summaryrefslogtreecommitdiffstats
path: root/utils/exportfs/exportfs.c
diff options
context:
space:
mode:
authorChuck Lever <chuck.lever@oracle.com>2016-07-18 11:08:23 -0400
committerSteve Dickson <steved@redhat.com>2016-07-18 13:30:45 -0400
commit2dca98711b55079a7c915b0d1f5ed06bed6284a5 (patch)
tree719e280b37497a16adaa2d1747e1770bc4d7dda1 /utils/exportfs/exportfs.c
parent8fef90084f3d19e90ba1bb22b8cd1d58ddaf6ef3 (diff)
downloadnfs-utils-2dca98711b55079a7c915b0d1f5ed06bed6284a5.tar.gz
nfs-utils-2dca98711b55079a7c915b0d1f5ed06bed6284a5.tar.xz
nfs-utils-2dca98711b55079a7c915b0d1f5ed06bed6284a5.zip
nfs(5): Add lease management security considerations
Several years ago, the kernel Linux NFS client was changed to attempt to use strong security for lease management operations that are shared by all NFSv4 mounts of a server on that client. This forces the client to use a consistent security flavor and principal for lease management, even across reboots, to ensure that state recovery works, independent of what mounts have been done, what order they were done, and with what sec= option. The use of krb5i for lease management does not affect the flavor used for RPCs done on behalf of individual users, but sometimes it means krb5i is used for certain operations even when "sec=sys" is specified. This has occasionally been surprising. Link: https://bugzilla.redhat.com/show_bug.cgi?id=1334510 Signed-off-by: Chuck Lever <chuck.lever@oracle.com> Signed-off-by: Steve Dickson <steved@redhat.com>
Diffstat (limited to 'utils/exportfs/exportfs.c')
0 files changed, 0 insertions, 0 deletions