Use kerberos authentication for nfs shares
To improve security when nfs shares are used, we should use kerberos authentication.
- Modified share configuration
- Modified client configuration
- invis Server 14 setup is prepared for kerberos, but exports are still without
- membermod adds the spn we need for kerberos (execute manual)
- client setup is prepared for kerberos. Todo: Exporting the additional spn to the client keytab after the join (or do it manual).
Export keytab on the client: "net ads keytab create" or "net ads keytab create -P"
#6 Updated by ingogoeppert over 3 years ago
- File nfs-kerberos nfs-kerberos added
- Status changed from New to In Progress
- % Done changed from 0 to 30
First setup was successful. Steps to modify a classic nfs setup to a kerberos setup are described in German in the attached document. Test setup was a invis 15 Server and a openSUSE Leap 42.3 Client with KDE Desktop. Both VirtualBox VMs.
#9 Updated by ingogoeppert about 3 years ago
Tests at FrOSCon 13 failed with "permission denied". Very strange: after restarting sssd in the running system it succeeds. It also happened at my test setup. We have to find out why before we roll out nfs with kerberos as default or reconfigure systems to nfs with kerberos.