Path: csiph.com!weretis.net!feeder8.news.weretis.net!news.samoylyk.net!gothmog.csi.it!bofh.it!news.nic.it!robomod From: "Tyler W. Ross" Newsgroups: linux.debian.bugs.dist,linux.kernel,linux.debian.kernel Subject: Bug#1120598: ls input/output error ("NFS: readdir(/) returns -5") on krb5 NFSv4 client using SHA2 Date: Wed, 19 Nov 2025 00:50:01 +0100 Message-ID: References: X-Original-To: Scott Mayhew X-Mailbox-Line: From debian-bugs-dist-request@lists.debian.org Tue Nov 18 23:45:09 2025 Old-Return-Path: X-Spam-Flag: NO X-Spam-Score: -2.399 Reply-To: "Tyler W. Ross" , 1120598@bugs.debian.org Resent-To: debian-bugs-dist@lists.debian.org Resent-Cc: debian-kernel@lists.debian.org X-Debian-Pr-Message: followup 1120598 X-Debian-Pr-Package: src:linux X-Debian-Pr-Keywords: upstream X-Debian-Pr-Source: linux Feedback-ID: 101639484:user:proton X-Pm-Message-ID: 62ff09ffe1ef4c6c0b9b55182eac4e6f57851e90 MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable X-Greylist: delayed 70396 seconds by postgrey-1.37 at buxtehude; Tue, 18 Nov 2025 23:43:39 UTC X-Debian-Message: from BTS X-Mailing-List: archive/latest/1937472 List-ID: List-URL: Approved: robomod@news.nic.it Lines: 64 Organization: linux.* mail to news gateway Sender: robomod@news.nic.it X-Original-Cc: Trond Myklebust , Chuck Lever , Anna Schumaker , Salvatore Bonaccorso , "1120598@bugs.debian.org" <1120598@bugs.debian.org>, Jeff Layton , NeilBrown , Steve Dickson , Olga Kornievskaia , Dai Ngo , Tom Talpey , linux-nfs@vger.kernel.org, linux-kernel@vger.kernel.org X-Original-Date: Tue, 18 Nov 2025 23:43:29 +0000 X-Original-Message-ID: <85cd9202-dc22-41b8-8a20-e82cd118215f@TylerWRoss.com> X-Original-References: <4a63ad3d-b53a-4eab-8ffb-dd206f52c20e@oracle.com> <902ff4995d8e75ad1cd2196bf7d8da42932fba35.camel@kernel.org> <176298368872.955.14091113173156448257.reportbug@nfsclient-sid.ipa.twrlab.net> Xref: csiph.com linux.debian.bugs.dist:1270732 linux.kernel:1743502 linux.debian.kernel:90136 On 11/18/25 10:52 AM, Scott Mayhew wrote: > Oh! I see the problem. If the automatically acquired service ticket > for a normal user is using aes256-cts-hmac-sha1-96, then I'm assuming > the machine credential is also using aes256-cts-hmac-sha1-96. > Run 'klist -ce /tmp/krb5ccmachine_IPA.TWRLAB.NET' to check. You can't > use 'kvno -e' to choose a different encryption type. Why are you doing > that? Aha! Thank you! That's exactly the case: the machine credential is aes256-cts-hmac-sha1-96. So, taking a step back for context/background: this issue was escalated=20 to me by someone attempting to use constrained delegation via gssproxy.=20 In the course of troubleshooting that, we found (by examining the=20 krb5kdc logs on the IPA server) that the NFS service ticket acquired by=20 gssproxy had an aes256-cts-hmac-sha384-192 session key. Not understanding that the machine and user tickets must having matching=20 enctypes, I ended up down this rabbit hole thinking the problem was with=20 the SHA2 enctypes. Sorry to bring you all with me on that misadventure. The actual issue at hand then seems to be that gssproxy is requesting=20 (and receiving) a service ticket with an unusable (for the NFS mount)=20 enctype, when performing constrained delegation/S4U2Proxy. krb5kdc logs of gssproxy performing S4U2Self and S4U2Proxy:Nov 18=20 18:06:51 directory.ipa.twrlab.net krb5kdc[8463](info): TGS_REQ (8 etypes=20 {aes256-cts-hmac-sha1-96(18), aes128-cts-hmac-sha1-96(17),=20 aes256-cts-hmac-sha384-192(20), aes128-cts-hmac-sha256-128(19),=20 UNSUPPORTED:des3-hmac-sha1(16), DEPRECATED:arcfour-hmac(23),=20 camellia128-cts-cmac(25), camellia256-cts-cmac(26)}) 10.108.2.105:=20 ISSUE: authtime 1763506600, etypes {rep=3Daes256-cts-hmac-sha1-96(18),=20 tkt=3Daes256-cts-hmac-sha384-192(20), ses=3Daes256-cts-hmac-sha1-96(18)},= =20 host/nfsclient.ipa.twrlab.net@IPA.TWRLAB.NET for=20 host/nfsclient.ipa.twrlab.net@IPA.TWRLAB.NET Nov 18 18:06:51 directory.ipa.twrlab.net krb5kdc[8463](info): ...=20 PROTOCOL-TRANSITION s4u-client=3Djsmith@IPA.TWRLAB.NET Nov 18 18:06:51 directory.ipa.twrlab.net krb5kdc[8463](info): closing=20 down fd 4 Nov 18 18:06:51 directory.ipa.twrlab.net krb5kdc[8465](info): TGS_REQ (4=20 etypes {aes256-cts-hmac-sha384-192(20), aes128-cts-hmac-sha256-128(19),=20 aes256-cts-hmac-sha1-96(18), aes128-cts-hmac-sha1-96(17)}) 10.108.2.105:=20 ISSUE: authtime 1763506600, etypes {rep=3Daes256-cts-hmac-sha1-96(18),=20 tkt=3Daes256-cts-hmac-sha384-192(20), ses=3Daes256-cts-hmac-sha384-192(20)}= ,=20 host/nfsclient.ipa.twrlab.net@IPA.TWRLAB.NET for=20 nfs/nfssrv.ipa.twrlab.net@IPA.TWRLAB.NET Nov 18 18:06:51 directory.ipa.twrlab.net krb5kdc[8465](info): ...=20 CONSTRAINED-DELEGATION s4u-client=3Djsmith@IPA.TWRLAB.NET Nov 18 18:06:51 directory.ipa.twrlab.net krb5kdc[8465](info): closing=20 down fd 11 On the Fedora 43 client, gssproxy also acquires an aes256-cts-hmac-sha384-192 service ticket, but the machine credential is=20 aes256-cts-hmac-sha384-192 and everything works as-expected. TWR