diff options
author | Chuck Lever <chuck.lever@oracle.com> | 2016-07-18 11:08:23 -0400 |
---|---|---|
committer | Steve Dickson <steved@redhat.com> | 2016-07-18 13:30:45 -0400 |
commit | 2dca98711b55079a7c915b0d1f5ed06bed6284a5 (patch) | |
tree | 719e280b37497a16adaa2d1747e1770bc4d7dda1 /utils/exportfs/exportfs.c | |
parent | 8fef90084f3d19e90ba1bb22b8cd1d58ddaf6ef3 (diff) | |
download | nfs-utils-2dca98711b55079a7c915b0d1f5ed06bed6284a5.tar.gz nfs-utils-2dca98711b55079a7c915b0d1f5ed06bed6284a5.tar.xz nfs-utils-2dca98711b55079a7c915b0d1f5ed06bed6284a5.zip |
nfs(5): Add lease management security considerations
Several years ago, the kernel Linux NFS client was changed to
attempt to use strong security for lease management operations that
are shared by all NFSv4 mounts of a server on that client.
This forces the client to use a consistent security flavor and
principal for lease management, even across reboots, to ensure that
state recovery works, independent of what mounts have been done,
what order they were done, and with what sec= option.
The use of krb5i for lease management does not affect the flavor
used for RPCs done on behalf of individual users, but sometimes it
means krb5i is used for certain operations even when "sec=sys" is
specified. This has occasionally been surprising.
Link: https://bugzilla.redhat.com/show_bug.cgi?id=1334510
Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
Signed-off-by: Steve Dickson <steved@redhat.com>
Diffstat (limited to 'utils/exportfs/exportfs.c')
0 files changed, 0 insertions, 0 deletions