SImple name-to-id mapping with idmapd not working?
Alessio
alga777 at libero.it
Tue Mar 4 07:10:26 EST 2008
Tank you very much, you've been very clear.
> I read something about that (RPC only carries UID/GID in headers), but
> my guess was that idmapd was precisely intended to workaround this
> "limit".
>
>> Nope. You're not the first to make the same mistake, and the confusion
>> is a problem--I'm not quite sure what to do about it. But idmapd only
>> handles the names that are used when setting and getting acls or file
>> owners.
>
I noticed it surfing on the web... Maybe on CITI's website developer
should clarify this point, stressing it a little more (maybe a FAQ). The
main difficulty I encountered searching informations is that almost
everywhere people talks about "complex" setup (with Kerberos, LDAP,
...); of course is interesting to learn more, but sometimes one only
needs to share files on a home LAN with his (non IT-expert) friends...
>> ...
>> We have no choice but to use idmapd for nfsv4, because the NFSv4
>> protocol uses names for acls and owners, whereas we need uid's to do
>> anything on either end.
>
>> In other words, idmapd isn't adding some special new feature--it's
>> needed for basic NFSv4 functionality.
OK... It seems there is no hope to get what I want in a simple way. I
think I will relay on Samba/CIFS for Linux clients too (two Windows in
the LAN clients work well already).
>> If we also wanted to do id<->id mapping of auth_unix credentials, we'd
>> need a new mechanism for that.
Only for curiosity, it is so difficult to implement it? Did someone
thought about it when idmapd was implemented?
Thank you again.
More information about the NFSv4
mailing list