Uploaded image for project: 'Lustre'
  1. Lustre
  2. LU-17518

MDS still trust client-originated support GID on a Kerberos enabled filesystem

    XMLWordPrintable

Details

    • 3
    • 9223372036854775807

    Description

      On a kerberos enabled filesystem, the MDS should not trust the UID/GID/supplementary groups sent by the clients, and instead get the UID from the GSS context, and the GID and supplementary groups from the identity upcall.

      Attachments

        Activity

          People

            sebastien Sebastien Buisson
            sebastien Sebastien Buisson
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: