- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Re: CIFS client & Kerberos
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-24-2007 03:29 AM
08-24-2007 03:29 AM
I might be over complicating things with this configuration but I have reached an stuck point.
I am trying to share a directory in HPUX 11i v1 (A) with CIFS. My goal is to be able to mount it to another HPUX 11i v1 (B).
To achive this, I have installed Kerberos Server T1417AA in other server 11i v1 (C).
To begin with, the autoconfiguration of kerberos server behaved different from what was in the documentation. To simplify things I cannot find a /etc/krb5.conf file...
Any help, advice or suggestion would be gratefully appreciated.
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-24-2007 08:11 AM
08-24-2007 08:11 AM
Re: CIFS client & Kerberos
You need a Windows KDC to use Kerberos with both the CIFS Server and Client. You need to install the HP-UX 11v1 Kerberos Client for either the CIFS Server/Client to work with krb5 authentication. Don't use the Kerberos Client that originally came with 11iv1 - go here and get the latest client:
http://h20293.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=KRB5CLIENT
All of this may be moot if you do not have a Windows 2000/2003 KDC to use.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-27-2007 09:01 PM
08-27-2007 09:01 PM
Re: CIFS client & Kerberos
I do not have a windows KDC. Are you sure is absolutely necessary? I've been reading quite a lot of kerberos documentation (my head is spinning around) and is never mentioned Windows...
But if that is the case I will go back to NFS, last thing I want is to get into Windows.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-27-2007 09:08 PM
08-27-2007 09:08 PM
Re: CIFS client & Kerberos
I actually have a case open on this with the HP response center in Israel.
So far, I have been advised to make sure the latest version of CIFS client and server are installed on the HP-UX system.
I will provide further update as I run a checklist and diagnose.
cifs client requires a reboot to install, so plan that one out.
Hopefully I can get back to you with good news soon.
SEP
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-27-2007 10:03 PM
08-27-2007 10:03 PM
Re: CIFS client & Kerberos
I have installed the most recent versions in the servers. But I have to tell I am lost following the documentation. I am wandering if is a case of updating the document...
This is the dialog that I've got for the server configuration:
1) Configure as a Primary Security Server
2) Configure as a Secondary Security Server
-I chose option 1.
Do you want to stash the principal database key on your local disk (y/n)
- I replied y
Please enter the fully qualified name of the Secondary Security Server1
press 'q' if you want to skip this and proceed further:
-replied q
Enter the realm name
- I gave a name different from the default
Then it shown all these lines:
/opt/krb5/krb.conf moved to /opt/krb5/krb.conf.keep
/opt/krb5/krb.realms moved to /opt/krb5/krb.realms.keep
/opt/krb5/kpropd.ini moved to /opt/krb5/kpropd.ini.keep
Creating krb.conf and krb.realms files
Copying admin_acl_file and password.policy file onto KRB5_ROOT dir
You will be prompted for the database Master Password.
It is important that you DO NOT FORGET this password.
Enter Password:
Kerberos server has been configured successfully.
Then the next thing in the document (http://docs.hp.com/en/T1417-90001/ch03s03.html) is a description of the files that suppose to be generated automatically and that I cannot find: krb5.conf and kdc.conf.
So I hope the guys from HP come up with a nice explanation.
Thanks and regards,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-28-2007 03:44 AM
08-28-2007 03:44 AM
Re: CIFS client & Kerberos
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-28-2007 03:51 AM
08-28-2007 03:51 AM
Re: CIFS client & Kerberos
Still fighting with this. We are trying to avoid a Kerberos server on HP-UX for fear it will interfere with SSO, single sign on using the windows PDC.
I will read your doc, run your configuration script and see what it gets me. I'm thinking I may need to install the server product to make this work.
SEP
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-28-2007 04:22 AM
08-28-2007 04:22 AM
Re: CIFS client & Kerberos
Kerberos Key Distribution Center and CIFS Servers
For this release, only Windows 2000 is supported for Kerberos authentication.
Specifically, Key Distribution Centers (KDCs) and CIFS file servers
that participate in Kerberos authentication with the HP CIFS Client
must be Windows 2000 systems. Any other supported server platform
can be used for traditional NTLM authentication.
After all it seems that Eric was right...
I think I did some work with Samba in Suse 8, but I was not happy with the results and as my favourites servers are HP, I was just dreaming with CIFS replacing the awful NFS.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-28-2007 05:44 AM
08-28-2007 05:44 AM
Re: CIFS client & Kerberos
I'm not sure that HP CIFS Client is up to the task of replacing NFS. My (brief) dealings with it did not give me confidence. It worked, but it seemed a little quirky and very poorly documented.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-29-2007 02:30 AM
08-29-2007 02:30 AM
Re: CIFS client & Kerberos
I am going to give it another shot without touching kerberos. I think I got so confused reading here and there, that I lost the plot completely.
It may be a bit academic, but the question is still valid for that kerberos configuration script...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-29-2007 03:55 AM
08-29-2007 03:55 AM
Re: CIFS client & Kerberos
I don't know about the Kerberos configuration script, but most of the HP-supplied setup scripts I've looked at were outdated, had undocumented limitations, or had no documentation at all. It wouldn't surprise me if the documentation was wrong or the script was broken.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-29-2007 11:07 AM
08-29-2007 11:07 AM
Solutionyes - I am absolutely sure that to authenticate either HP CIFS Server or HP CIFS Client with Kerberos, you must use a Windows KDC.
The HP-UX Kerberos server can auth-n HP-UX applications, Inet-Services, or PAM-Kerberos, but not either CIFS product.
Sorry for the misunderstanding. I can post the links in the docs that explain this, if you like. You can look at the Samba list for postings where users try to hack in an MIT or Heimdal KDC, but that's not a "supported" Samba config.
Eric Roseme
Hewlett-Packard
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-29-2007 09:19 PM
08-29-2007 09:19 PM
Re: CIFS client & Kerberos
This then settles it down. I was wrong trying to use kerberos for what I intended to do.
I will wait for Steve to write his findings before closing the thread.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-30-2007 04:49 AM
08-30-2007 04:49 AM
Re: CIFS client & Kerberos
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-15-2007 09:48 PM
11-15-2007 09:48 PM
Re: CIFS client & Kerberos
http://docs.hp.com/en/T1417-90003/ch05s03.html