Re: Question on current state of sec=krb5* integration in cifs.ko

Jeff Layton <[email protected]>
Newsgroups gmane.linux.file-systems.cifs
Message-ID <[email protected]>
On Fri, 23 Oct 2009 17:46:02 +0200
Holger Rauch <[email protected]> wrote:

> Hi Jeff,
> 
> thanks again for replying that quickly. I tried sec=krb5 and it indeed
> worked (even in conjunction with autofs5). Strangely enough, it even
> continued to work when the credentials cache was empty (having run
> "kdestroy" deliberately in order to test Kerberos security).
> 
> I could add files even though there were no tickets left in the cache.
> This shouldn't be the case, I think (at least that's how it works on
> NFSv4; i.e. on NFSv4 I would get "permission denied" when tickets are
> either expired or not present). Is CIFS different in this regard?
> 

Yes, much...

NFS (well, RPC actually) sends credentials with every call, so if you
destroy the creds, then the client and server will tend to pick up on
that fact rather quickly. With CIFS the credentials are just used to
establish a "session". After that, krb5 doesn't really come into play
very much (at least until you have to reconnect).

-- 
Jeff Layton <[email protected]>

_______________________________________________
linux-cifs-client mailing list
[email protected]
https://lists.samba.org/mailman/listinfo/linux-cifs-client
signature.asc (application/pgp-signature, 198 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.12 (GNU/Linux)

iEYEARECAAYFAkrh0eQACgkQojH4PzJJfGUGowCaApm1r0hECNa2gIFQ9R0/g8NJ
XzgAn1GvjyfPVj7JZDJ6rK98rdzTyGEJ
=gqkU
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.