rpc.gssd(8) System Manager's Manual rpc.gssd(8) rpc.gssd - RPCSEC_GSS rpc.gssd [-DfMnlvrHC] [-k keytab] [-p pipefsdir] [-d ccachedir] [-t timeout] [-T timeout] [-U timeout] [-R realm] RPCSEC_GSS RFC 5403 RPC NFS. RPC RPCSEC_GSS RPC GSS. GSS-API. . . kinit(1) PAM . ( kerberos(1) ). . . keytab. . . GSS RPC rpc.gssd. rpc.gssd rpc_pipefs . kinit(1) UID . NFS Kerberos RPC rpc.gssd . /tmp. rpc.gssd . -d . rpc.gssd keytab /etc/krb5.keytab . rpc.gssd Kerberos. $@ root/@ nfs/@ host/@ root/@ nfs/<_>@ host/@ rpc.gssd DHCP . keytab . . $@ NFS Kerberos Active Directory Samba. keytab . keytab -k /etc/krb5.keytab . UID 0 UID 0 . rpc.gssd UID 0 GSS. . -n rpc.gssd . -n GSS NFSv4 SETCLIENTID RENEW . rpc.gssd ( keytab) NFSv4 . keytab . / aes256-cts-hmac-sha384-192 aes128-cts-hmac-sha256-128 aes256-cts-hmac-sha1-96 aes128-cts-hmac-sha1-96. rpc.gssd NFS . -D GSSAPI . NFS "servername:/path". IP (IPv4 IPv6) ( ) DNS . -D DNS . . -D -D . -f rpc.gssd stderr ( syslogd) -n UID 0 . -k keytab rpc.gssd keytab . /etc/krb5.keytab. -p path rpc.gssd rpc_pipefs. /var/lib/nfs/rpc_pipefs. -d search-path rpc.gssd . /tmp:/run/user/%U. "%U" UID . -M ( -d). -M rpc.gssd . -v ( ). -r RPCSEC_GSS ( ). -R realm Kerberos . Kerberos. -t _ GSS . Kerberos . Kerberos . -T timeout RPC gss . 5 . "WARNING: can't create tcp rpc_clnt to server %servername% for user with uid %uid%: RPC: Remote system error - Connection timed out" . -U timeout . . 30 . 5 . 600 . -C -ETIMEDOUT . -H $HOME "/". rpc.gssd k5identity /.k5identity . -H rpc.gssd /var/kerberos/krb5/user/$EUID/client.keytab (principal) / $HOME/.k5identity. [gssd] /etc/nfs.conf. : verbosity -v. rpc-verbosity -r. use-memcache -M. use-machine-creds . false -n. avoid-dns false -D. allowed-enctypes rpc.gssd krb5. NFS SHA2 Camellia . . context-timeout -t. rpc-timeout -T. keytab-file -k. cred-cache-directory -d. preferred-realm -R. upcall-timeout -U. cancel-timed-out-upcalls true -C. set-home false -H. use-gss-proxy 1 gssproxy(8) GSSAPI rpc.gssd keytab. gssproxy(8) NFS. https://github.com/gssapi/gssproxy/blob/main/docs/NFS.md#nfs-client. [general]: pipefs-directory -p. rpc.svcgssd(8) kerberos(1) kinit(1) krb5.conf(5) gssproxy(8) Dug Song . (J. Bruce Fields) 3 . . : . 20 2013 rpc.gssd(8)