kerberized NFS mount fails if NFS server's DNS domain differs from clients' DNS domain

2015-02-14 Thread Sascha Frey
I need some help with Kerberos and NFS. I have to extend an existing installation with one KDC, two NFS servers and a couple of clients. The kerberos realm is: FIRST-DOMAIN.COM DNS (forward&reverse) of the first two NFS servers: nfs-server1.First-Domain.COM nfs-server2.First-Domain.COM DNS of so

Re: Populating krbPrincipalName multivalued (Was: Re: LDAP searches for Kerberos entries)

2015-02-14 Thread Greg Hudson
On 02/14/2015 02:20 AM, Gergely Czuczy wrote: > So, actually there's a difference between an alias, and the -x linkdn= > option? > The alias is technically the very same principal, and addprinc -x > linkdn= is a new principal, linked to an already existing entry in LDAP? linkdn is totally differen