specified the dns domain
#name (if any) is used to construct the domain dn
#for the SRV RR lookup. The server list returned
#from an SRV RR lookup is refreshed according to
#the minimum ttl found in the SRV RR records or
#after one hour, whichever is less.
#


LDAP_URI=ldap://IPA Server


#
# LDAP__TIMEOUT - timeout value for the synchronous API  calls
# (default is LDAP library default).
#
#LDAP_TIMEOUT=-1
#
# LDAP_NETWORK_TIMEOUT - set the network response timeout (default 8).
#
#LDAP_NETWORK_TIMEOUT=8
#
# SEARCH_BASE - base dn to use for searching for map search dn.
#   Multiple entries can be given and they are checked
#   in the order they occur here.
#



SEARCH_BASE=ou=admins,ou=students,dc=DOMAIN,dc=OF,dc=IPA,dc=SERVER



#
# Define the LDAP schema to used for lookups
#
# If no schema is set autofs will check each of the schemas
# below in the order given to try and locate an appropriate
# basdn for lookups. If you want to minimize the number of
# queries to the server set the values here.
#
#MAP_OBJECT_CLASS=nisMap
#ENTRY_OBJECT_CLASS=nisObject
#MAP_ATTRIBUTE=nisMapName
#ENTRY_ATTRIBUTE=cn
#VALUE_ATTRIBUTE=nisMapEntry
#
# Other common LDAP nameing
#
#MAP_OBJECT_CLASS=automountMap
#ENTRY_OBJECT_CLASS=automount
#MAP_ATTRIBUTE=ou
#ENTRY_ATTRIBUTE=cn
#VALUE_ATTRIBUTE=automountInformation
#


MAP_OBJECT_CLASS=automountMap
ENTRY_OBJECT_CLASS=automount
MAP_ATTRIBUTE=automountMapName
ENTRY_ATTRIBUTE=automountKey
VALUE_ATTRIBUTE=automountInformation



#
# AUTH_CONF_FILE - set the default location for the SASL
#  authentication configuration file.
#
#AUTH_CONF_FILE=/etc/autofs_ldap_auth.conf
#
# MAP_HASH_TABLE_SIZE - set the map cache hash table size.
#   Should be a power of 2 with a ratio roughly
#   between 1:10 and 1:20 for each map.
#
#MAP_HASH_TABLE_SIZE=1024
#
# General global options
#
# If the kernel supports using the autofs miscellanous device
# and you wish to use it you must set this configuration option
# to yes otherwise it will not be used.