在受信任域中使用NFS Kerberos挂载时、服务器拒绝访问
适用场景
- ONTAP 9
- NFS Kerberos
- 受信任域
问题描述
- 在受信任域中挂载NFS Kerberos失败。
[root@host1 ~]#mount -t nfs -vvv -o rw,sec=krb5,nfsvers=4,minorversion=1,clientaddr=10.x.x.x nfs:/volumepath /hostpath
Thu Apr 13 10:52:49 IST 2023
mount.nfs: timeout set for Thu Apr 13 10:54:49 2023
mount.nfs: trying text-based options 'sec=krb5,nfsvers=4,clientaddr=10.x.x.x,vers=4.1,addr=10.x.x.x'
mount.nfs: mount(2): Permission denied
mount.nfs: access denied by server while mounting nfs:/volumepath
- NFS Kerberos LIF在域domain1.com.in"上创建。
::*> nfs kerberos interface show -vserver nfsserver-3
Logical
Vserver Interface Address Kerberos SPN
-------------- ------------- --------------- -------- -----------------------
clus-sv3 clus-sv3-if1 10.xx.yy.228 enabled nfs/clus-sv3.nas.ss.com.in@domain1.com.in
- NFS客户端属于不同的域domain2.com.in。
[root@host1 ~]# realm list
domain2.com.in
type: kerberos
realm-name: DOMAIN2.COM.IN
domain-name: domain2.com.in
configured: kerberos-member
server-software: ipa
client-software: sssd
required-package: ipa-client
required-package: oddjob
required-package: oddjob-mkhomedir
required-package: sssd
login-formats: %U
login-policy: allow-realm-logins