Received: by 2002:a05:6a10:206:0:0:0:0 with SMTP id 6csp3482576pxj; Mon, 24 May 2021 07:45:24 -0700 (PDT) X-Google-Smtp-Source: ABdhPJxXRGNndQWeJT/js4NSouVgS4RxL71l0fvxdCltqDVASVSSi1AmL87eW+i13lxXoBoftRcU X-Received: by 2002:a17:906:8504:: with SMTP id i4mr24195887ejx.515.1621867524174; Mon, 24 May 2021 07:45:24 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1621867524; cv=none; d=google.com; s=arc-20160816; b=LRXbVDQ6Epik+Z1qXXNcJuKBVK9KkNj/+Vldw1KQuzzYPUIgpU2QRBrmCWJDBNlLlG Ke51FlRBES0xCsrPBBi7AqN7p6lzczMCA8uKIy9N3SHLKel8EJg0WTfEHgauU3pXWmY4 roUW4jw1K3bs4iVAKmxAsgmznyZoUnPkoOEx+YwdmOB18bul/Xm4sV33c17IZ/SvcoeO 4QqyXUHFiIxW3/IRTHccPWlKbbRLXvqgDNYELtSngrqyMOc+V4P1uze77n4sVIiVT/vY Hcl1of42RHLV4HDGzCEQ55GY+Yuh7o5A0aEvXhsUH9Yo+O8/PwvO7tCq5VJhwNhNrxby qbQQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-language:content-transfer-encoding :in-reply-to:mime-version:user-agent:date:message-id:from:references :cc:to:subject; bh=VPHsK6/u08ZW8wFA6ANDjtNAn8uz648KzoDuHxBBKZI=; b=D54Fs4RtCXhjsabb2qPVlpqKpNAxEoCh/jxE0JHZZGIWjzRBl8OadWpclufBOEfBHX FtGEZVXwx91PmWK5e3IqLnFYfYventVhqDzHW4OAr7Y7ZKo6/k6g1MnGMYSuv3iEssGc tM0tIpiYrF3FNOnksdqIB1hhkufJMHrTCQHn9R1uqmyESTS7SwAe40jEThDusFeBkXZI 0mKEBjHfLbp9nDEXGjtIZiMsAR6b1QT5PYRiMi9gr8+RlRajY5OiYs20j32eipH7hXjU lPNp9yB8Ohx6OlrlbPCkwHgdM6cj7hZqphtyPDok1kBMMssFYcrjXt+DLp1AJDNMO5EG +Dcg== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of linux-nfs-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-nfs-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id f16si13879594edy.298.2021.05.24.07.45.00; Mon, 24 May 2021 07:45:24 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-nfs-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; spf=pass (google.com: domain of linux-nfs-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-nfs-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S233048AbhEXOpj (ORCPT + 99 others); Mon, 24 May 2021 10:45:39 -0400 Received: from bronze1.eecs.yorku.ca ([130.63.94.75]:51284 "EHLO bronze1.eecs.yorku.ca" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S233045AbhEXOph (ORCPT ); Mon, 24 May 2021 10:45:37 -0400 Received: from [170.133.224.154] (helo=[192.168.1.136]) by bronze1.eecs.yorku.ca with esmtpsa (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (Exim 4.94.2-31-503e55a2c) (envelope-from ) id 1llBoO-0012Sp-BD; Mon, 24 May 2021 10:44:08 -0400 Subject: Re: ksu problem with sec=krb5 and nfs To: Benjamin Coddington Cc: linux-nfs@vger.kernel.org References: <7714ABF4-E9CD-424B-BF7F-6F1B91F58C2B@redhat.com> From: Jason Keltz Message-ID: Date: Mon, 24 May 2021 10:44:01 -0400 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:78.0) Gecko/20100101 Thunderbird/78.10.1 MIME-Version: 1.0 In-Reply-To: <7714ABF4-E9CD-424B-BF7F-6F1B91F58C2B@redhat.com> Content-Type: text/plain; charset=utf-8; format=flowed Content-Transfer-Encoding: 8bit Content-Language: en-US X-Spam-Score: -101.0 X-Spam-Level: --------------------------------------------------- X-Spam-Report: Content analysis details: (-101.0 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- -100 SHORTCIRCUIT Not all rules were run, due to a shortcircuited rule -1.0 ALL_TRUSTED Passed through trusted hosts only via SMTP Precedence: bulk List-ID: X-Mailing-List: linux-nfs@vger.kernel.org Hi Benjamin, That's exactly it - I definately want ksu to be writing that exact file.  Any idea why it isn't, and why it matters if the home directory is using sec=krb5 or not? Jason. On 5/24/2021 7:30 AM, Benjamin Coddington wrote: > On 22 May 2021, at 10:47, Jason Keltz wrote: > >> Can someone help me understand the issue, and whether there is a solution? > Don't you want ksu to write its target cache to /tmp/krb5cc_1011 so rpc.gssd > can find it? Why isn't that happening? > > Ben > >