NFSv4 client in FIPS mode (fips=1 on kernel command line) kerberos mount causes kernel panic in gss_pipe_downcall - kernel BUG at net/sunrpc/auth_gss/auth_gss.c:699!
Issue
- NFSv4 Mount with krb5 causes kernel panic
- mounting with sec=krb5{,i,p} causes kernel panic in fips mode if the gss context received by the client uses md5
Environment
- Red Hat Enterprise Linux 6 or 7
- Secure (kerberized) NFS configured
- EMC Isilon NFS server running OneFS 7.x (but can also be reproduced using a Linux NFS server that has aes256-cts-hmac-sha1-96 and aes128-cts-hmac-sha1-96 disabled)
- Client running in FIPS mode (i.e. fips=1 is in the kernel command line)
- Seen with Microsoft Active Directory (AD) Key Distribution Center (KDC)
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.