Here seems to be the kernel patch we're expecting: http://www.spinics.net/lists/linux-nfs/msg31197.html Regards Le 1 juil. 2012 à 17:14, Dominic Gross a écrit : >> The Kernel posted by Chris allows, (with console login), the user to unlock the >> screensaver > > Well, this seems to fix the original bug reported here. Which is that > nobody can log in using LDAP / Kerberos once a ticket of one signed in > user expired. > >> but applications, such like web browser, remains stuck and the session has to >> be restarted in order to work properly. > > This looks like the intended behavior to me. The user's Kerberos Ticket > expires some time after log in. At that point the applications can no > longer access the user's NFS home directory and the applications get > stuck or crash. Once a user enters his / her password again a new ticket > is granted and the user can log into the session /access the home > directory again. However, in my experience few applications fully > recover from not being able to access the home directory for a longer > time. > > So, it seems to me, that in order to fix this remaining issue one needs > to set up something to automatically renew Kerberos Tickets. This can be > implemented either via a cronjob or packages like kstart or sssd. > > -- > You received this bug notification because you are subscribed to the bug > report. > https://bugs.launchpad.net/bugs/794112 > > Title: > Kerberos + LDAP + NFSv4 on Natty - Unable to recover unattended client > > Status in Network Authentication System: > New > Status in The Linux Kernel: > New > Status in NFS-Utils - NFS support files common to client and server: > New > Status in “linux” package in Ubuntu: > Incomplete > Status in “linux” source package in Precise: > Incomplete > Status in “nfs-utils” package in Debian: > New > > Bug description: > Hi there! > > I've configured a Natty client/server pair to authenticate over > Kerberos and LDAP and to mount user home directories via NFSv4 with > sec=krb5. I am using a slight variation on the configuration described > here: http://www.danbishop.org/2011/05/01/ubuntu-11-04-sbs-small- > business-server-setup-part-3-openldap/ > > Under this setup, user sessions that are left unattended for a long > period of time -- eg, when someone goes home for the night but stays > logged in -- always result in a wedged machine. What do I mean by > "wedged?" When the user returns to their session (the next morning), > the screen is sorta grayed out. Keystrokes and mouse movement fail to > elicit a reaction from the OS. I can switch to an ANSI terminal > (Ctrl+Alt+F1), but cannot log in as the offending user there; the > prompt will accept a username and password but never return. I CAN > login using my localadmin, presumably because it uses UNIX > authentication rather than LDAP/Kerberos. I have heretofore been > unable to recover the machine as the localadmin, though. If localadmin > attempts to sudo reboot the machine, the reboot process starts but > never finishes. > > Some odd things in the server syslog: > > Jun 6 07:40:15 server krb5kdc[822]: AS_REQ (7 etypes {18 17 16 23 1 3 2}) 192.168.0.59: NEEDED_PREAUTH: