Uploaded image for project: 'Lustre'
  1. Lustre
  2. LU-17518

MDS still trust client-originated support GID on a Kerberos enabled filesystem

Details

    • 3
    • 9223372036854775807

    Description

      On a kerberos enabled filesystem, the MDS should not trust the UID/GID/supplementary groups sent by the clients, and instead get the UID from the GSS context, and the GID and supplementary groups from the identity upcall.

      Attachments

        Issue Links

          Activity

            [LU-17518] MDS still trust client-originated support GID on a Kerberos enabled filesystem
            pjones Peter Jones made changes -
            Link New: This issue is duplicated by LU-11612 [ LU-11612 ]
            pjones Peter Jones made changes -
            Fix Version/s New: Lustre 2.16.0 [ 15190 ]
            Resolution New: Fixed [ 1 ]
            Status Original: Open [ 1 ] New: Resolved [ 5 ]
            sebastien Sebastien Buisson made changes -
            Link New: This issue is related to NVDCSE-160 [ NVDCSE-160 ]
            sebastien Sebastien Buisson created issue -

            People

              sebastien Sebastien Buisson
              sebastien Sebastien Buisson
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: