Hi Marc, On Mon, Aug 5, 2024 at 5:51 PM marc eshel <eshel.marc@xxxxxxxxx> wrote: > > Hi Trond, > > Will the Linux NFS client try to us krb5i regardless of the MDS > configuration? My expectation is that the NFS client will use SECINFO_NO_NAME to find the preferred security flavors of the server. If krb5i is first on the list that the server returns then that's what the client will use. > > Is there any option to avoid it? Yes, you can use the '-o sec=$FLAVOR' mount option to mount with other security flavors. Valid flavors are 'none', 'sys', 'krb5', 'krb5i', and 'krb5p'. I hope this helps! Anna > > Thanks, Marc. > > ul 30 11:10:58 svl-marcrh-node-1 kernel: nfs4_fl_alloc_deviceid_node > stripe count 1 > Jul 30 11:10:58 svl-marcrh-node-1 kernel: nfs4_fl_alloc_deviceid_node > ds_num 1 > Jul 30 11:10:58 svl-marcrh-node-1 kernel: RPC: Couldn't create > auth handle (flavor 390004) > >