Rocksolid Light

Welcome to RetroBBS

mail  files  register  newsreader  groups  login

Message-ID:  

Memories of you remind me of you. -- Karl Lehenbauer


devel / comp.protocols.kerberos / Re: About the purpose of client host principals for NFS

SubjectAuthor
o Re: About the purpose of client host principals for NFSSimo Sorce

1
Re: About the purpose of client host principals for NFS

<mailman.7.1696861753.2263420.kerberos@mit.edu>

  copy mid

https://www.rocksolidbbs.com/devel/article-flat.php?id=383&group=comp.protocols.kerberos#383

  copy link   Newsgroups: comp.protocols.kerberos
Path: i2pn2.org!i2pn.org!usenet.blueworldhosting.com!diablo1.usenet.blueworldhosting.com!tncsrv06.tnetconsulting.net!.POSTED.mailman.mit.edu!not-for-mail
From: simo@redhat.com (Simo Sorce)
Newsgroups: comp.protocols.kerberos
Subject: Re: About the purpose of client host principals for NFS
Date: Mon, 09 Oct 2023 10:28:45 -0400
Organization: Red Hat
Lines: 27
Message-ID: <mailman.7.1696861753.2263420.kerberos@mit.edu>
References: <2245400.ev0DxJNslZ@invader> <87r0m6ur2z.fsf@hope.eyrie.org>
<2917780.mvXUDI8C0e@invader>
<39b779680f37010209842b1e68d07aef2fc52d0b.camel@redhat.com>
Mime-Version: 1.0
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: 8bit
Injection-Info: tncsrv06.tnetconsulting.net; posting-host="mailman.mit.edu:18.7.21.50";
logging-data="16896"; mail-complaints-to="newsmaster@tnetconsulting.net"
User-Agent: Evolution 3.46.4 (3.46.4-1.fc37)
To: Marco Rebhan <me@dblsaiko.net>, kerberos@mit.edu
Authentication-Results: mit.edu;
dmarc=pass (p=none dis=none) header.from=redhat.com
Authentication-Results: mit.edu; arc=pass smtp.remote-ip=18.9.3.18
ARC-Seal: i=2; a=rsa-sha256; d=mit.edu; s=arc; t=1696861751; cv=pass;
b=tYb7DKAaW6FynQlPpNvJiWQqSuVZrO+Rm6NiQNGTvFORjDZ92MdLFCOwBbmkXptkKPm0r56vTnYSFb9Y/kp6D/Vc4qmwNwEOtB96yuqC/6zk3RMghnUsOqagxbbkwcNJYTj0gvTFQ7HzaNyoL06cFUkxRcZ1nYKUmQPxIfeRMbtKjSRVJP7KwtZGiY6TTwnuu6XmSmn3kRG36VyEOVm0KMY4fcJkY3hT4fEac4XcdLN7wc7np42383eeCp2QFU4p4a+IpNa6bSY+Q7jjon11anEM7j/Jr26myszjCHlZ9dHG8HSQ/W+Ci7FQox7wcJpmJAtM6uVKM3HWofu5vPUYsQ==
ARC-Message-Signature: i=2; a=rsa-sha256; d=mit.edu; s=arc; t=1696861751;
c=relaxed/relaxed; bh=fTu+ZrCk+3pDkfmZdDuuMSAnJEL7jGlrwSs4v8W0xKs=;
h=Message-ID:Subject:From:Date:MIME-Version:Content-Type;
b=GtI2anA+oE/yl9HXYZtpkPOYEYiWZRjR+jRpqzidqJ9+J1Cz0AlZFQZvvbWCmHLDpNgX5ERz404W1oQ3os17uCOR/gWP8PgkJq4t9s7fz+lLj8DHfKvvJVFPtvby7zJcWbqIwi87DSurJJWL6wX4j5oYTiQWuE9I8mGTOz+QJSHIdiXB6lctD+Gdmxgd23l4APHXiFh8epfIpAo9N8uEXbT4Aup6iqVPTG8344ZkCZk3aV6MtJVyGFg6+YC8nr3oeCi+H5nX3zwr89ny+ny0OerV0DzNskCdvtATxIfw7HOy4+O/qh8fpfnTg+Uf12yCzrYuZbcm4LacsnR5lWNRLg==
ARC-Authentication-Results: i=2; mit.edu; dkim=pass (1024-bit key;
unprotected) header.d=mitprod.onmicrosoft.com
header.i=@mitprod.onmicrosoft.com header.a=rsa-sha256
header.s=selector2-mitprod-onmicrosoft-com header.b=HqF/fK7I;
dkim=pass (1024-bit key;
unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256
header.s=mimecast20190719 header.b=QxS0Rau+
Authentication-Results: mit.edu; dkim=pass (1024-bit key;
unprotected) header.d=mitprod.onmicrosoft.com
header.i=@mitprod.onmicrosoft.com header.a=rsa-sha256
header.s=selector2-mitprod-onmicrosoft-com header.b=HqF/fK7I;
dkim=pass (1024-bit key;
unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256
header.s=mimecast20190719 header.b=QxS0Rau+
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;
b=Go5RdbztZFFIG6ER1AgnXZ9RRe6FZlQ+4F6be99yGXBcMMTRccgidjhUvrmsJ+1EDBLu41FhTxqgqcBnPWXwdBIUa+RXEy7H0CR7JE6rj0DNkg3+QZ/ZKCQQSKH9yxZppNRXZqCpxFTOkuyVksJoq4oni5Y3i7D4iOFEA2Z3CkzHMWsUDruGyBUsjMQOIJr0p857k4ZVhsUQODzfi+YIHiHqNNyJOluG33psyyRxzg2EiwfuuIqJWwVaL1VDJ+hNMb7mXYz8BDOYooU2wOkvKpJbM6DydB0OlapKOR6WkkSX2bUxkLvfOSjwI+6kl6784/vZ361obnpQzmHLL9NePg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;
s=arcselector9901;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;
bh=fTu+ZrCk+3pDkfmZdDuuMSAnJEL7jGlrwSs4v8W0xKs=;
b=QQHNtxpqWVbGVw+YSWn3brLD9aHrn84WXNBI4Bvc5ZzMaHBkb8iZzcrNUDxfsBUOZDM1Y1rAzz5GJW1snMihX/d37QhhQr87xHEDOwv8hzUF6x/uihJN2rIzAOsblgiljQQpNZ7iDUJWrR6F8FqmTl4oqLXZIxgZFgZ72kW/6OcYHXofl5aO6JstjS1yIgQHrsGAuxpe+IfV0H7EZSMz+yB+GDfq/21ZEsz7MtGS96/VrCc8u+pqFn6K+fKH9frXboNoygTQB89rJkbRGELjsKPp6/8sRi18u8Rx7qoMpnT0eDLYEeeO6YiaCTN5521Ih+2EI2KX9lh6v3Y8weLwEQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is
170.10.133.124) smtp.rcpttodomain=mit.edu smtp.mailfrom=redhat.com;
dmarc=pass (p=none sp=none pct=100) action=none header.from=redhat.com;
dkim=pass (signature was verified) header.d=redhat.com; arc=none (0)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=mitprod.onmicrosoft.com; s=selector2-mitprod-onmicrosoft-com;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;
bh=fTu+ZrCk+3pDkfmZdDuuMSAnJEL7jGlrwSs4v8W0xKs=;
b=HqF/fK7I81syjYvwrLrU+uNJd+1KYyP2rxlPUn5uXd0x1FvrgnqfUi4LobBXtEixT593MW9mWiOcVPfRWVTSxHGwXgM8qmpabXBrqNRPMGc0zn1aTJI/d8XBNQ/EsxDOy+d0aFgmaEimQQ43yNilnfgHQr6fXIVjuLWpZOp2P9I=
Authentication-Results: spf=pass (sender IP is 170.10.133.124)
smtp.mailfrom=redhat.com; dkim=pass (signature was verified)
header.d=redhat.com;dmarc=pass action=none header.from=redhat.com;
Received-SPF: Pass (protection.outlook.com: domain of redhat.com designates
170.10.133.124 as permitted sender) receiver=protection.outlook.com;
client-ip=170.10.133.124; helo=us-smtp-delivery-124.mimecast.com; pr=C
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com;
s=mimecast20190719; t=1696861731;
h=from:from:reply-to:subject:subject:date:date:message-id:message-id:
to:to:cc:mime-version:mime-version:content-type:content-type:
content-transfer-encoding:content-transfer-encoding:
in-reply-to:in-reply-to:references:references;
bh=fTu+ZrCk+3pDkfmZdDuuMSAnJEL7jGlrwSs4v8W0xKs=;
b=QxS0Rau+XYqEgsIZHVb6l8BXfUIdFet1HIwbCX2MHaECyzSB7wf9E8Gu108Va8UO6lkHh/
0SOw7I8WsuEScbsKCqdT+e0pErPxGrYyEGso2vW81ZBp0f1LS41errjG5e+lFA1tldZRBj
MZpTvmDzSzdFAdg7To5uTK1HwOke1dA=
X-MC-Unique: TOnol-WcPwWwsrVUi6l7vQ-1
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20230601; t=1696861729; x=1697466529;
h=mime-version:user-agent:content-transfer-encoding:organization
:references:in-reply-to:date:to:from:subject:message-id
:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to;
bh=fTu+ZrCk+3pDkfmZdDuuMSAnJEL7jGlrwSs4v8W0xKs=;
b=J6x2c7KUOcv2Rqoswd7VLm6Guuuv7/B5xywU17doKRVaqYrzuj9uVPliT0e3iZ8tF1
YHuJbGjgqCSeT9tYygt/Qy53VEhR46W4jpg8gczKAPrdQDemXfX5RDmZnrZgJG7HMxjp
8GM8lgDyXRuK9sYRWYn3qtrye1gBEHso7FrXEJiq+8RxLb1nE3kiM4erDkkEN+XYXXze
fpvDNzA+JOjDE6nVbWpo5aky8J97utiJ8AMQJihty89hf2QcOLfIa8zvDqKFhzs1KzQP
X4MUJ6BMPw3BMlbVUInk48jWTGkeEdpn5thryYALYp40pcwlQmse1QlgLRZMRRHOHeH0
uAzw==
X-Gm-Message-State: AOJu0YxpUVlzsY6hMlj3z/fmS0IbfjJV6IWNLYoXwhGGS9hxYGLwYLtq
Mcr/3wUG5bDzuKODfh3YnHVWhUFjB9XSOPzgD3AJRW5RrcMyLPkocX1HiK+QFABTFDmKBaq8qC7
j/C6DE1JaPRr4St/T
X-Received: by 2002:a05:6102:34f1:b0:44e:8353:e86a with SMTP id
bi17-20020a05610234f100b0044e8353e86amr9780051vsb.24.1696861728218;
Mon, 09 Oct 2023 07:28:48 -0700 (PDT)
X-Google-Smtp-Source: AGHT+IEjVTWJKeGSeX7SaTxlwqic77qK282oPI21NTJJDgXbrD8xzejaE5dhVFkeEwLUekHGVwL6Dw==
X-Received: by 2002:a05:6102:34f1:b0:44e:8353:e86a with SMTP id
bi17-20020a05610234f100b0044e8353e86amr9779979vsb.24.1696861726399;
Mon, 09 Oct 2023 07:28:46 -0700 (PDT)
In-Reply-To: <2917780.mvXUDI8C0e@invader>
X-Mimecast-Spam-Score: 0
X-Mimecast-Originator: redhat.com
X-EOPAttributedMessage: 0
X-EOPTenantAttributedMessage: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b:0
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: CO1PEPF000044F1:EE_|MW4PR01MB6145:EE_
X-MS-Office365-Filtering-Correlation-Id: 9bbd99af-250b-416a-c8a9-08dbc8d40fea
X-LD-Processed: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b,ExtAddr
X-MS-Exchange-AtpMessageProperties: SA
X-MS-Exchange-SenderADCheck: 0
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: 7Bqlj0rVW3vgHzRThGqztbRgVnO5luIbFFyernruOIlKEzZuYb9UUdKcW/IK3iJ/4WJugBMXKFX96NWF5QYwr5yNejkqsCM7PlZDMW5RSIuqPujuLVh3Z2LAzow0JGRr5sGH2U/AuhKmIexDc+WYLK70OkSui6kBZp6hv4I8B/3oG5etOlQVUH1HJBq2q6OuS0Ietg6zLtY3rZLzcjjGlXitmmo7zm/UCpqn6WTcTnodYRpjP4nHylmrYeTRyq6srKJuGdqNDx/jCTVu+8FYmGc6QzTFEvnuKrYO7rBixhJqyU8iCW1K4bBiG6kDgqTFFk/anP1L5VlPUqxiS+R0qEJf8JR1MCB8eAXEkQFm2QGEDI20pk7EYP6A7SgGc2eXifJPj2P1i80Ove59f0wE5KjnJA+JdWZXcVUr7nrvOgwcPaZZFL5P7FHZ3fzxR/d2HcgYKX3j2YTyylhZhbuxDiGDHJv4zxJjZnfNx9fxeQ07Qz9zuj/oQBJCogmB7a/WdnypyIXbaxt3i+xL3pBPcBik1FNmfr7uTLPBOve4L9OS/OCYoLohpAYbPfjZl4laCuRi1TI2YSZK3UBP5Bt/olVGImkfmHfYKsrstVC3qhTow9xLekafMqA1wse5JroptStiXnB8VInfLZQH02htmboFLjNXAOC5fA1FqKVr4qexX5/dJwP0vyeOzUN3jqNAeJBHQQzzqD3zElnzcbTuUg==
X-Forefront-Antispam-Report: CIP:170.10.133.124; CTRY:US; LANG:en; SCL:1; SRV:;
IPV:NLI; SFV:NSPM; H:us-smtp-delivery-124.mimecast.com;
PTR:us-smtp-delivery-124.mimecast.com; CAT:NONE;
SFS:(13230031)(4636009)(396003)(136003)(346002)(376002)(39860400002)(61400799006)(48200799006)(451199024)(64100799003)(336012)(2616005)(26005)(68406010)(316002)(70586007)(786003)(8676002)(7696005)(2906002)(498600001)(4744005)(5660300002)(36916002)(36756003)(356005)(7636003)(7596003)(86362001);
DIR:OUT; SFP:1102;
X-Auto-Response-Suppress: DR, OOF, AutoReply
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 09 Oct 2023 14:28:52.5755 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 9bbd99af-250b-416a-c8a9-08dbc8d40fea
X-MS-Exchange-CrossTenant-Id: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b
X-MS-Exchange-CrossTenant-AuthSource: CO1PEPF000044F1.namprd05.prod.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: Internet
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MW4PR01MB6145
X-OriginatorOrg: mitprod.onmicrosoft.com
X-MIME-Autoconverted: from quoted-printable to 8bit by mailman.mit.edu id
399ETBZ7004140
X-BeenThere: kerberos@mit.edu
X-Mailman-Version: 2.1.34
Precedence: list
List-Id: The Kerberos Authentication System Mailing List <kerberos.mit.edu>
List-Unsubscribe: <https://mailman.mit.edu/mailman/options/kerberos>,
<mailto:kerberos-request@mit.edu?subject=unsubscribe>
List-Archive: <http://mailman.mit.edu/pipermail/kerberos/>
List-Post: <mailto:kerberos@mit.edu>
List-Help: <mailto:kerberos-request@mit.edu?subject=help>
List-Subscribe: <https://mailman.mit.edu/mailman/listinfo/kerberos>,
<mailto:kerberos-request@mit.edu?subject=subscribe>
X-Mailman-Original-Message-ID: <39b779680f37010209842b1e68d07aef2fc52d0b.camel@redhat.com>
X-Mailman-Original-References: <2245400.ev0DxJNslZ@invader>
<87r0m6ur2z.fsf@hope.eyrie.org>
<2917780.mvXUDI8C0e@invader>
 by: Simo Sorce - Mon, 9 Oct 2023 14:28 UTC

On Sun, 2023-10-08 at 03:03 +0200, Marco Rebhan via Kerberos wrote:
> On Saturday, 7 October 2023 22:15:32 CEST Russ Allbery wrote:
> > [..]
>
> That clears up a lot, thank you so much!

Keying clients is useful to allow mount at boot time, before any user
with valid credentials has logged in, as well as for NFS 4.0 only (doe
snot apply to earlier protocol version nor to 4.1 and later) to do some
callback calls to the server where the protocol does not know what user
to use.

It is not strictly needed, if you use autofs for homes for example you
can live w/o a client service principal.

HTH,
Simo.

--
Simo Sorce,
DE @ RHEL Crypto Team,
Red Hat, Inc

1
server_pubkey.txt

rocksolid light 0.9.8
clearnet tor