Re: [Freeipa-users] apache kerberized nfs4 /var/www/html access denied for apache user

2014-09-22 Thread Dmitri Pal
On 09/20/2014 05:19 PM, Simo Sorce wrote: On Sat, 20 Sep 2014 19:44:28 +0200 Rob Verduijn rob.verdu...@gmail.com wrote: Hi again, Thank you for the quick response. I've removed the credstore entries that are not necessary for the nfs access. Now the users no longer go through gssproxy, but

Re: [Freeipa-users] apache kerberized nfs4 /var/www/html access denied for apache user

2014-09-22 Thread Simo Sorce
On Mon, 22 Sep 2014 15:09:42 -0400 Dmitri Pal d...@redhat.com wrote: On 09/20/2014 05:19 PM, Simo Sorce wrote: On Sat, 20 Sep 2014 19:44:28 +0200 Rob Verduijn rob.verdu...@gmail.com wrote: Hi again, Thank you for the quick response. I've removed the credstore entries that are not

Re: [Freeipa-users] apache kerberized nfs4 /var/www/html access denied for apache user

2014-09-20 Thread Rob Verduijn
Hello all, I've managed to get the gssproxy to work on my installation. I can now mount my apache document root using sec=krb5p and apache automagically mounts the share when needed. However I noticed that now all nfs credentials are going through gssproxy. Is there a way to disable this for

Re: [Freeipa-users] apache kerberized nfs4 /var/www/html access denied for apache user

2014-09-20 Thread Simo Sorce
On Sat, 20 Sep 2014 16:53:48 +0200 Rob Verduijn rob.verdu...@gmail.com wrote: Hello all, I've managed to get the gssproxy to work on my installation. I can now mount my apache document root using sec=krb5p and apache automagically mounts the share when needed. However I noticed that now

Re: [Freeipa-users] apache kerberized nfs4 /var/www/html access denied for apache user

2014-09-20 Thread Anthony Messina
On Saturday, September 20, 2014 12:15:04 PM Simo Sorce wrote: [service/nfs-client] mechs = krb5 cred_store = keytab:/etc/krb5.keytab cred_store = ccache:FILE:/var/lib/gssproxy/clients/krb5cc_%U cred_store = client_keytab:/etc/gssproxy/%U.keytab cred_usage = initiate

Re: [Freeipa-users] apache kerberized nfs4 /var/www/html access denied for apache user

2014-09-20 Thread Rob Verduijn
Hi again, Thank you for the quick response. I've removed the credstore entries that are not necessary for the nfs access. Now the users no longer go through gssproxy, but apache does. I've googled around quite a bit and and it seems that your presentation on youtube and the gssproxy page

Re: [Freeipa-users] apache kerberized nfs4 /var/www/html access denied for apache user

2014-09-20 Thread Simo Sorce
On Sat, 20 Sep 2014 11:38:16 -0500 Anthony Messina amess...@messinet.com wrote: On Saturday, September 20, 2014 12:15:04 PM Simo Sorce wrote: [service/nfs-client] mechs = krb5 cred_store = keytab:/etc/krb5.keytab cred_store = ccache:FILE:/var/lib/gssproxy/clients/krb5cc_%U

Re: [Freeipa-users] apache kerberized nfs4 /var/www/html access denied for apache user

2014-09-20 Thread Simo Sorce
On Sat, 20 Sep 2014 19:44:28 +0200 Rob Verduijn rob.verdu...@gmail.com wrote: Hi again, Thank you for the quick response. I've removed the credstore entries that are not necessary for the nfs access. Now the users no longer go through gssproxy, but apache does. I've googled around quite

Re: [Freeipa-users] apache kerberized nfs4 /var/www/html access denied for apache user

2014-09-17 Thread Rob Verduijn
2014-09-16 20:57 GMT+02:00 Nordgren, Bryce L -FS bnordg...@fs.fed.us: Also opened https://fedorahosted.org/freeipa/ticket/4544 Tried to summarize this thread on that ticket. Back to the OP's concern, whenever I use NFS as a documentroot for apache (even a WebDAV server), I make a separate

Re: [Freeipa-users] apache kerberized nfs4 /var/www/html access denied for apache user

2014-09-15 Thread Nordgren, Bryce L -FS
Hi Rob, How does the NFS server map the apache user to “something” it recognizes? I would suggest that the easiest solution may be to use an IPA account called “apache”, so that the mappings would just work, but currently I’m having trouble running a service as a domain user via systemd.

Re: [Freeipa-users] apache kerberized nfs4 /var/www/html access denied for apache user

2014-09-15 Thread Anthony Messina
On Monday, September 15, 2014 06:10:13 PM Nordgren, Bryce L -FS wrote: How does the NFS server map the apache user to “something” it recognizes? I would suggest that the easiest solution may be to use an IPA account called “apache”, so that the mappings would just work, but currently I’m having