Re: [Freeipa-users] issues with nfs4 privileges.

2014-06-20 Thread Simo Sorce
On Fri, 2014-06-20 at 18:02 +0200, Rob Verduijn wrote: Hello, I'm a bit at loss with my freeipa kerberized nfs4 shares. the nfs4 shares mount fine and users can read and write their files. However pulse audio does not work properly, and some programs fail to start. When logging in with a

Re: [Freeipa-users] issues with nfs4 privileges.

2014-06-20 Thread Rob Verduijn
Hi Simo, Thanx for the quick answer, i will consider the root implications. However, what about pulse audio not working ? The logs complain about that one not beeing able to write in home as well. Rob 2014-06-20 18:27 GMT+02:00 Simo Sorce s...@redhat.com: On Fri, 2014-06-20 at 18:02 +0200, Rob

Re: [Freeipa-users] issues with nfs4 privileges.

2014-06-20 Thread Simo Sorce
On Fri, 2014-06-20 at 18:57 +0200, Rob Verduijn wrote: Hi Simo, Thanx for the quick answer, i will consider the root implications. However, what about pulse audio not working ? The logs complain about that one not beeing able to write in home as well. Is it running as the pulse user ? If so

Re: [Freeipa-users] issues with nfs4 privileges.

2014-06-20 Thread Rob Verduijn
Hi, I have not touched pulse audio configuration, it's set to default, I can see in the logs the pulseaudio daemon assumes the user id. rtkit-daemon[697]: Successfully made thread 3299 of process 3299 (/usr/bin/pulseaudio) owned by '4701' high priority at nice level -11. rtkit-daemon[697]:

Re: [Freeipa-users] issues with nfs4 privileges.

2014-06-20 Thread Rob Verduijn
Considering the root immplications. Handing out root to all nfs clients is indeed something that is undesirable. However personally I believe manually creating homedirs to be a procedure from the previous millenium. Can I get freeipa to do this automatically the right way ? (respecting security)

Re: [Freeipa-users] issues with nfs4 privileges.

2014-06-20 Thread Simo Sorce
On Fri, 2014-06-20 at 19:51 +0200, Rob Verduijn wrote: Considering the root immplications. Handing out root to all nfs clients is indeed something that is undesirable. However personally I believe manually creating homedirs to be a procedure from the previous millenium. Can I get freeipa