NFS exports and the mandatory no_root_squash

We are running a SUSE11/OES11 cluster serving NSS volumes as NCP, NFS and AFP. Is the only feasible workaround for the NFS no_root_squash requirement to firewall the mountd port?
If so will having a list of 1,000+ IP numbers in the allow list for mountd have a significant impact on the cluster nodes? Unfortunately on our University class B IPv4 site the allocated IP addresses are scattered and the subset of PCs controlled by technicians (and therefore 'trusted') are not contiguous and neatly arranged.

There is another workaround to the "no_root_squash" requirement. The below is taken from TID: Support | OES: Compatibility issues between NSS and NFS
2. no_root_squash: Officially, this is mandatory, so care should be taken to limit what hosts can mount the export (as the root user of the NFS client host will be able to act as the root user on the NSS exported path).
However, due to potential security concerns with allowing root access, some administrators chose to set this up in another way. This alternative way is thus far considered experimental, and not thoroughly tested: It seems that the key requirement here is that the user who is requesting the mount (typically root) have at least Filescan rights to the NSS volume. If root is "squashed" he is treated like "nobody." Typically, "nobody" does not have access, neither through its own merits nor by being associated with any LUM-enabled user in eDir. However, an eDir user can be created and LUM-enabled, given Filescan right to the NSS volume(s), and then the UID assigned to that user can be used as the "anonuid" for that particular export. So, for example, if the user in question was given UID 1011, then instead of "no_root_squash" the combination of "root_squash,anonuid=1011" could be used.
In that case, be sure to remember that even after mount, "squashed root user" will be treated as having whatever rights the anonuid user has been given. Also remember that if you use the "all_squash" parameter as well, all NFS client users (not just eDir users and not just root) will be treated as the anonuid user, and will be able to access the NSS volume.
On the other subject: I do not know the potential impact of 1000+ IP numbers in an allow list for mountd.
Darcy

Similar Messages

  • After upgrading to Mavericks, all of my contacts disappeared. Did a "contacts archive" export and the file is 17mbs. Looks like there's data, but none of it at all displays. What gives? 20" iMac, early '09

    After upgrading to Mavericks, all of my contacts disappeared. Did a "contacts archive" export and the file is 17mbs. Looks like there's data, but none of it at all displays. What gives? 20" iMac, early '09

    After upgrading to Mavericks, all of my contacts disappeared. Did a "contacts archive" export and the file is 17mbs. Looks like there's data, but none of it at all displays. What gives? 20" iMac, early '09

  • Questions on exporting and the trash folder?

    A friend has i Photo 5 on here iMac (older) and I was trying to copy some of the pictures out of the Trash folder, it wouldn't do it. Well it would copy the file number but it would read zero kilobites. Not sure why this happening, but even in the trash folder it was saying how large each picture was. So I moved them back into the Libary folder and you could view them small version but couldn't enlarge them etc.. I tried to copying them and got the same result, says the information is there but if you try to open the pictures in "picture viewer" or import them into another iPhoto folder you get an error reading. The only thing I can think of is trying to download her whole iPhoto file and then going from there. Any suggestions? Thanks, looks like these where taken with a Cannon Powershot 3 series, camera is about a year old.

    If you fooled around with the folders in finder, you might have done a slight amount of damage to the iPhoto library... if not you can try rebuilding the library:
    Hold down the Option and Command (Apple) Keys and open iPhoto, a window should appear asking if you would like to rebuild etc., check them all... hopefully this will get the library working again.
    If you're only going to copy a few pics, you can drag them out of iphoto to your desktop and then into whatever device you're using to save into. Or you can export the photos using the share > export function...
    You can also copy the entire iPhoto library to an external and open that library in your copy of iPhoto...
    Rick
    iMac G5 iSight 20" - 30G iPOD in Slimming Black - Mac OS X (10.4.7) - HP Pav 15" WS and Toshiba Sat 17" WS LP's - Canon 20D & A620

  • I Paid for PDF Export and the files are not converting correctly

    I purchased PDF Export to take a PDF file and convert it to a text file so I could import it into excel, when doing so I get a bunch of extra symbles plus the numbers that i'm trying to convert are not complete.

    Could you try disabling the 'Recognize text' function and convert the file again?
    Let us know how it goes!
    -David

  • OS X extern drive ownership/permissions and NFS exporting

    - I have an external (250GB) firewire drive on OS X 10.4.9.
    - I want to have it available to local users of this Mac but with ownership/permissions of created files/directories protected in the usual UNIX sense of unique UID/GID -- files/directories created by one user cannot be read/written by other users of this Mac except as allowed by standard UNIX permissions groups settings; eg., those set with 'chmod' command.
    - I want to NFS-server this drive volume to a linux NFS client (eg., RHEL 4), again with files/directories protected in this same UID/GID UNIX sense. In our case, the users' UID/GIDs will be made to match, but regardless, I wish likewise for file/directory use on the linux client to be restricted as per UNIX permissions and the files/directories created by the Mac users have protections remain in place against linux user access, and visa versa, as above.
    Is this feasable in Mac OS X (without OS X Server)?
    How does one go about acheiving it?
    I have basic Netinfo Manager skills for creating NFS exports and starting NFS daemon services, but am not expert on all available export options. I have average linux IT NFS server/client and user management skills.
    Thanks,
    -Neil

    I don't know about networking with Linux, but I don know that for OS X users, enforcing permissions on an external drive without OS X Server is tricky.
    First, log in to your admin account. Right-click the drive, Get Info, expand Ownership & Permissions, and uncheck "Ignore ownership on this volume". Then set permissions accordingly.
    The problem is that any unprivileged user can log in to his own account, Get Info, recheck the box, and get ownership of the entire contents of the drive. This is possible even without the admin password.
    There is a workaround that will remove the Ignore Ownership box from the Get Info panel so that there will be no box for them to check. First make sure that the box is unchecked and that the permissions are set how you want. Then enable ACLs on the volume by entering this command in a Terminal window:
    sudo fsaclctl -p /Volumes/volumename -e
    Then restart Finder. Now there's no box for the unprivileged user to check. But I don't know where this setting is stored; perhaps the unprivileged user can find some command-line way of getting the box re-checked and thus getting ownership of everything.
    If there is some way you can get the data off of the external drive and onto the main boot drive you will have the best chance of keeping the data safe.

  • "Offline material is present in this export and will be encoded using the offline media graphic"

    This comes up every so often with my renders.  I have a 28:30 minute project that is 100% complete.  All the files are present locally, and nothing shows as offline or missing.  I've gone through the final sequence frame by frame and NOTHING is offline or missing.  But when I want to send it out to export, I get the message above in the title.
    What's strage is if I ignore it, then sometimes the final render WILL have display the offline graphic even though it didn't display as such in the Premiere timeline.
    Often, restarting Premiere and reopening the project irons that glitch out just fine, but I have one particular project that seems to do it every time. I've tried the "import into a new project" trick, but with no luck.
    Clueless in Exportville

    Hey Guys,
    Anybody find a solution to this yet? I am working with Premiere Pro cs5, working with r3d footage, and am having the "offline material is present" error pop up when I try to export using adobe media encoder. Prior to that error box popping up, there is another dialogue box that says that premiere has detected that there is an update to media encoder, I am running media encoder 5.01 and tried to update it but it tells me all files are up to date.
    Anyways back to the problem, there is only one shot that is affected and is rendered with the offline media image( this clip also happens to be a different colour(green or teal) than the other clips in my sequence(which are blue or greyish), not sure if this is an indication of anything. I reimported the clip, and re did the edits and then exported just that new small section to see if the error would happen again,this time however, when I did the export, instead of  "queue", I just hit "export" ,and the export happened without media encoder actually opening. The file came out fine,even though I had the offline media present pop up, the video was all good. I know I changed a couple of variables in that troubleshooting, so now I am trying the entire sequence with the "export" button instead of "queue" button in the media encoder pop up box, hopefully that will help. The only downside is that it seams like it takes way longer to export this way than in the queue.
    I'll report back to let you know if that helps and if I can reproduce the error with the "queue" button.
    EDIT
    Both exports worked, so it must have been due to the re importing and re editing of the clips, however I still get the error message "offline material is present..." I guess I'll see what happens next time I do an export. Cross my fingers.

  • Discover Plus - Export to Text Tab delimited is not exporting all the rows

    Hi gurus,
    I am trying to export a large data report which has 1 million plus rows to text tab delimited. The export takes 9 plus hours to export and the data is not more than 100000.
    My question is
    1. How can I make the discoverer to export it quicker or rather faster to tab delimited.
    2. Where can I change the number of rows to be exported.
    Any help, suggestions is appreciated.
    Thanks,
    SAI

    Hi Rod,
    Yes. The text tab delimited export is taking lot of time. The total rows for this report are nearly 1 million. If I break down the report with condition and export it I was able to export it ( three files exported with 212000, 103000 and 687000 rows respectively).
    But I m still having problems exporting it in one shot. Is there any way I could resolve this? Please let me know.
    Thanks,
    SAI

  • Solaris 10 NFS client and readdir

    I have a Solaris 10 u5 client that mounts a directory using NFS from a Mac OS X server. The mount works fine and programs and tools such as /bin/ls, etc work ok. However, several programs that I have that use the readdir (or readdir_r) library calls never return lists of files from this NFS mounted directory (point these programs at a ufs/zfs file system and all works fine). I created a simple test using readdir and it happens in that as well. The only thing that it will find/list is the "." and the ".." directories for anything in the NFS mounted name space.
    I found a reference to the nfs:nfs3_shrinkreaddir and the nfs:nfs_shrinkreaddir solaris tunable parameters and placed them both in the /etc/system file and rebooted, but it did not change the behavior. I also tried setting the nfs:nfs_disable_rddir_cache=1 and related entities to no avail.
    I also noticed that tar was dumping core reading this directory, but have found a patch for tar to fix this. It did not include any guidance on nfs parameters for Mac OS X or similar NFS v3 servers.
    Is there some set of NFS settings that I can make that will enable this Solaris client to mount the file system and be able to actually read the directories and files?

    I believe I have found my problem. Turns out that it appears to be only remotely related to NFS. The application I have is built for 32 bits and the O/S is an i386/x64 system. Apparently, readdir fails when it gets an "nfs" inode when it is built in 32 bit mode - works fine when compiled with -m64. So now I need to track down some x64 builds of the failing packages.

  • Export and then import those images in one step?

    I'm slightly annoyed that every time I want to use the export function to create jpeg versions of images, I then have to do the extra step of importing those jpegs into my catalog. Is there some way to do this in one step?
    If I need .tiff's of .psd's, I just use the edit in photoshop function, because that has the option to automatically stack with original, but there is no option that I can find for other formats.
    Thanks

    Right, then until 2.0 comes out, I'll try the watched folder idea that John suggests. Yea, I was talking about raw files, but also psds or really any "digital neg".
    As for the workflow import-process-export, and the final product not needing to be re-imported because it theoretically needs no more processing, this would be fine if one used lightroom to organize digital negs and bridge to organize absolutely everything, including final versions for various media, but I'm glad that adobe has realized that at least some of us use are trying to use lightroom without opening bridge a lot of the time. Although I haven't even tried using bridge that much, maybe there are advantages over lightroom as a central depository.

  • Title issues when exported and re-open FCP X

    Every time I create a title box and change the words I export and I get "Title" again. All my work is lost.  For example, it might say "Project Management" in a title text box, and I work on the project all day and then export and the video appears as "Title" and is no longer the size, this also happens when I leave for the day and open FCP back up and I have lost all my text. This is really frustrating I have deadliens to meet not spending all day trying to fix a problem that is now mine.  Please tell me why FCP is doing this? I need some help! I have tried everything I can think of.

    cmuunswcanberra wrote:
    It has happened once in another project but I was able to re-type into it and it worked.
    So it sounds as though it may be the project.
    Try this.
    Delete preference files with Preference Manager.
    Delete project ender files.
    Create a new project.
    Copy the problem project and paste into the new project.
    Test a title.
    Good luck.
    Russ

  • Systemd and nfs exports [solved]

    I recently switched my server over to systemd and now I cannot connect to the NFS share that it is exporting.
    Here is the entry in the /etc/fstab on the server:
    /dev/sdb1 /media/media ext4 defaults,noatime 0 1
    /media/media /nfs4exports/media none rw,bind 0 0
    Here is the /etc/systemd/system/media-media.mount :
    [Unit]
    Description=media
    Wants=network.target rpc-statd.service
    After=network.target rpc-statd.service
    [Mount]
    What=/media/media
    Where=/nfs4exports/media
    Type=nfs
    StandardOutput=syslog
    StandardError=syslog
    When I connect it from my workstation, the mount command just hangs:
    # mount -t nfs mars:/media /media/media
    Help
    Last edited by graysky (2012-05-10 17:01:08)

    The solution is NOT to create this file at all.  Apparently, exports from the server do not require them.  If I remove it and reboot the server, I am able to connect from my workstation with no issues.  For reference:
    $ ls -l /etc/systemd/system/multi-user.target.wants/
    total 0
    lrwxrwxrwx 1 root root 40 May 10 10:58 cpupower.service -> /usr/lib/systemd/system/cpupower.service
    lrwxrwxrwx 1 root root 38 May 10 10:58 cronie.service -> /usr/lib/systemd/system/cronie.service
    lrwxrwxrwx 1 root root 40 May 10 12:10 exportfs.service -> /usr/lib/systemd/system/exportfs.service
    lrwxrwxrwx 1 root root 42 May 10 10:59 lm_sensors.service -> /usr/lib/systemd/system/lm_sensors.service
    lrwxrwxrwx 1 root root 35 Apr 30 15:15 network.service -> /etc/systemd/system/network.service
    lrwxrwxrwx 1 root root 36 May 10 10:59 ntpd.service -> /usr/lib/systemd/system/ntpd.service
    lrwxrwxrwx 1 root root 36 May 10 11:33 rc-local.service -> /etc/systemd/system/rc-local.service
    lrwxrwxrwx 1 root root 40 May 2 22:37 remote-fs.target -> /usr/lib/systemd/system/remote-fs.target
    lrwxrwxrwx 1 root root 39 May 10 10:58 rpcbind.service -> /usr/lib/systemd/system/rpcbind.service
    lrwxrwxrwx 1 root root 42 May 10 12:10 rpc-mountd.service -> /usr/lib/systemd/system/rpc-mountd.service
    lrwxrwxrwx 1 root root 41 May 10 12:10 rpc-statd.service -> /usr/lib/systemd/system/rpc-statd.service
    lrwxrwxrwx 1 root root 43 May 10 10:58 sshdgenkeys.service -> /usr/lib/systemd/system/sshdgenkeys.service
    lrwxrwxrwx 1 root root 36 May 10 10:58 sshd.service -> /usr/lib/systemd/system/sshd.service
    lrwxrwxrwx 1 root root 41 May 10 11:06 syslog-ng.service -> /usr/lib/systemd/system/syslog-ng.service
    lrwxrwxrwx 1 root root 35 May 10 10:57 ufw.service -> /usr/lib/systemd/system/ufw.service

  • I am using Iphoto 11 ver 9.4.3 on mac using oxs 10.8.5 i want to export calendar projects to an external hard drive. what is the easiest way to do this? i have tried export and import but it didn't seem to work.

    I am using Iphoto 11 ver 9.4.3 on mac using oxs 10.8.5 i want to export calendar projects to an external hard drive. my goal is to store them in an external hard drive so it doesn't use up memory on the mac hard drive. is it possible to copy the specific projects without copying the entire library? what is the easiest way to do this? i have tried export and import but it didn't seem to work.

    What do you not understand?
    You can duplicate the iPhoto library (command - D ) and delete everything except the project and its photos from the copy and move that
    Or
    However the calendar takes very little space - it is simpy database entries - it is the photos in the calendar that take space - and for most people you would wnat to keep those photos in your library
    you can use a photo in 50 calendars and it still is only one photo in your library - as I explained calenders do not exist as such - they are simply database entries telling iPhotop how to display the calendar - they take almost no space at all
    LN

  • Exporting from InDesign to PDF, and the updated PDF is larger than a month ago and not printing easily on letter paper, it is PDF presets?

    Hello,
    I am exporting from InDesign to a PDF and the page is larger in the PDF then others I have exported. Is this because of the PDF presents? One of the project managers is not able to print it out on 8.5 x 11 paper, but the document presets for InDesign are the same as before. I wish I could upload the PDFs to show, but the newly exported PDF is larger than the version I created a month ago. I created a PDF binder and the newly updated PDF is almost a .5 inch wider with the same export presets. Any thoughts?

    Sadira00123456789 wrote:
    One of the project managers is not able to print it out on 8.5 x 11 paper, but the document presets for InDesign are the same as before.
    I suspect the project manager simply has his/her copy of Reader/Acrobat set to print at actual size, rather than "Fit" (assuming the InDesign page size is truly 8.5 x 11).
    ..the newly updated PDF is almost a .5 inch wider with the same export presets.
    It would have nothing to do with export presets. How are you determining that half-inch difference?

  • Print, Export and Page Navigation Buttons in the Report

    When I view a report through CR4E, the generated report has 3 buttons namely Print, Export and Page Navigation buttons. But when I click on either of the buttons I get a 'null pointer exception'. This is a critical error as I am unable to navigate past the first page. Do I have to add code to these buttons? If not, why am I getting an error? Kindly solve my problem as soon as possible.

    <p>Looking at your code it appears that you are storing the ReportSource in session prior to passing in the ResultSet. This will create a problem when a postback is made on  the viewer page (which all of the viewer actions do). If you look at the sample code which is generated when you use the JSP Page Wizard you will notice that the ResultSet is passed to the ReportClientDocument object prior to it being stored in session. Then, when the page is called again this object is retrieved and the ReportSource is used by the viewer. You can quickly run the test using one of our sample reports to see what I am talking about. The code below was generated using the Consolidated Balance Sheet.rpt and did not experience any problems doing any of the viewer actions.</p><%@page import="com.businessobjects.samples.JRCHelperSample,<br />com.crystaldecisions.report.web.viewer.CrystalReportViewer,<br />com.crystaldecisions.reports.sdk.ReportClientDocument,<br />com.crystaldecisions.sdk.occa.report.application.OpenReportOptions,<br />com.crystaldecisions.sdk.occa.report.lib.ReportSDKExceptionBase,<br />com.crystaldecisions.sdk.occa.report.reportsource.IReportSource,<br />java.sql.Connection,<br />java.sql.DriverManager,<br />java.sql.ResultSet,<br />java.sql.SQLException,<br />java.sql.Statement"%><%<br /><br /><br />    try {<br /><br />        String reportName = "Sample Reports/Consolidated Balance Sheet.rpt";<br />        ReportClientDocument clientDoc = (ReportClientDocument) session.getAttribute(reportName);<br /><br />        if (clientDoc == null) {<br /><br />            clientDoc = new ReportClientDocument();<br />            <br />            // Open report<br />            clientDoc.open(reportName, OpenReportOptions._openAsReadOnly);<br /><br />  <br />            {<br />                // **** POPULATE MAIN REPORT ****<br />                {<br />                     // Connection Info for fetching the resultSet<br />                    String connectStr = "jdbc:derby:classpath:/Xtreme";<br />                    String driverName = "org.apache.derby.jdbc.EmbeddedDriver";<br />                    String userName = "dbuser";        // TODO: Fill in database user<br />                    String password = "dbpassword";    // TODO: Fill in valid password<br /><br />                    String query = "SELECT CUSTOMER_NAME FROM APP.CUSTOMER WHERE COUNTRY = &#39;Australia&#39;";<br /><br />                    <br />                    String tableAlias = "FINANCIALS";        // TODO: Change to correct table alias<br /><br />                     <br />                    JRCHelperSample.passResultSet(clientDoc, fetchResultSet(driverName, connectStr, userName, password, query),<br />                        tableAlias, "");<br />                }<br /><br /><br />            }<br />        <br />            // Store the report document in session<br />            session.setAttribute(reportName, clientDoc);<br /><br />        }<br /><br /><br />            {<br />                // Create the CrystalReportViewer object<br />                CrystalReportViewer crystalReportPageViewer = new CrystalReportViewer();<br /><br />                //    set the reportsource property of the viewer<br />                IReportSource reportSource = clientDoc.getReportSource();                <br />                crystalReportPageViewer.setReportSource(reportSource);<br /><br />                // set viewer attributes<br />                crystalReportPageViewer.setOwnPage(true);<br />                crystalReportPageViewer.setOwnForm(true);<br /><br />                // Process the report<br />                crystalReportPageViewer.processHttpRequest(request, response, application, null); <br /><br />            }<br />            <br /><br />    } catch (ReportSDKExceptionBase e) {<br />        out.println(e);<br />    } <br />    <br />%><%!<br />// Simple utility function for obtaining result sets that will be pushed into the report.  <br />// This is just standard querying of a Java result set and does NOT involve any <br />// Crystal JRC SDK functions. <br /><br />    private static ResultSet fetchResultSet(String driverName,<br />            String connectStr, String userName, String password, String query) throws SQLException, ClassNotFoundException {<br /><br />        //Load JDBC driver for the database that will be queried    <br />        Class.forName(driverName);<br /><br />        Connection connection = DriverManager.getConnection(connectStr, userName, password);<br />        Statement statement = connection.createStatement(ResultSet.TYPE_SCROLL_INSENSITIVE, ResultSet.CONCUR_READ_ONLY);<br /><br />        //Execute query and return result sets<br />        return statement.executeQuery(query);<br /><br />}%><p>Try using the code generated from the wizard to see if it works for you as well. </p><p>Regards,<br />Sean Johnson (CR4E Product Manager) </p>

  • I just purchased Export PDF, and when I use it, it opens them in WordPad (which I never use) instead of Word. Thus, the pictures are not there, and the fonts are changed. How do I get into Word?

    I just purchased Export PDF, and when I use it, it opens them in WordPad (which I never use) instead of Word. Thus, the pictures are not there, and the fonts are changed. How do I get them imported into Word?

    Hi,
    I checked your account,your Export PDF subscription is in 'Pending' status.
    Once it gets confirmed you will be able to use it.
    Please let us know if you require further assistance.
    Regards,
    Florence

Maybe you are looking for

  • How to mantain imension members

    Hello there, I need add new member in a dimension account. i run a import pkg, if any member into csv file there isn´t in dimension, i need impot this mmber automaticaly, how can i do it? Thanks,

  • User Exit - MIRO (TX)

    Hi, Well , in this oportunity , I'm looking for a user exit which is called after I save information in  MIRO TX, besides,  The User Exit should recieve information like document header  and all their positions. Can anybody help me ?

  • Restore in other instance

    Hi all. I want testing my backups. Testing will be in restore backups into other copy of SAP instance. for example: 1. I have instance with name SID1. and backup on tape                    2. Create new_zone in Solaris                    3. Copy orac

  • LAYERS PRINTING WITH Internet Explorer

    Hi. I made a webpage in Dreamweaver 8. I have 2 tables on top of each other so I wanted to make a layer behind them 2, so I can have a graphic in the background. This graphic does not print well from IE. It overlaps the tables when I try to scale the

  • 2 month old iMac, crashes during boot

    Yesterday I received an automatic software update. Today it crashes during boot up. This is what I see: panic (cpu 0 caller 0x003AA827) Unable to find driver for this platform: "ACPI" Debugger called: <panic> .... then it spits out a bunch of hex cod