Re: Secdir early review of draft-ietf-nfsv4-rpc-tls-03

Chuck Lever <[email protected]>
Newsgroups gmane.ietf.nfsv4
Message-ID <[email protected]>
> On Oct 23, 2019, at 5:13 PM, Rick Macklem <[email protected]> wrote:
> 
> I'll admit I haven't read the most recent draft and haven't looked at it
> in detail. However, my impression is that the reviewer might be more
> comfortable if the draft makes it clear that "rpc-tls only" servers will
> not only be permitted, but encouraged.

Indeed, they are permitted. All legacy servers will take this form,
and of course, if no certificate material is provided to a TLS-capable
NFS server, it will act as if RPC-on-TLS is recognized but not
supported.

"Encouraged" is a bit strong, however. I think if we /encourage/ a
behavior, it would be to encourage the use of RPC-on-TLS where it is
practical.


> (I don't see a "http" vs "https" distinction, but extant NFSv4 servers that
> I am familiar with can be configured to only allow clients that use
> RPCSEC_GSS and I would expect that rpc-tls enabled servers could be
> configured the same way.)
> 
> As an aside, I do plan on implementing this in Winter 2020, rick

Thanks Rick!

--
Chuck Lever



_______________________________________________
nfsv4 mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/nfsv4
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.