NFS share and groups


Login or Register for Dates, Times and to Reply

 
Thread Tools Search this Thread
# 1  
NFS share and groups

I am having an issue with getting the proper group settings on NFS-shared directories.
NFS server, NFServe, nfs-shares hundreds of project directories...running Solaris 10 latest patches/updates.
SAS server, SAServe, statistical analysis server running on RedHat 7 with latest kernel/patches/etc.

NFServe uses ancient Sun Directory Server for LDAP.
SAServe uses Active Directory on win2008r2. UIDs and GIDs set up matching on LDAP/Unix/AD (so if you are group ibex GID 5005 on LDAP, you are group 5005 on AD).

NFServe also nfs-shares project directories to an old SAS server also running Solaris 10 and all groups are correct.

On SAServe, all but six of the nfs-shared directories show the proper groups. However, on six of them, the group is nobody.

Does anyone have any suggestions where to look? I can't find the problem, and I can't find anything that makes these groups/directories unique.
# 2  
What do you mean by proper groups. What problem are you trying to solve?
# 3  
If I do an ls -l listing of the nfs-shared directories on the sas server they should show owner:group something like this
Code:
drwxrwx---     jbrown   dev       patches
drwxrws---     ssmith    prod     real_work

etc.

However, on six of several hundred directories (which have the correct group), it shows:

Code:
drwxrwx---   jbrown  nobody   document_files

when it should be:
Code:
drwxrwx---    jbrown  hrdept   document_files

So the problem is that the document_files directory, which should be jbrown:hrdept (and that's the way it is on the nfsserver) is showing up as jbrown:nobody and the only one who can access it is jbrown.

When I google this, I find instances where ALL directories are set to the group nobody, but I can't find anyone else who has just a couple set to nobody and all the others set properly.

Last edited by Scott; 03-02-2015 at 06:47 PM.. Reason: Please use code tags
# 4  
Go to each the directories and run df .
It gives you the export path on the NFS server.
A quick comparison is done with the inode number: ls -lid .
If they *are* identical then there is a problem with different GID-group mapping.
# 5  
I'm not sure that is clear, but

sasserver:
Code:
[root@srv-sas-01 acrn]# ls -lid .
7 drwxrwx--x 51 jsmith nobody 66 Oct 24 07:24 .

nfsserver:
Code:
root@fs  # ls -lid .
7 drwxrwx--x  51 jsmith prod     66 Oct 24 07:24 .

The share point is the top level, /projects and all of the directories fall beneath that.

Last edited by Scott; 03-02-2015 at 06:48 PM.. Reason: Please use code tags
# 6  
Ok, the inodes are identical.
Then you have different GID-group mapping.
Code:
ls -lin

shows UID GID. On each system map to group names with
Code:
getent group <GID>

On the system that is wrong,
how is group defined in nsswitch.conf?
Code:
grep group: /etc/nsswitch.conf

Do you have nscd running?
Code:
pgrep nscd && grep group /etc/nscd.conf

# 7  
I may be running afoul of the fact that unix can have the same name for a user and a group whereas that is not permitted in Active Directory. But that doesn't explain all of the cases.

Related to the nsswitch.conf question, obviously, on the nfsserver groups is files ldap and on the RH7 machine it's files sss.

Neither system runs nscd (solaris or rh). I inherited the S10 system, so I don't know why it was set up that way. I believe there are some reported issues running NSCD in conjunction with AD on RH, but I'd have to go back and re-research that.
Login or Register for Dates, Times and to Reply

Previous Thread | Next Thread
Thread Tools Search this Thread
Search this Thread:
Advanced Search

Test Your Knowledge in Computers #649
Difficulty: Easy
aterm is an rxvt based terminal emulator developed for Afterstep.
True or False?

10 More Discussions You Might Find Interesting

1. IP Networking

Unable to search NFS Share

My customer has created a share on a Windows Server 2012 system and exported it as a NFS share. I can mount the share on a SCO system, but I only have read/write access. So I am unable to list the contents of the share. It is as if the directories had 0666 permissions. My customer says that this... (5 Replies)
Discussion started by: jgt
5 Replies

2. Shell Programming and Scripting

Mount NFS Share On NFS Client via bash script.

I need a help of good people with effective bash script to mount nfs shared, By the way I did the searches, since i haven't found that someone wrote a script like this in the past, I'm sure it will serve more people. The scenario as follow: An NFS Client with Daily CRON , running bash script... (4 Replies)
Discussion started by: Brian.t
4 Replies

3. UNIX for Dummies Questions & Answers

Permissions for NFS share

Hi, I have created a NFS share in Solaris 10 server1 and mounted it on solaris 10 server 2.But I want to change owner of the files from nobody to a particular user in client. Which command should I use. I have tried the following but it doesn't allow to change permissions in the server2 as... (0 Replies)
Discussion started by: Rossdba
0 Replies

4. Red Hat

NFS share

Hi, I have an NFS server, i want to mount that nfs share which is having around 500GB to my client system. But my client system doesnt have any free space, is it possible to mount that nfs share in my client. Regards, Mastan (1 Reply)
Discussion started by: mastansaheb
1 Replies

5. Solaris

Solaris 10 NFS Share Issue

Hello all, I am having an issue with an NFS share I have created between two Solaris 10 boxes. I want the share to have read/write permissions, but for some reason it is coming up as read-only on the client side mount despite "rw" being specified in the mount options. Here is what I have... (6 Replies)
Discussion started by: fallersaur
6 Replies

6. Red Hat

How to Map AD groups to Samba share?

I am setup a samba share server which is authenticating from Active Directory. I am able to access the share with AD user but not able to access when group defined in "valid users" parameters. below are the steps i performed. In smb.conf workgroup = QASLABS password server =... (3 Replies)
Discussion started by: sunnysthakur
3 Replies

7. UNIX for Advanced & Expert Users

du and df do not match on NFS share

Here is the scenario... NFS share that is accessed every few minutes by approx 70 systems (AIX 5.3/6.1). Filesystem space is being eaten up rapidly according to df however du numbers really never change. lsof and fuser cannot see any unlinked files on either the NFS server or remote... (3 Replies)
Discussion started by: masterpengu
3 Replies

8. Linux

Secondary groups not working with NFS (+LDAP)

Im using LDAP for groups and NFS for home dirs. My problem is as follows: I only have a few groups, so it's not the problem everyone else had. When I've mounted a disk over NFS, I need to have my primary group in order to read in the groups I'm a member of. Secondary groups is not working. ... (0 Replies)
Discussion started by: velmont
0 Replies

9. Red Hat

NFS share error

I got a problem while creating files on a NFS mounted share in a RHEL box. That is when I create an empty file, this is what appears on the screen ############################################### E325: ATTENTION Found a swap file by the name ".test.swp" owned by: jsmith dated: Tue... (2 Replies)
Discussion started by: rcmrulzz
2 Replies

10. Solaris

NFS share options

Hello, I'm doing a Perl script to parse the dfstab file and find dangerous configurations (rw to everyone, root access, etc). My question is, if I have a share command like this: share -F nfs -o ro=chrome:copper:zinc,root=chrome /usr/man it means that the /usr/man is "rw" to everyone... (6 Replies)
Discussion started by: psimoes79
6 Replies

Featured Tech Videos