Re: [BUG] sec=krb5 mount problem with nfs-utils 1.2.3 on client side

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Fri, Apr 15, 2011 at 9:29 AM, Trond Myklebust
<trond.myklebust@xxxxxxxxxx> wrote:
> On Fri, 2011-04-15 at 12:16 +0200, Michael Guntsche wrote:
>> Thank you for the information, but I got it working in the meantime.
>> The main problem still is that the code for some reason tries to use AES
>> although I tried specifying a different enctype in my kerberos config.
>> Nevertheless it should just work with AES as well, so where was the
>> problem?
>> Quite simple....missing kernel support. I enabled AES support but I DID
>> NOT enable CTS support which is of course needed as well. So after
>> compiling the server and client kernels with BOTH AES and CTS support I
>> can no mount the NFS4 export without any issues.
>
> Sigh. We really should not allow that kind of config. It just creates
> confusion.
>
> Kevin, what are the dependencies for the kerberos V module today? Am I
> missing something in the following list?
>
>        depends on SUNRPC && CRYPTO
>        depends on CRYPTO_MD5 && CRYPTO_DES && CRYPTO_CBC && CRYPTO_CTS
>        depends on CRYPTO_ECB && CRYPTO_HMAC && CRYPTO_MD5 &&
>        CRYPTO_SHA1
>        depends on CRYPTO_AES
>
> Cheers
>  Trond

Yeah, I think that stuff got left out of the final patches.

DES3 needs (in addition to the stuff already there for DES) HMAC and SHA1
AES needs SHA1 AES CTS
RC4 needs ECB ARC4 MD5

So I think you are only missing CRYPTO_ARC4.
--
To unsubscribe from this list: send the line "unsubscribe linux-nfs" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html


[Index of Archives]     [Linux Filesystem Development]     [Linux USB Development]     [Linux Media Development]     [Video for Linux]     [Linux NILFS]     [Linux Audio Users]     [Yosemite Info]     [Linux SCSI]

  Powered by Linux