Re: [OpenAFS] Changed behaviour (?) in client kernel module.

2014-12-02 Thread Anders Magnusson
Marc Dionne skrev den 2014-12-02 12:33: On Mon, Dec 1, 2014 at 12:37 PM, Anders Magnusson wrote: Some years ago (around 2008) I did setup a SMB to AFS gateway like this (on RedHat): - samba configured to use Kerberos for client auth - when user authenticated, use root preexec with kimpersonate

Re: [OpenAFS] Changed behaviour (?) in client kernel module.

2014-12-02 Thread Marc Dionne
On Mon, Dec 1, 2014 at 12:37 PM, Anders Magnusson wrote: > Some years ago (around 2008) I did setup a SMB to AFS gateway like this (on > RedHat): > > - samba configured to use Kerberos for client auth > - when user authenticated, use root preexec with kimpersonate to get an AFS > token > - The tok

Re: [OpenAFS] Changed behaviour (?) in client kernel module.

2014-12-01 Thread Anders Magnusson
D Brashear skrev den 2014-12-01 19:49: On Mon, Dec 1, 2014 at 12:28 PM, Anders Magnusson > wrote: Jonathan Billings skrev den 2014-12-01 17:43: On Mon, Dec 1, 2014 at 11:37 AM, Anders Magnusson mailto:ra...@ltu.se>> wrote: chdir("/afs/ltu.se/staff/all/ra

Re: [OpenAFS] Changed behaviour (?) in client kernel module.

2014-12-01 Thread D Brashear
On Mon, Dec 1, 2014 at 12:28 PM, Anders Magnusson wrote: > Jonathan Billings skrev den 2014-12-01 17:43: > > On Mon, Dec 1, 2014 at 11:37 AM, Anders Magnusson wrote: > >> chdir("/afs/ltu.se/staff/all/ragge") = -1 EACCES (Permission denied) >> > > SELinux? > > Nope. > > Do you see any AVC au

Re: [OpenAFS] Changed behaviour (?) in client kernel module.

2014-12-01 Thread Anders Magnusson
Jonathan Billings skrev den 2014-12-01 17:43: On Mon, Dec 1, 2014 at 11:37 AM, Anders Magnusson > wrote: chdir("/afs/ltu.se/staff/all/ragge ") = -1 EACCES (Permission denied) SELinux? Nope. Do you see any AVC audit entries? Not c

Re: [OpenAFS] Changed behaviour (?) in client kernel module.

2014-12-01 Thread Jonathan Billings
On Mon, Dec 1, 2014 at 11:37 AM, Anders Magnusson wrote: > chdir("/afs/ltu.se/staff/all/ragge") = -1 EACCES (Permission denied) > SELinux? Do you see any AVC audit entries? Do you have samba_share_nfs=1? -- Jonathan Billings College of Engineering - CAEN - Unix and Linux Support

[OpenAFS] Changed behaviour (?) in client kernel module.

2014-12-01 Thread Anders Magnusson
Some years ago (around 2008) I did setup a SMB to AFS gateway like this (on RedHat): - samba configured to use Kerberos for client auth - when user authenticated, use root preexec with kimpersonate to get an AFS token - The token was set to the uid, PAGs were not used. This worked actually we