Secure NFS may not work in Active Directory domains if fully qualified usernames are enabled

Solution In Progress - Updated -

Issue

  • We are able to mount an NFS filesystem with sec=krb5, but files created by users are owned by nobody or nfsnobody
  • File ownership is correct if the NFS filesystem is mounted with sec=sys
  • Secure NFS may not work in Active Directory domains if fully qualified usernames are enabled

Environment

  • Red Hat Enterprise Linux 7 NFS server
  • Active Directory KDC
  • /etc/sssd/sssd.conf has
use_fully_qualified_names = True

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase of over 48,000 articles and solutions.

Current Customers and Partners

Log in for full access

Log In
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.