NFSv4 client in FIPS mode (fips=1 on kernel command line) kerberos mount causes kernel panic in gss_pipe_downcall - kernel BUG at net/sunrpc/auth_gss/auth_gss.c:699!

Solution In Progress - Updated -

Issue

  • NFSv4 Mount with krb5 causes kernel panic
  • mounting with sec=krb5{,i,p} causes kernel panic in fips mode if the gss context received by the client uses md5

Environment

  • Red Hat Enterprise Linux 6 or 7
  • Secure (kerberized) NFS configured
  • EMC Isilon NFS server running OneFS 7.x (but can also be reproduced using a Linux NFS server that has aes256-cts-hmac-sha1-96 and aes128-cts-hmac-sha1-96 disabled)
  • Client running in FIPS mode (i.e. fips=1 is in the kernel command line)
  • Seen with Microsoft Active Directory (AD) Key Distribution Center (KDC)

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase of over 48,000 articles and solutions.

Current Customers and Partners

Log in for full access

Log In
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.