From owner-freebsd-stable@FreeBSD.ORG Mon Sep 3 19:25:46 2012 Return-Path: Delivered-To: freebsd-stable@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [69.147.83.52]) by hub.freebsd.org (Postfix) with ESMTP id C4A87106564A for ; Mon, 3 Sep 2012 19:25:46 +0000 (UTC) (envelope-from rmacklem@uoguelph.ca) Received: from esa-jnhn.mail.uoguelph.ca (esa-jnhn.mail.uoguelph.ca [131.104.91.44]) by mx1.freebsd.org (Postfix) with ESMTP id 7BCA18FC18 for ; Mon, 3 Sep 2012 19:25:46 +0000 (UTC) X-IronPort-Anti-Spam-Filtered: true X-IronPort-Anti-Spam-Result: Ap8EAHwDRVCDaFvO/2dsb2JhbABFhgW2JoIgAQEBAwEBAQEgBCcgCwUWDgoRGQIEJQEJJgYIBwQBHASHZgYLp1WSXYsnhXeBEgOOYoRLgiyBFI8Ggn+BRQ X-IronPort-AV: E=Sophos;i="4.80,362,1344225600"; d="scan'208";a="177538336" Received: from erie.cs.uoguelph.ca (HELO zcs3.mail.uoguelph.ca) ([131.104.91.206]) by esa-jnhn-pri.mail.uoguelph.ca with ESMTP; 03 Sep 2012 15:25:38 -0400 Received: from zcs3.mail.uoguelph.ca (localhost.localdomain [127.0.0.1]) by zcs3.mail.uoguelph.ca (Postfix) with ESMTP id DAB17B4020; Mon, 3 Sep 2012 15:25:38 -0400 (EDT) Date: Mon, 3 Sep 2012 15:25:38 -0400 (EDT) From: Rick Macklem To: Herbert Poeckl Message-ID: <233953231.1437527.1346700338839.JavaMail.root@erie.cs.uoguelph.ca> In-Reply-To: <5044D574.3050305@ist.tugraz.at> MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="----=_Part_1437526_780559.1346700338836" X-Originating-IP: [172.17.91.203] X-Mailer: Zimbra 6.0.10_GA_2692 (ZimbraWebClient - FF3.0 (Win)/6.0.10_GA_2692) Cc: freebsd-stable@FreeBSD.org Subject: Re: Need help with nfsv4 and krb5 access denied X-BeenThere: freebsd-stable@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Production branch of FreeBSD source code List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 03 Sep 2012 19:25:46 -0000 ------=_Part_1437526_780559.1346700338836 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit Herbert Poeckl wrote: > On 6/25/12 1:21 PM, Herbert Poeckl wrote: > > We are getting access denied error on our debian clients when > > mounting > > nfsv4 network drives with kerberos 5 authentication. > > > > What is wired about this, is that it works with one server, but not > > with > > a second server. > [..] > > For the records: > > The problem was fixed in this post: > http://lists.freebsd.org/pipermail/freebsd-fs/2012-August/015047.html > Ok, so are you saying that the patch in Attila's email fixed your problem? If so, please try the attached patch. (It doesn't set the client security handle stale when DESTROY fails, due to an invalid encrypted checksum. It is similar to his patch, but only for the DESTROY case, which seems to be ok to do from my understanding of the RPCSEC_GSS. It doesn't include the timer changes, which shouldn't affect the outcome from afaik.) To consider the client security handle still valid when a data (real RPC in the message) phase entry fails the encrypted checksum seems riskier to do, so I'd like to avoid that in any patch for head. rick > Kind regards, > Herbert Poeckl > > _______________________________________________ > freebsd-stable@freebsd.org mailing list > http://lists.freebsd.org/mailman/listinfo/freebsd-stable > To unsubscribe, send any mail to > "freebsd-stable-unsubscribe@freebsd.org" ------=_Part_1437526_780559.1346700338836 Content-Type: text/x-patch; name=rpcsec-destroy.patch Content-Transfer-Encoding: base64 Content-Disposition: attachment; filename=rpcsec-destroy.patch LS0tIHJwYy9ycGNzZWNfZ3NzL3N2Y19ycGNzZWNfZ3NzLmMuc2F2CTIwMTItMDktMDEgMTk6MjA6 MzUuMDAwMDAwMDAwIC0wNDAwCisrKyBycGMvcnBjc2VjX2dzcy9zdmNfcnBjc2VjX2dzcy5jCTIw MTItMDktMDEgMTk6MjQ6MTUuMDAwMDAwMDAwIC0wNDAwCkBAIC05ODQsNyArOTg0LDcgQEAgc3Zj X3JwY19nc3NfYWNjZXB0X3NlY19jb250ZXh0KHN0cnVjdCBzdgogCiBzdGF0aWMgYm9vbF90CiBz dmNfcnBjX2dzc192YWxpZGF0ZShzdHJ1Y3Qgc3ZjX3JwY19nc3NfY2xpZW50ICpjbGllbnQsIHN0 cnVjdCBycGNfbXNnICptc2csCi0gICAgZ3NzX3FvcF90ICpxb3ApCisgICAgZ3NzX3FvcF90ICpx b3AsIHJwY19nc3NfcHJvY190IGdjcHJvYykKIHsKIAlzdHJ1Y3Qgb3BhcXVlX2F1dGgJKm9hOwog CWdzc19idWZmZXJfZGVzYwkJIHJwY2J1ZiwgY2hlY2tzdW07CkBAIC0xMDI0LDcgKzEwMjQsOCBA QCBzdmNfcnBjX2dzc192YWxpZGF0ZShzdHJ1Y3Qgc3ZjX3JwY19nc3NfCiAJaWYgKG1hal9zdGF0 ICE9IEdTU19TX0NPTVBMRVRFKSB7CiAJCXJwY19nc3NfbG9nX3N0YXR1cygiZ3NzX3ZlcmlmeV9t aWMiLCBjbGllbnQtPmNsX21lY2gsCiAJCSAgICBtYWpfc3RhdCwgbWluX3N0YXQpOwotCQljbGll bnQtPmNsX3N0YXRlID0gQ0xJRU5UX1NUQUxFOworCQlpZiAoZ2Nwcm9jICE9IFJQQ1NFQ19HU1Nf REVTVFJPWSkKKwkJCWNsaWVudC0+Y2xfc3RhdGUgPSBDTElFTlRfU1RBTEU7CiAJCXJldHVybiAo RkFMU0UpOwogCX0KIApAQCAtMTM1OCw3ICsxMzU5LDcgQEAgc3ZjX3JwY19nc3Moc3RydWN0IHN2 Y19yZXEgKnJxc3QsIHN0cnVjdAogCQkJYnJlYWs7CiAJCX0KIAotCQlpZiAoIXN2Y19ycGNfZ3Nz X3ZhbGlkYXRlKGNsaWVudCwgbXNnLCAmcW9wKSkgeworCQlpZiAoIXN2Y19ycGNfZ3NzX3ZhbGlk YXRlKGNsaWVudCwgbXNnLCAmcW9wLCBnYy5nY19wcm9jKSkgewogCQkJcmVzdWx0ID0gUlBDU0VD X0dTU19DUkVEUFJPQkxFTTsKIAkJCWJyZWFrOwogCQl9Cg== ------=_Part_1437526_780559.1346700338836--