Re: [SLUG] mount/NFS problems SOLVED?

From: Paul M Foster (paulf@quillandmouse.com)
Date: Wed Jan 14 2009 - 22:30:22 EST


On Wed, Jan 14, 2009 at 04:59:08PM -0500, blee2@tampabay.rr.com wrote:

> Thus Paul M Foster hast written on Wed, Jan 14, 2009 at 04:36:01PM -0500,
> and, according to prophecy, it shall come to pass that:

<snip>

>
> > Additional data: "none" and "sys" don't affect behavior either way as
> > sec= options under NFS (by actual experiment).
>
> There's a SUN page about NFS security that says:
>
> none:
> Use null authentication (AUTH_NONE). NFS clients using AUTH_NONE have
> no identity and are mapped to the anonymous user nobody by NFS servers.
> A client using a security mode other than the one with which a Solaris
> NFS server shares the file system has its security mode mapped to
> AUTH_NONE. In this case, if the file system is shared with sec=none,
> users from the client are mapped to the anonymous user. The NFS
> security mode none is supported by share_nfs(1M), but not by
> mount_nfs(1M) or automount(1M).
>
> If the server see you as anonymous user or having no auth, you aren't going
> to be able to write to anything (directory) that isn't world writable,
> and even then, maybe not.

Eureka... I think!

I just changed the security setting to "sys" in the client fstab and
copied a file as root with no problem. So I decided to run the backup.
Went off without a hitch. That's the only change I'm aware of having
made. And since it appeared to work properly, I'd have to say my
*observation* was off in the first place. I put the sec= parameter in
there after upgrading, and thought I had put in sec=sys and tested. But
I guess I didn't.

The backup is scheduled to go off again tomorrow morning at about 6am.
If it goes off as usual, then I'll know I was right. If not, I'll let
you know.

In any case, thanks for all the think time spent on this.

Paul

-- 
Paul M. Foster
-----------------------------------------------------------------------
This list is provided as an unmoderated internet service by Networked
Knowledge Systems (NKS).  Views and opinions expressed in messages
posted are those of the author and do not necessarily reflect the
official policy or position of NKS or any of its employees.



This archive was generated by hypermail 2.1.3 : Fri Aug 01 2014 - 18:21:45 EDT