RHEL7: Provide NFS network shares suitable for group collaboration.

Share this link

Note: This is an RHCE 7 exam objective.

Configuration Procedure

Install the NFS packages:

# yum groupinstall -y "file-server"

Add a new service to the firewall:

# firewall-cmd --permanent --add-service=nfs
Success

Reload the firewall configuration:

# firewall-cmd --reload
Success

Activate the NFS services at boot:

# systemctl enable rpcbind
# systemctl enable nfs-server
# systemctl enable nfs-lock

Note: With the RHEL 7.3 release, the Systemd init system is able to use aliases. For example, the nfs.service is a symbolic link/alias to the nfs-server.service service file. This enables, for example, using the systemctl status nfs.service command instead of systemctl status nfs-server.service.
Previously, running the systemctl enable command using an alias instead of the real service name failed with an error.

Start the NFS services:

# systemctl start rpcbind
# systemctl start nfs-server
# systemctl start nfs-lock

Create a directory to export (here /shared):

# mkdir /shared

Create a dedicated group (here called sharedgrp):

# groupadd -g 60000 sharedgrp

Assign this group to the new directory:

# chgrp sharedgrp /shared

Define permissions:

# chmod 2770 /shared

Edit the /etc/exports file and add the following lines with the name (or IP address) of the client(s):

/shared client(rw,no_root_squash)

Export the directories:

# exportfs -avr
# systemctl restart nfs-server

Note1: The client needs to have access to the same group (via LDAP) and be a member of this group.
Note2: The last command shouldn’t be necessary in the future. But, for the time being, it avoids rebooting.
Note3: The standard way to export shares is to create a file finishing by .exports in the /etc/exports.d directory (/etc/exports.d/openshift-ansible.exports for example).

(3 votes, average: 4.33 out of 5)
Loading...
11 comments on “RHEL7: Provide NFS network shares suitable for group collaboration.
  1. Abdelrahman says:

    Thank you for your efforts.
    I’ve a question here, in the exam, Will I need to make any LDAP configuration, or just the NFS server configuration?

  2. alexritm says:

    Note1: The client needs to have access to the same group (via LDAP) and be a member of this group. – ipa group-add… ???

  3. hcc says:

    Hi, thanks for the great tutorial.

    I am also not clear about “Note1: The client needs to have access to the same group (via LDAP) and be a member of this group.”.

    What does “this group” mean? Does that mean the test will provide us with the user group name so we can add locally on nfs server? In this case, on LDAP server, there is a group called “sharedgrp”??

    Or the LDAP clients (the nfs server and client) need to be in the same group?

    Thanks

    • itninja says:

      Hi, since I am preparing now my RHCE, I will try to answer you question.
      For example, if you have IPA server in place as LDAP/Kerberos/DNS/NFS server and in LDAP you create user “Alice” and group “Ldapusers”, you add Alice to Ldapusers. Next step is to change group owner of the NFS directory(your export) on the Linux FS to Ldapusers. Imagine that your client is configured to use LDAP/Kerberos and you mapped shared folder on the client under /nfs. If you now login on the client as Alice using LDAP repository, user is member of the Ldapusers group, you then request kerberos ticket with kinit, you will be able to access /nfs as Alice, so if you add more users to the same group, they will be able to write to that directory as well. Hope this helps a bit

Leave a Reply

Upcoming Events (Local Time)

There are no events.

Follow me on Twitter

Archives

vceplus-200-125    | boson-200-125    | training-cissp    | actualtests-cissp    | techexams-cissp    | gratisexams-300-075    | pearsonitcertification-210-260    | examsboost-210-260    | examsforall-210-260    | dumps4free-210-260    | reddit-210-260    | cisexams-352-001    | itexamfox-352-001    | passguaranteed-352-001    | passeasily-352-001    | freeccnastudyguide-200-120    | gocertify-200-120    | passcerty-200-120    | certifyguide-70-980    | dumpscollection-70-980    | examcollection-70-534    | cbtnuggets-210-065    | examfiles-400-051    | passitdump-400-051    | pearsonitcertification-70-462    | anderseide-70-347    | thomas-70-533    | research-1V0-605    | topix-102-400    | certdepot-EX200    | pearsonit-640-916    | itproguru-70-533    | reddit-100-105    | channel9-70-346    | anderseide-70-346    | theiia-IIA-CIA-PART3    | certificationHP-hp0-s41    | pearsonitcertification-640-916    | anderMicrosoft-70-534    | cathMicrosoft-70-462    | examcollection-cca-500    | techexams-gcih    | mslearn-70-346    | measureup-70-486    | pass4sure-hp0-s41    | iiba-640-916    | itsecurity-sscp    | cbtnuggets-300-320    | blogged-70-486    | pass4sure-IIA-CIA-PART1    | cbtnuggets-100-101    | developerhandbook-70-486    | lpicisco-101    | mylearn-1V0-605    | tomsitpro-cism    | gnosis-101    | channel9Mic-70-534    | ipass-IIA-CIA-PART1    | forcerts-70-417    | tests-sy0-401    | ipasstheciaexam-IIA-CIA-PART3    | mostcisco-300-135    | buildazure-70-533    | cloudera-cca-500    | pdf4cert-2v0-621    | f5cisco-101    | gocertify-1z0-062    | quora-640-916    | micrcosoft-70-480    | brain2pass-70-417    | examcompass-sy0-401    | global-EX200    | iassc-ICGB    | vceplus-300-115    | quizlet-810-403    | cbtnuggets-70-697    | educationOracle-1Z0-434    | channel9-70-534    | officialcerts-400-051    | examsboost-IIA-CIA-PART1    | networktut-300-135    | teststarter-300-206    | pluralsight-70-486    | coding-70-486    | freeccna-100-101    | digitaltut-300-101    | iiba-CBAP    | virtuallymikebrown-640-916    | isaca-cism    | whizlabs-pmp    | techexams-70-980    | ciscopress-300-115    | techtarget-cism    | pearsonitcertification-300-070    | testking-2v0-621    | isacaNew-cism    | simplilearn-pmi-rmp    | simplilearn-pmp    | educationOracle-1z0-809    | education-1z0-809    | teachertube-1Z0-434    | villanovau-CBAP    | quora-300-206    | certifyguide-300-208    | cbtnuggets-100-105    | flydumps-70-417    | gratisexams-1V0-605    | ituonline-1z0-062    | techexams-cas-002    | simplilearn-70-534    | pluralsight-70-697    | theiia-IIA-CIA-PART1    | itexamtips-400-051    | pearsonitcertification-EX200    | pluralsight-70-480    | learn-hp0-s42    | giac-gpen    | mindhub-102-400    | coursesmsu-CBAP    | examsforall-2v0-621    | developerhandbook-70-487    | root-EX200    | coderanch-1z0-809    | getfreedumps-1z0-062    | comptia-cas-002    | quora-1z0-809    | boson-300-135    | killtest-2v0-621    | learncia-IIA-CIA-PART3    | computer-gcih    | universitycloudera-cca-500    | itexamrun-70-410    | certificationHPv2-hp0-s41    | certskills-100-105    | skipitnow-70-417    | gocertify-sy0-401    | prep4sure-70-417    | simplilearn-cisa    |
http://www.pmsas.pr.gov.br/wp-content/    | http://www.pmsas.pr.gov.br/wp-content/    |