Quicksearch |
Friday, June 4. 2010Filesystems Quo Vadis: ClientsComments
Display comments as
(Linear | Threaded)
Just out of curiosity (and because I happen to support an environment more or less like yours) why you so fast say "no" to NFSv4 (plus Kerberos, plus LDAP)? I'd say out of my experience that POSIX ACLs work just OK.
I've read everywhere that NFSv4 uses a different set of ACL, which are in some cases not just a superset of POSIX, but show slightly different behaviour. Also, AFAIK setfacl/getfacl don't work with NFSv4 acl. Is that not the case?
I support (at home and work), a heterogeneous mix of machines/OS.
I have my user base in LDAP, use KRB5 (in LDAP) for SSO, and serve data via NFSv4 and samba (3).
Whilst I also export NFSv3 points, I find NFSv4 so much easier to handle - especially with firewalls (needing only port 2049).
I've not had any trouble with NFSv4 ACLs mapping to POSIX ACLs on either the client or server side - but my ACLs are not really complicated.
|
Debian Planet |
Comments