Re: TLS certificates for NFS-over-TLS floating client

From: Jan Bramkamp <crest_at_rlwinm.de>
Date: Fri, 20 Mar 2020 18:51:10 +0100
On 20.03.20 02:44, Russell L. Carter wrote:
> Here I commit heresy, by A) top posting, and B) by just saying, why
> not make it easy, first, to tunnel NFSv4 sessions through
> e.g. net/wireguard or sysutils/spiped?  NFS is point to point.
> Security infrastructure that actually works understands the shared
> secret model.

Why not use IPsec in transport mode instead of a tunnel? It avoids 
unnecessary overhead and is already implemented in the kernel. It should 
be enough to "just" require IPsec for TCP port 2049 and run a suitable 
key exchange daemon.
Received on Fri Mar 20 2020 - 16:51:20 UTC

This archive was generated by hypermail 2.4.0 : Wed May 19 2021 - 11:41:23 UTC