[Samba] Samba4 PDC keytab creation for NFSv4 not working

steve steve at steve-ss.com
Tue Nov 4 14:33:15 MST 2014

On 04/11/14 15:21, Rowland Penny wrote:
> On 04/11/14 13:49, Henrik Dige Semark wrote:

>> Hey,
>> Sorry I missed that in the blog.
>> I read through it, and thought my setup, and what I had done/tried
>> before, was more or less the same - but I missed that he created a
>> nfs-user and added the keytab on the user instead.
>> It's true, I can now add the NFS principal to the keytab but my
>> clients still can't connect.
>> I have also doublet and triple checked, that I do the same on the
>> clients as he describe in the blog-post.
>> My client (hymer$) is part of the domain - I can SSH without password
>> to jotunheim, I have DNS and reverce DNS for the machine, both
>> jotunheim and hymer can ping each other.

So it's your nfs4 exports then. Remember that butter is bad for you 
again this year and so you must not export nfs4 mounts from a bind 
mounted fsid=0 pseudo-root. No sir. This year, we're exporting them as 
margarine, just like in the good old nfs3 days. If you're not sure what 
brand of margarine you should be using, post your /etc/exports and 
idmapd configs at both ends and we'll advise and rpc.idmapd -fvvv at 
both ends should help us nail it.

More information about the samba mailing list