Secure NFS may not work in Active Directory domains if fully qualified usernames are enabled

Solution In Progress - Updated -

Issue

  • We are able to mount an NFS filesystem with sec=krb5, but files created by users are owned by nobody or nfsnobody
  • File ownership is correct if the NFS filesystem is mounted with sec=sys
  • Secure NFS may not work in Active Directory domains if fully qualified usernames are enabled

Environment

  • Red Hat Enterprise Linux 7 NFS server
  • Active Directory KDC
  • /etc/sssd/sssd.conf has
use_fully_qualified_names = True

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content