home.social

#nfsv4 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #nfsv4, aggregated by home.social.

fetched live
  1. #OpenBSD ei vieläkään tunnu tukevan #NFSv4:ää 😞 #NAS'sini sinänsä suostuisi toimimaan vaikka yhteyskäytännön kakkosversiolla, mutta olen asettanut sen vaatimaan nelosta. Harmillista. Ehkä teen paluun #FreeBSD:hen uudella asennuksella. #floss #bsd #atkjuttuja

  2. #OpenBSD ei vieläkään tunnu tukevan #NFSv4:ää 😞 #NAS'sini sinänsä suostuisi toimimaan vaikka yhteyskäytännön kakkosversiolla, mutta olen asettanut sen vaatimaan nelosta. Harmillista. Ehkä teen paluun #FreeBSD:hen uudella asennuksella. #floss #bsd #atkjuttuja

  3. Had to setup a NFS share and realized that I haven't done so since the Solaris 8 days.

    Good thing that my setup is for a trusted network.
    so quickly writing a /etc/exports and adding the correct line to the clients /etc/fstab don't forget to add a ,noauto there and done.

    ,nobootwait doesn't seem to be a thing anymore.

    I'm not looking forward to the Kerberos fuckery

    Oh and before anyone asks to get a NFS server running on Chimera Linux all you have to do is

    doas apk add nfs-utils-server-dinit
    doas dinictl nfs-utils-server-dinit
    #write your /etc/exports file
    doas exportfs -a

    #linux #nfs #nfsv4 #chimeralinux

  4. Had to setup a NFS share and realized that I haven't done so since the Solaris 8 days.

    Good thing that my setup is for a trusted network.
    so quickly writing a /etc/exports and adding the correct line to the clients /etc/fstab don't forget to add a ,noauto there and done.

    ,nobootwait doesn't seem to be a thing anymore.

    I'm not looking forward to the Kerberos fuckery

    Oh and before anyone asks to get a NFS server running on Chimera Linux all you have to do is

    doas apk add nfs-utils-server-dinit
    doas dinitctl enable nfs-server
    # write your /etc/exports file
    doas exportfs -a

    #linux #nfs #nfsv4 #chimeralinux

  5. Aaaaaargh, verdammte Hütte: Einfach NEED_IDMAPD=yes und NEED_GSSD=yes in /etc/defaults/nfs-common setzen und alles funzt. Steht's in den gängigen Wikis/Dokus? Nö. Uff. #NFSv4 #Kerberos

  6. I run on my home network of systems. It works perfectly well.

    I use to move from system to system and in the past was able to get to work as well between them.

    So far I've never been able to get NFS and Kerberos to work at the same time and this bugs me. I will have to try harder to make it work.

    I don't strictly need to make it work, all my systems are inside my firewall/NAT but it annoys me that I failed to make it work.

  7. NFSRODS v2.3.1 is released!

    github.com/irods/irods_client_

    This release updates dependencies so that NFSRODS is compatible with iRODS 5.

  8. auto-mounting isn't working.

    On one Debian 12 system the /etc/fstab stanza works and auto-mounts without a problem.

    On a pair of Debian 12 & 13 systems, the same /etc/fstab stanza doesn't work when connecting to a different server but does work with the same server as the first one.

    I thought that must mean the connection is a problem, but a manual issue of the mount, using the stanza in fstab command works perfectly.

  9. Got working over between an old and a box both running for a project.

    Now I've set one MacMini up, I need to set the rest up and the RaspberryPis so that we can organise software on them easily.

  10. 📊 New #Haiku development report - May 2025!

    A month focused on targeted improvements and stability:
    - HaikuDepot now more user-friendly for newcomers
    - Important Tracker and Terminal fixes
    - Major BUrl class rework with cleaner API
    - More stable #NFSv4 and #EXT4 drivers
    - #Wacom #Intuos4 support added

    Interesting milestone: 258 HaikuPorts commits vs 52 core system - shows growing maturity! 🚀

    Full report: desktoponfire.com/haikuos/soft

    #OpenSource #BeOS #HaikuOS #SoftwareDevelopment

  11. 📊 New #Haiku development report - May 2025!

    A month focused on targeted improvements and stability:
    - HaikuDepot now more user-friendly for newcomers
    - Important Tracker and Terminal fixes
    - Major BUrl class rework with cleaner API
    - More stable #NFSv4 and #EXT4 drivers
    - #Wacom #Intuos4 support added

    Interesting milestone: 258 HaikuPorts commits vs 52 core system - shows growing maturity! 🚀

    Full report: desktoponfire.com/haikuos/soft

    #OpenSource #BeOS #HaikuOS #SoftwareDevelopment

  12. Trying to get a box to make a mount on a box. I can see that NFsv4 is enabled and there is a share - but when I try to mount the share, I get an error from mount on and the Synology box vanishes from the net for several minutes...

    Strange.

  13. Trying to get a #Debian box to make a #NFSv4 mount on a #Synology box. I can see that NFsv4 is enabled and there is a share - but when I try to mount the share, I get an error from mount on #Linux and the Synology box vanishes from the net for several minutes...

    Strange.

  14. Been set a challenge to make which doesn't have on, accessible over the Internet.

    I think I'm going to use a VM in the cloud as my public Wireguard entry point and a Debian box inside the office to act as my relay, and then use IP tables rules to relay packets to and from the Synology NAS. I think it can all be done.

    Don't like but Windows doesn't speak .

  15. Been set a challenge to make #Synology #NAS which doesn't have #Wireguard on, accessible over the Internet.

    I think I'm going to use a #Debian VM in the cloud as my public Wireguard entry point and a Debian box inside the office to act as my relay, and then use IP tables rules to relay packets to and from the Synology NAS. I think it can all be done.

    Don't like #SMB but Windows doesn't speak #NFSv4.

  16. @le_friwi_56 I use Strawberry on a small PC next to my old Pioneer A-400X amp, driving old Mission 760SE speakers. The AV kit is over 30 years old and while good for it's price in it's day, it was never the best possible. But it works.

    I have all my music ripped to and then available via to any computer in the house, and also via a server.

  17. Mike @PerformantData ·

    Anyone have experience running an server on ?

    I'm not finding anything recent: a four-year-old Docker image, a six-year-old blog post,…

  18. Anyone have experience running an #NFSv4 server on #Kubernetes?

    I'm not finding anything recent: a four-year-old Docker image, a six-year-old blog post,…

  19. Has anyone successfully mounted on #macOS #NFS or #Samba shares hosted on a #FreeBSD server?

    If I use NFSv3, then all my shares are full of #AppleDouble files (i.e., with the "._" prefix).

    If I use #NFSv4, then "git fetch" just hangs forever and never finishes.

    If I use #Samba, then either 1) everything is 755 but I cannot delete files xD or 2) (after applying askubuntu.com/a/1126633/413683) the permissions are correct, but something is wrong with my .git: ad_convert: Failed to convert [.git].

    :(

  20. Has anyone successfully mounted on #macOS #NFS or #Samba shares hosted on a #FreeBSD server?

    If I use NFSv3, then all my shares are full of #AppleDouble files (i.e., with the "._" prefix).

    If I use #NFSv4, then "git fetch" just hangs forever and never finishes.

    If I use #Samba, then either 1) everything is 755 but I cannot delete files xD or 2) (after applying askubuntu.com/a/1126633/413683) the permissions are correct, but something is wrong with my .git: ad_convert: Failed to convert [.git].

    :(

  21. My desktop computer is 10 years old, and the CPU just isn't up to it anymore. I don't want a gaming system, but I don't want a overprices bottom of the range tat either.

    I need something that will run , drive a 4K screen, be fine for editing pictures in , and doesn't need much local storage, that's what 1Gig and is for.

    Some of the small form factor PCs looks sensible, e.g. Bee-Link. Suggestions?

  22. @photocyte ah yes, hashtags, forgot about those.

    so, `mount` is setuid and mounting a filesystem as not-root is a totally acceptable and normal thing to be able to do, and the code is nominally set up to do it but it looks a heck of a lot like /[gs]ete?uid/ is being called in lieu of its counterpart, because the net effect is root needs a copy of the non-root user's kerberos ticket as well for it to work, which is SUPER annoying for e.g. ticket renewal

    #nfs #nfs4 #nfsv4 #kerberos #krb5

  23. @photocyte ah yes, hashtags, forgot about those.

    so, `mount` is setuid and mounting a filesystem as not-root is a totally acceptable and normal thing to be able to do, and the code is nominally set up to do it but it looks a heck of a lot like /[gs]ete?uid/ is being called in lieu of its counterpart, because the net effect is root needs a copy of the non-root user's kerberos ticket as well for it to work, which is SUPER annoying for e.g. ticket renewal

    #nfs #nfs4 #nfsv4 #kerberos #krb5

  24. @TomAoki @peteorrall @hl @xdydx I'm surprised ... I didn't expect this to come up in the "enterprise" realm, "just" using kerberized #NFSv4 instead should be pretty fine there and it's probably more the #soho environment that will profit most from some up-to-date #smb client in #FreeBSD 😎 ... but would certainly be very nice to get that!

    Also interesting they finally want to move to #MIT #krb5 in base. I'll probably continue to build it from ports, so I can use #LibreSSL instead of #OpenSSL, but still nice, as I found you're e.g. forced to use base #kerberos with the NFS client.

  25. @TomAoki @[email protected] @hl @xdydx I'm surprised ... I didn't expect this to come up in the "enterprise" realm, "just" using kerberized instead should be pretty fine there and it's probably more the environment that will profit most from some up-to-date client in 😎 ... but would certainly be very nice to get that!

    Also interesting they finally want to move to in base. I'll probably continue to build it from ports, so I can use instead of , but still nice, as I found you're e.g. forced to use base with the NFS client.

  26. @hl @xdydx #FreeBSD has only support for SMBv1, which you should absolutely avoid for security reasons, although you can probably configure #samba to still allow it ... but ... don't. Nowadays I'd prefer to say FreeBSD does not support mounting SMB shares.

    There are some ports available implementing "modern" SMB (v2/v3) on top of #fuse, which might be an option, but in my experience, they're not perfectly reliable and performance isn't the greatest either.

    If ever possible, work on the server side and see whether you can share via #NFS instead. Either #NFSv3 (which is only "secure" as long as your network is perfectly secure and you control all participating machines, but at least it doesn't pretend to do anything else), or #NFSv4 with #kerberos security.

  27. @hl @xdydx has only support for SMBv1, which you should absolutely avoid for security reasons, although you can probably configure to still allow it ... but ... don't. Nowadays I'd prefer to say FreeBSD does not support mounting SMB shares.

    There are some ports available implementing "modern" SMB (v2/v3) on top of , which might be an option, but in my experience, they're not perfectly reliable and performance isn't the greatest either.

    If ever possible, work on the server side and see whether you can share via instead. Either (which is only "secure" as long as your network is perfectly secure and you control all participating machines, but at least it doesn't pretend to do anything else), or with security.

  28. @drscriptt I'll just dump my understanding of the issue with #kerberos, #nfsv4 and #samba (or #ActiveDirectory) now on here, so if you know better, please correct me 😉

    A kerberized service needs an SPN to prove its identity towards clients. This SPN can be attached to any account, it's just best practice to have a dedicated service account. For nfs, it must be named "nfs/<host.fqdn>". The key for this SPN must be available to the server, that's why you have to export it and add it to /etc/krb5.keytab on the server.

    To access the service, you need a "service ticket" for its SPN. This can be obtained with your kerberos TGT (ticket-granting ticket). In case of NFS, this is also needed for mounting. And here's the issue with system-wide mounts, there's no user logged into the domain, so you need a "host-based initiator". Basically a key present in the host's /etc/krb5.keytab that's used for the kinit procedure.

    [...]

  29. @drscriptt I'll just dump my understanding of the issue with , and (or ) now on here, so if you know better, please correct me 😉

    A kerberized service needs an SPN to prove its identity towards clients. This SPN can be attached to any account, it's just best practice to have a dedicated service account. For nfs, it must be named "nfs/<host.fqdn>". The key for this SPN must be available to the server, that's why you have to export it and add it to /etc/krb5.keytab on the server.

    To access the service, you need a "service ticket" for its SPN. This can be obtained with your kerberos TGT (ticket-granting ticket). In case of NFS, this is also needed for mounting. And here's the issue with system-wide mounts, there's no user logged into the domain, so you need a "host-based initiator". Basically a key present in the host's /etc/krb5.keytab that's used for the kinit procedure.

    [...]

  30. @drscriptt I'm still doing a lot of testing and I guess I now finally have a somewhat good understanding what's going on.

    With a samba (Windows AD) domain, you should

    * create a service account for the nfs-server and create the nfs SPN in that account, export keytab entries for just that SPN and add them to /etc/krb5.keytab on the NFS server

    * set the "host" SPN as UPN on all machine accounts that are NFS clients, including the realm in the UPN, which enables the host-based initiator to work (authenticating as the machine account) for the system-wide mount

    I'll try to write that down in some howto soon, #jailed #nfsv4 with #kerberos on #FreeBSD and a #samba domain...

    I guess it won't necessarily apply to a directory managed in OpenLDAP though ... 😶

  31. @drscriptt I'm still doing a lot of testing and I guess I now finally have a somewhat good understanding what's going on.

    With a samba (Windows AD) domain, you should

    * create a service account for the nfs-server and create the nfs SPN in that account, export keytab entries for just that SPN and add them to /etc/krb5.keytab on the NFS server

    * set the "host" SPN as UPN on all machine accounts that are NFS clients, including the realm in the UPN, which enables the host-based initiator to work (authenticating as the machine account) for the system-wide mount

    I'll try to write that down in some howto soon, with on and a domain...

    I guess it won't necessarily apply to a directory managed in OpenLDAP though ... 😶

  32. Impatiently waiting for my #ZFS backup to complete ...

    Then the next step will be to test #jailed #NFS (as introduced in #FreeBSD 13.3), to finally replace my horrible hack of redirecting NFS-related traffic with #pf (and, therefore, punching a hole for LAN machines to access the physical host located in the management segment).

    I hope to also move to #nfsv4 at the same time. And once *this* works, enable #krb5 auth and encryption. We will see 😎

  33. Impatiently waiting for my backup to complete ...

    Then the next step will be to test (as introduced in 13.3), to finally replace my horrible hack of redirecting NFS-related traffic with (and, therefore, punching a hole for LAN machines to access the physical host located in the management segment).

    I hope to also move to at the same time. And once *this* works, enable auth and encryption. We will see 😎

  34. Having a real battle getting posix permissions to behave as expected on #truenas_scale . Considering starting over with #nfsv4 rather than #posix. Is there any compelling reason to use posix ACLs or avoid nfsv4?

  35. Having a real battle getting posix permissions to behave as expected on #truenas_scale . Considering starting over with #nfsv4 rather than #posix. Is there any compelling reason to use posix ACLs or avoid nfsv4?

  36. Ok, tech mastodon, anyone here have some serious kung-fu around #nfsv4 on #macos?

    I've got a file server running #debian, it's exporting a directory via #nfs4 and I have a mac that can mount that directory. A user on the mac has the same username as a user on the server, and the /etc/nfs.conf settings map that successfully.

    Doing shell commands like cp and echo foo > file and such works fine. But copying files in finder or trying to open or save word docs etc borks.

  37. Switched my wife to #Kerberized #NFSv4, her new Mac laptop required about 3 lines of config, and she can connect encrypted over the internet immediately. It's dramatically faster than SMB. SMB has always been trash, and people only use it because it's the only thing #Windows supports. It got encryption around what 2013? NFSv4 is defined in #IETF RFCs dating back to 2000.