[Samba] Pam_mount not working with "sec=krb5"

buhorojo buhorojo.lcb at gmail.com
Mon Nov 2 14:10:45 UTC 2015


On 02/11/15 14:42, Ole Traupe wrote:
>
> Am 02.11.2015 um 13:12 schrieb buhorojo:
>> On 02/11/15 12:54, Ole Traupe wrote:

>> Why can't the user do it with his own key file?
Only root can perform mounts and anyway, cifs upcall looks for a key, 
not a cache.
>
> Also, if the user is not mounting his home share, but somebody else, 
> this _other_ user will be the owner of newly created files and 
> folders, right
No. With multiuser, acl and permissions are respected. If the user would 
normally be the owner of newly created files, then he will be also over 
cifs.

One other thing, you need a recent version of cifs utils (we don't think 
Centos has) and to make sure that you lose the -c at /etc/request-key.conf:
create  cifs.spnego     *       * /usr/sbin/cifs.upcall -c %k

HTH




More information about the samba mailing list