You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

配置Kerberos的NFS无法通过sec=krb5*挂载,sec=sys正常

无法使用sec=krb5*参数挂载NFS卷,但sec=sys模式正常工作

环境信息

  • 机器1(M1):部署nfs-kernel-server/Kerberos的openSUSE服务器,IP为192.168.2.255(/23网段)
  • 机器2(M2):Debian客户端,IP为192.168.2.120
  • 路由器(R):OPNSense DNS/DHCP服务器,IP为192.168.2.1

DNS配置

  • M1对应域名:kerberos.example.org、storage.example.org、nfs.example.org
  • M2对应域名:intel-deb.example.org
  • R对应域名:opnsense.example.org

Kerberos主体

已配置以下主体:

host/intel-deb.example.org@EXAMPLE.ORG
host/kerberos.example.org@EXAMPLE.ORG
host/nfs.example.org@EXAMPLE.ORG
host/storage.example.org@EXAMPLE.ORG
nfs/intel-deb.example.org@EXAMPLE.ORG
nfs/kerberos.example.org@EXAMPLE.ORG
nfs/nfs.example.org@EXAMPLE.ORG
nfs/storage.example.org@EXAMPLE.ORG

导出配置(/etc/exports)

尝试过两种配置:

#/mnt/raid6-main/Users/user intel-deb.example.org(rw,sync,no_subtree_check,sec=krb5p)
/mnt/raid6-main/Users/user  *(rw,sync,no_subtree_check,no_root_squash,sec=krb5p)

Kerberos配置(/etc/krb5.conf)

采用MIT Kerberos配置,默认域为EXAMPLE.ORG,指定KDC和管理服务器为kerberos.example.org,加密类型包含aes256-cts等。

密钥表与票据测试

  • M2:通过ktadd生成包含host/intel-deb.example.org@EXAMPLE.ORG的密钥表,执行kinit -k后klist显示已获取krbtgt和nfs/storage.example.org的有效票据
  • M1:通过ktadd添加host/storage.example.org@EXAMPLE.ORG,执行kinit -k后klist显示有效krbtgt票据

日志信息

  • M2的gssproxy日志显示成功获取nfs/storage.example.org的凭证并生成认证器
  • M1启用rpcdebug后,/var/log/messages无有效错误信息
  • M2执行mount -vvv -t nfs4 -o sec=krb5p ...时,多次尝试不同NFS版本均返回权限拒绝

其他验证

  • showmount -e显示导出目录正常
  • DNS正向、反向解析均正常
  • M1的/etc/hosts中自身域名指向127.0.0.1

内容的提问来源于stack exchange,提问作者fpc7063

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.22 14:34:56