[Freeipa-users] Mount cifs share using kerberos

John Obaterspok john.obaterspok at gmail.com
Fri Jan 9 10:26:12 UTC 2015


2015-01-09 10:11 GMT+01:00 Alexander Bokovoy <abokovoy at redhat.com>:

> On Thu, 08 Jan 2015, John Obaterspok wrote:
>
>> Hello,
>>
>> I've tried to do the following on the client (and also on the ipaserver
>> itself) where I want to the the ipaserver share mounted.
>>
>> [root at ipaserver mnt]# mount -t cifs //ipaserver.MY.LAN/TheShare -o
>> sec=krb5
>> mountpoint
>> mount error(126): Required key not available
>> Refer to the mount.cifs(8) manual page (e.g. man mount.cifs)
>>
>> (root has an admin ticket aquired)
>>
>> Any hints for a newbie?
>>
> Do you have proper configuration in request-key.conf(5)?


I didn't know about those files, so if there are no defaults then I guess I
don't have a proper configuration.


> On Fedora 21 we have /etc/request-key.d/cifs.upcall.conf and
> /etc/request-key.d/cifs.idmap.conf to allow kernel to properly fetch
> Kerberos keys and map IDs of CIFS identities. These configurations are
> part of cifs-utils package which also supplies mount.cifs.
>
>
Thanks Alexander,

-- john
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://listman.redhat.com/archives/freeipa-users/attachments/20150109/58a5f878/attachment.htm>


More information about the Freeipa-users mailing list