* [PATCH kdevops] ktls: allow setting up hosts with tlshd
@ 2023-12-12 19:35 Jeff Layton
2023-12-12 19:43 ` Chuck Lever
2023-12-13 6:11 ` Luis Chamberlain
0 siblings, 2 replies; 4+ messages in thread
From: Jeff Layton @ 2023-12-12 19:35 UTC (permalink / raw)
To: Luis Chamberlain; +Cc: Chuck Lever, kdevops, Jeff Layton
Add a new option to the post-install "goals" phase to configure tlshd
for TLS handshake upcalls. This adds a new playbook to build a CA,
generate certs for the hosts, and then configure tlshd to use them.
Finally, it also adds a new NFS fstests option to test RPC over TLS
(using xprtsec=mtls).
Signed-off-by: Jeff Layton <jlayton@kernel.org>
---
Makefile | 4 +
kconfigs/Kconfig.bringup.goals | 9 ++
playbooks/ktls.yml | 4 +
playbooks/roles/fstests/templates/nfs/nfs.config | 7 ++
.../roles/ktls/tasks/install-deps/debian/main.yml | 10 ++
playbooks/roles/ktls/tasks/install-deps/main.yml | 9 ++
.../roles/ktls/tasks/install-deps/redhat/main.yml | 15 +++
.../roles/ktls/tasks/install-deps/suse/main.yml | 9 ++
playbooks/roles/ktls/tasks/main.yml | 110 +++++++++++++++++++++
playbooks/roles/ktls/templates/tlshd.conf | 39 ++++++++
scripts/bringup.Makefile | 5 +
scripts/ktls.Makefile | 8 ++
workflows/fstests/nfs/Kconfig | 9 +-
workflows/fstests/nfs/Makefile | 3 +
14 files changed, 240 insertions(+), 1 deletion(-)
diff --git a/Makefile b/Makefile
index 895a0a67c705..0f6fa024f14c 100644
--- a/Makefile
+++ b/Makefile
@@ -114,6 +114,10 @@ ifeq (y,$(CONFIG_WORKFLOWS))
include workflows/Makefile
endif # CONFIG_WORKFLOWS
+ifeq (y,$(CONFIG_KDEVOPS_SETUP_KTLS))
+include scripts/ktls.Makefile
+endif # CONFIG_KDEVOPS_SETUP_KTLS
+
ifeq (y,$(CONFIG_KDEVOPS_SETUP_NFSD))
include scripts/nfsd.Makefile
endif # CONFIG_KDEVOPS_SETUP_NFSD
diff --git a/kconfigs/Kconfig.bringup.goals b/kconfigs/Kconfig.bringup.goals
index 5df74d4bcb08..a2af3ffba499 100644
--- a/kconfigs/Kconfig.bringup.goals
+++ b/kconfigs/Kconfig.bringup.goals
@@ -56,6 +56,15 @@ config KDEVOPS_TRY_INSTALL_KDEV_TOOLS
most kernel developers might prefer to have installed on target
systems.
+config KDEVOPS_SETUP_KTLS
+ bool "Configure ktls on the hosts with self-signed CA"
+ default n
+ help
+ Enabling this will have kdevops create a self-signed certificate
+ authority, and configure tlshd on the hosts to use it. This is
+ necessary for testing RPC over TLS, or some NVMe over fabrics
+ configurations.
+
config KDEVOPS_SETUP_NFSD
bool "Set up the kernel nfs server"
default n
diff --git a/playbooks/ktls.yml b/playbooks/ktls.yml
new file mode 100644
index 000000000000..8b7044c7ef2d
--- /dev/null
+++ b/playbooks/ktls.yml
@@ -0,0 +1,4 @@
+---
+- hosts: all
+ roles:
+ - role: ktls
diff --git a/playbooks/roles/fstests/templates/nfs/nfs.config b/playbooks/roles/fstests/templates/nfs/nfs.config
index 60915f824764..e2265f3f3ee2 100644
--- a/playbooks/roles/fstests/templates/nfs/nfs.config
+++ b/playbooks/roles/fstests/templates/nfs/nfs.config
@@ -15,6 +15,13 @@ CANON_DEVS=yes
# Test with default mount options
[nfs_default]
{% endif %}
+{% if fstests_nfs_section_tls -%}
+
+# Test NFS with RPC over TLS
+[nfs_tls]
+TEST_FS_MOUNT_OPTS="-o xprtsec=mtls"
+MOUNT_OPTIONS="-o xprtsec=mtls"
+{% endif %}
{% if fstests_nfs_section_v40 -%}
# Test NFSv4.0
diff --git a/playbooks/roles/ktls/tasks/install-deps/debian/main.yml b/playbooks/roles/ktls/tasks/install-deps/debian/main.yml
new file mode 100644
index 000000000000..704c394e0c49
--- /dev/null
+++ b/playbooks/roles/ktls/tasks/install-deps/debian/main.yml
@@ -0,0 +1,10 @@
+---
+- name: Install ktls dependencies
+ become: yes
+ become_method: sudo
+ apt:
+ name:
+ - python3-cryptography
+ - ktls-utils
+ state: present
+ update_cache: yes
diff --git a/playbooks/roles/ktls/tasks/install-deps/main.yml b/playbooks/roles/ktls/tasks/install-deps/main.yml
new file mode 100644
index 000000000000..ab343e8b05c6
--- /dev/null
+++ b/playbooks/roles/ktls/tasks/install-deps/main.yml
@@ -0,0 +1,9 @@
+---
+# tasks to install dependencies for pynfs
+- name: oscheck distribution ospecific setup
+ import_tasks: tasks/install-deps/debian/main.yml
+ when: ansible_facts['os_family']|lower == 'debian'
+- import_tasks: tasks/install-deps/suse/main.yml
+ when: ansible_facts['os_family']|lower == 'suse'
+- import_tasks: tasks/install-deps/redhat/main.yml
+ when: ansible_facts['os_family']|lower == 'redhat'
diff --git a/playbooks/roles/ktls/tasks/install-deps/redhat/main.yml b/playbooks/roles/ktls/tasks/install-deps/redhat/main.yml
new file mode 100644
index 000000000000..0e1ab7505b3e
--- /dev/null
+++ b/playbooks/roles/ktls/tasks/install-deps/redhat/main.yml
@@ -0,0 +1,15 @@
+---
+- name: Install ktls dependencies
+ become: yes
+ become_method: sudo
+ dnf:
+ update_cache: yes
+ name: "{{ packages }}"
+ retries: 3
+ delay: 5
+ register: result
+ until: result.rc == 0
+ vars:
+ packages:
+ - python3-cryptography
+ - ktls-utils
diff --git a/playbooks/roles/ktls/tasks/install-deps/suse/main.yml b/playbooks/roles/ktls/tasks/install-deps/suse/main.yml
new file mode 100644
index 000000000000..ce5935154038
--- /dev/null
+++ b/playbooks/roles/ktls/tasks/install-deps/suse/main.yml
@@ -0,0 +1,9 @@
+---
+- name: Install ktls dependencies
+ become: yes
+ become_method: sudo
+ zypper:
+ state: present
+ name:
+ - python3-cryptography
+ - ktls-utils
diff --git a/playbooks/roles/ktls/tasks/main.yml b/playbooks/roles/ktls/tasks/main.yml
new file mode 100644
index 000000000000..1aa545835502
--- /dev/null
+++ b/playbooks/roles/ktls/tasks/main.yml
@@ -0,0 +1,110 @@
+- name: Import optional extra_args file
+ include_vars: "{{ item }}"
+ ignore_errors: yes
+ with_first_found:
+ - files:
+ - "../extra_vars.yml"
+ - "../extra_vars.yaml"
+ - "../extra_vars.json"
+ skip: true
+
+- name: Install dependencies
+ import_tasks: install-deps/main.yml
+
+- name: Construct the path to the CA directory
+ delegate_to: localhost
+ set_fact:
+ ca_dir: "{{ topdir_path }}/ca/{{ kdevops_host_prefix }}"
+
+- name: Create directory to hold the CA on local host
+ delegate_to: localhost
+ run_once: true
+ ansible.builtin.file:
+ path: "{{ ca_dir }}"
+ state: directory
+
+- name: Create private key for CA
+ delegate_to: localhost
+ run_once: true
+ community.crypto.openssl_privatekey:
+ path: "{{ ca_dir }}/ca-cert.key"
+
+- name: Create certificate signing request (CSR) for CA certificate
+ delegate_to: localhost
+ run_once: true
+ community.crypto.openssl_csr_pipe:
+ privatekey_path: "{{ ca_dir }}/ca-cert.key"
+ common_name: "kdevops {{ kdevops_host_prefix }} CA"
+ use_common_name_for_san: false # since we do not specify SANs, don't use CN as a SAN
+ basic_constraints:
+ - 'CA:TRUE'
+ basic_constraints_critical: true
+ key_usage:
+ - keyCertSign
+ key_usage_critical: true
+ register: ca_csr
+
+- name: Create self-signed CA certificate from CSR
+ delegate_to: localhost
+ run_once: true
+ community.crypto.x509_certificate:
+ path: "{{ ca_dir }}/ca-cert.pem"
+ csr_content: "{{ ca_csr.csr }}"
+ privatekey_path: "{{ ca_dir }}/ca-cert.key"
+ provider: selfsigned
+
+- name: Create private key for new TLS certificate
+ community.crypto.openssl_privatekey:
+ path: "/etc/pki/tls/private/ktls.key"
+ become: yes
+
+- name: Copy CA cert to all of the hosts
+ ansible.builtin.copy:
+ src: "{{ ca_dir }}/ca-cert.pem"
+ dest: "/etc/pki/tls/certs/ca-cert.pem"
+ owner: root
+ group: root
+ mode: 0644
+ become: yes
+
+- name: Create certificate signing request (CSR) for new certificate
+ community.crypto.openssl_csr_pipe:
+ privatekey_path: "/etc/pki/tls/private/ktls.key"
+ subject_alt_name:
+ - "DNS:{{ ansible_host }}"
+ - "IP:{{ ansible_default_ipv4.address }}"
+ register: csr
+ become: yes
+
+- name: Sign certificate with our CA
+ community.crypto.x509_certificate_pipe:
+ csr_content: "{{ csr.csr }}"
+ provider: ownca
+ ownca_path: "{{ ca_dir }}/ca-cert.pem"
+ ownca_privatekey_path: "{{ ca_dir }}/ca-cert.key"
+ ownca_not_after: +365d # valid for one year
+ ownca_not_before: "-1d" # valid since yesterday
+ delegate_to: localhost
+ register: certificate
+
+- name: Write certificate file on host
+ copy:
+ dest: "/etc/pki/tls/certs/ktls.pem"
+ content: "{{ certificate.certificate }}"
+ become: yes
+
+- name: Install new /etc/tlshd.conf
+ ansible.builtin.copy:
+ src: "{{ playbook_dir }}/roles/ktls/templates/tlshd.conf"
+ dest: "/etc/tlshd.conf"
+ owner: root
+ group: root
+ mode: 0644
+ become: yes
+
+- name: Enable and start tlshd
+ become: yes
+ ansible.builtin.systemd_service:
+ name: tlshd.service
+ enabled: true
+ state: reloaded
diff --git a/playbooks/roles/ktls/templates/tlshd.conf b/playbooks/roles/ktls/templates/tlshd.conf
new file mode 100644
index 000000000000..63ee5b59a8bd
--- /dev/null
+++ b/playbooks/roles/ktls/templates/tlshd.conf
@@ -0,0 +1,39 @@
+#
+# Copyright (c) 2022 Oracle and/or its affiliates.
+#
+# This file is part of ktls-utils.
+#
+# ktls-utils is free software; you can redistribute it and/or
+# modify it under the terms of the GNU General Public License as
+# published by the Free Software Foundation; version 2.
+#
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
+# General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License
+# along with this program; if not, write to the Free Software
+# Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
+# 02110-1301, USA.
+#
+# See tlshd.conf(5) for details.
+#
+
+[debug]
+loglevel=0
+tls=0
+nl=0
+
+[authenticate]
+#keyrings= <keyring>;<keyring>;<keyring>
+
+[authenticate.client]
+x509.truststore=/etc/pki/tls/certs/ca-cert.pem
+x509.certificate=/etc/pki/tls/certs/ktls.pem
+x509.private_key=/etc/pki/tls/private/ktls.key
+
+[authenticate.server]
+x509.truststore=/etc/pki/tls/certs/ca-cert.pem
+x509.certificate=/etc/pki/tls/certs/ktls.pem
+x509.private_key=/etc/pki/tls/private/ktls.key
diff --git a/scripts/bringup.Makefile b/scripts/bringup.Makefile
index 0051bc3d5e0d..520e2993a7b1 100644
--- a/scripts/bringup.Makefile
+++ b/scripts/bringup.Makefile
@@ -21,6 +21,11 @@ ifeq (y,$(CONFIG_KDEVOPS_SETUP_NFSD))
KDEVOPS_BRING_UP_DEPS += nfsd
endif # KDEVOPS_SETUP_NFSD
+ifeq (y,$(CONFIG_KDEVOPS_SETUP_KTLS))
+KDEVOPS_BRING_UP_DEPS += ktls
+KDEVOPS_DESTROY_DEPS += ktls-destroy
+endif # KDEVOPS_SETUP_KTLS
+
update_etc_hosts:
$(Q)ansible-playbook $(ANSIBLE_VERBOSE) \
-f 30 -i hosts playbooks/update_etc_hosts.yml
diff --git a/scripts/ktls.Makefile b/scripts/ktls.Makefile
new file mode 100644
index 000000000000..977538041ae8
--- /dev/null
+++ b/scripts/ktls.Makefile
@@ -0,0 +1,8 @@
+ktls:
+ $(Q)ansible-playbook $(ANSIBLE_VERBOSE) --extra-vars=@./extra_vars.yaml \
+ -f 30 -i hosts playbooks/ktls.yml
+
+ktls-destroy:
+ $(Q)rm -rf $(TOPDIR)/ca
+
+PHONY += ktls ktls-destroy
diff --git a/workflows/fstests/nfs/Kconfig b/workflows/fstests/nfs/Kconfig
index 7e202778d286..7e8731dc4dc1 100644
--- a/workflows/fstests/nfs/Kconfig
+++ b/workflows/fstests/nfs/Kconfig
@@ -54,11 +54,18 @@ config FSTESTS_NFS_SECTION_DEFAULT
time of this writing, this makes the client autonegotiate an NFS
version, starting with v4.2 if it's available.
+config FSTESTS_NFS_SECTION_TLS
+ bool "Enable testing section: nfs_tls"
+ default n
+ depends on KDEVOPS_SETUP_KTLS
+ help
+ Enabling this will test with the xprtsec=tls mount option.
+
config FSTESTS_NFS_SECTION_V40
bool "Enable testing section: nfs_v40"
default n
help
- Enabling this will test NFSv4.0
+ Enabling this will test NFSv4.0.
config FSTESTS_NFS_SECTION_V3
bool "Enable testing section: nfs_v3"
diff --git a/workflows/fstests/nfs/Makefile b/workflows/fstests/nfs/Makefile
index 7a057532be67..0e5245920ee9 100644
--- a/workflows/fstests/nfs/Makefile
+++ b/workflows/fstests/nfs/Makefile
@@ -9,6 +9,9 @@ FSTESTS_ARGS += fstests_nfs_server_host='$(FSTESTS_NFS_SERVER_HOST)'
ifeq (y,$(CONFIG_FSTESTS_NFS_SECTION_DEFAULT))
FSTESTS_ARGS += fstests_nfs_section_default=True
endif
+ifeq (y,$(CONFIG_FSTESTS_NFS_SECTION_TLS))
+FSTESTS_ARGS += fstests_nfs_section_tls=True
+endif
ifeq (y,$(CONFIG_FSTESTS_NFS_SECTION_V40))
FSTESTS_ARGS += fstests_nfs_section_v40=True
endif
---
base-commit: 2f7d9b13a7ac734e2fb40ed68e45150af9d727ef
change-id: 20231212-ktls-5534fde5777c
Best regards,
--
Jeff Layton <jlayton@kernel.org>
^ permalink raw reply related [flat|nested] 4+ messages in thread
* Re: [PATCH kdevops] ktls: allow setting up hosts with tlshd
2023-12-12 19:35 [PATCH kdevops] ktls: allow setting up hosts with tlshd Jeff Layton
@ 2023-12-12 19:43 ` Chuck Lever
2023-12-12 20:12 ` Jeff Layton
2023-12-13 6:11 ` Luis Chamberlain
1 sibling, 1 reply; 4+ messages in thread
From: Chuck Lever @ 2023-12-12 19:43 UTC (permalink / raw)
To: Jeff Layton; +Cc: Luis Chamberlain, kdevops
On Tue, Dec 12, 2023 at 02:35:38PM -0500, Jeff Layton wrote:
> Add a new option to the post-install "goals" phase to configure tlshd
> for TLS handshake upcalls. This adds a new playbook to build a CA,
> generate certs for the hosts, and then configure tlshd to use them.
>
> Finally, it also adds a new NFS fstests option to test RPC over TLS
> (using xprtsec=mtls).
>
> Signed-off-by: Jeff Layton <jlayton@kernel.org>
> ---
> Makefile | 4 +
> kconfigs/Kconfig.bringup.goals | 9 ++
> playbooks/ktls.yml | 4 +
> playbooks/roles/fstests/templates/nfs/nfs.config | 7 ++
> .../roles/ktls/tasks/install-deps/debian/main.yml | 10 ++
> playbooks/roles/ktls/tasks/install-deps/main.yml | 9 ++
> .../roles/ktls/tasks/install-deps/redhat/main.yml | 15 +++
> .../roles/ktls/tasks/install-deps/suse/main.yml | 9 ++
> playbooks/roles/ktls/tasks/main.yml | 110 +++++++++++++++++++++
> playbooks/roles/ktls/templates/tlshd.conf | 39 ++++++++
> scripts/bringup.Makefile | 5 +
> scripts/ktls.Makefile | 8 ++
> workflows/fstests/nfs/Kconfig | 9 +-
> workflows/fstests/nfs/Makefile | 3 +
> 14 files changed, 240 insertions(+), 1 deletion(-)
>
> diff --git a/Makefile b/Makefile
> index 895a0a67c705..0f6fa024f14c 100644
> --- a/Makefile
> +++ b/Makefile
> @@ -114,6 +114,10 @@ ifeq (y,$(CONFIG_WORKFLOWS))
> include workflows/Makefile
> endif # CONFIG_WORKFLOWS
>
> +ifeq (y,$(CONFIG_KDEVOPS_SETUP_KTLS))
> +include scripts/ktls.Makefile
> +endif # CONFIG_KDEVOPS_SETUP_KTLS
> +
> ifeq (y,$(CONFIG_KDEVOPS_SETUP_NFSD))
> include scripts/nfsd.Makefile
> endif # CONFIG_KDEVOPS_SETUP_NFSD
> diff --git a/kconfigs/Kconfig.bringup.goals b/kconfigs/Kconfig.bringup.goals
> index 5df74d4bcb08..a2af3ffba499 100644
> --- a/kconfigs/Kconfig.bringup.goals
> +++ b/kconfigs/Kconfig.bringup.goals
> @@ -56,6 +56,15 @@ config KDEVOPS_TRY_INSTALL_KDEV_TOOLS
> most kernel developers might prefer to have installed on target
> systems.
>
> +config KDEVOPS_SETUP_KTLS
> + bool "Configure ktls on the hosts with self-signed CA"
> + default n
> + help
> + Enabling this will have kdevops create a self-signed certificate
> + authority, and configure tlshd on the hosts to use it. This is
> + necessary for testing RPC over TLS, or some NVMe over fabrics
> + configurations.
> +
> config KDEVOPS_SETUP_NFSD
> bool "Set up the kernel nfs server"
> default n
> diff --git a/playbooks/ktls.yml b/playbooks/ktls.yml
> new file mode 100644
> index 000000000000..8b7044c7ef2d
> --- /dev/null
> +++ b/playbooks/ktls.yml
> @@ -0,0 +1,4 @@
> +---
> +- hosts: all
> + roles:
> + - role: ktls
> diff --git a/playbooks/roles/fstests/templates/nfs/nfs.config b/playbooks/roles/fstests/templates/nfs/nfs.config
> index 60915f824764..e2265f3f3ee2 100644
> --- a/playbooks/roles/fstests/templates/nfs/nfs.config
> +++ b/playbooks/roles/fstests/templates/nfs/nfs.config
> @@ -15,6 +15,13 @@ CANON_DEVS=yes
> # Test with default mount options
> [nfs_default]
> {% endif %}
> +{% if fstests_nfs_section_tls -%}
> +
> +# Test NFS with RPC over TLS
> +[nfs_tls]
> +TEST_FS_MOUNT_OPTS="-o xprtsec=mtls"
> +MOUNT_OPTIONS="-o xprtsec=mtls"
> +{% endif %}
> {% if fstests_nfs_section_v40 -%}
>
> # Test NFSv4.0
> diff --git a/playbooks/roles/ktls/tasks/install-deps/debian/main.yml b/playbooks/roles/ktls/tasks/install-deps/debian/main.yml
> new file mode 100644
> index 000000000000..704c394e0c49
> --- /dev/null
> +++ b/playbooks/roles/ktls/tasks/install-deps/debian/main.yml
> @@ -0,0 +1,10 @@
> +---
> +- name: Install ktls dependencies
> + become: yes
> + become_method: sudo
> + apt:
> + name:
> + - python3-cryptography
> + - ktls-utils
> + state: present
> + update_cache: yes
> diff --git a/playbooks/roles/ktls/tasks/install-deps/main.yml b/playbooks/roles/ktls/tasks/install-deps/main.yml
> new file mode 100644
> index 000000000000..ab343e8b05c6
> --- /dev/null
> +++ b/playbooks/roles/ktls/tasks/install-deps/main.yml
> @@ -0,0 +1,9 @@
> +---
> +# tasks to install dependencies for pynfs
> +- name: oscheck distribution ospecific setup
> + import_tasks: tasks/install-deps/debian/main.yml
Since this is a new set of install-deps, how about using
include_tasks: instead?
> + when: ansible_facts['os_family']|lower == 'debian'
> +- import_tasks: tasks/install-deps/suse/main.yml
> + when: ansible_facts['os_family']|lower == 'suse'
> +- import_tasks: tasks/install-deps/redhat/main.yml
> + when: ansible_facts['os_family']|lower == 'redhat'
> diff --git a/playbooks/roles/ktls/tasks/install-deps/redhat/main.yml b/playbooks/roles/ktls/tasks/install-deps/redhat/main.yml
> new file mode 100644
> index 000000000000..0e1ab7505b3e
> --- /dev/null
> +++ b/playbooks/roles/ktls/tasks/install-deps/redhat/main.yml
> @@ -0,0 +1,15 @@
> +---
> +- name: Install ktls dependencies
> + become: yes
> + become_method: sudo
> + dnf:
> + update_cache: yes
> + name: "{{ packages }}"
> + retries: 3
> + delay: 5
> + register: result
> + until: result.rc == 0
> + vars:
> + packages:
> + - python3-cryptography
> + - ktls-utils
> diff --git a/playbooks/roles/ktls/tasks/install-deps/suse/main.yml b/playbooks/roles/ktls/tasks/install-deps/suse/main.yml
> new file mode 100644
> index 000000000000..ce5935154038
> --- /dev/null
> +++ b/playbooks/roles/ktls/tasks/install-deps/suse/main.yml
> @@ -0,0 +1,9 @@
> +---
> +- name: Install ktls dependencies
> + become: yes
> + become_method: sudo
> + zypper:
> + state: present
> + name:
> + - python3-cryptography
> + - ktls-utils
> diff --git a/playbooks/roles/ktls/tasks/main.yml b/playbooks/roles/ktls/tasks/main.yml
> new file mode 100644
> index 000000000000..1aa545835502
> --- /dev/null
> +++ b/playbooks/roles/ktls/tasks/main.yml
> @@ -0,0 +1,110 @@
> +- name: Import optional extra_args file
> + include_vars: "{{ item }}"
> + ignore_errors: yes
> + with_first_found:
> + - files:
> + - "../extra_vars.yml"
> + - "../extra_vars.yaml"
> + - "../extra_vars.json"
> + skip: true
> +
> +- name: Install dependencies
> + import_tasks: install-deps/main.yml
> +
> +- name: Construct the path to the CA directory
> + delegate_to: localhost
> + set_fact:
> + ca_dir: "{{ topdir_path }}/ca/{{ kdevops_host_prefix }}"
> +
> +- name: Create directory to hold the CA on local host
> + delegate_to: localhost
> + run_once: true
> + ansible.builtin.file:
> + path: "{{ ca_dir }}"
> + state: directory
> +
> +- name: Create private key for CA
> + delegate_to: localhost
> + run_once: true
> + community.crypto.openssl_privatekey:
> + path: "{{ ca_dir }}/ca-cert.key"
> +
> +- name: Create certificate signing request (CSR) for CA certificate
> + delegate_to: localhost
> + run_once: true
> + community.crypto.openssl_csr_pipe:
> + privatekey_path: "{{ ca_dir }}/ca-cert.key"
> + common_name: "kdevops {{ kdevops_host_prefix }} CA"
> + use_common_name_for_san: false # since we do not specify SANs, don't use CN as a SAN
> + basic_constraints:
> + - 'CA:TRUE'
> + basic_constraints_critical: true
> + key_usage:
> + - keyCertSign
> + key_usage_critical: true
> + register: ca_csr
> +
> +- name: Create self-signed CA certificate from CSR
> + delegate_to: localhost
> + run_once: true
> + community.crypto.x509_certificate:
> + path: "{{ ca_dir }}/ca-cert.pem"
> + csr_content: "{{ ca_csr.csr }}"
> + privatekey_path: "{{ ca_dir }}/ca-cert.key"
> + provider: selfsigned
> +
> +- name: Create private key for new TLS certificate
> + community.crypto.openssl_privatekey:
> + path: "/etc/pki/tls/private/ktls.key"
> + become: yes
> +
> +- name: Copy CA cert to all of the hosts
> + ansible.builtin.copy:
> + src: "{{ ca_dir }}/ca-cert.pem"
> + dest: "/etc/pki/tls/certs/ca-cert.pem"
> + owner: root
> + group: root
> + mode: 0644
> + become: yes
> +
> +- name: Create certificate signing request (CSR) for new certificate
> + community.crypto.openssl_csr_pipe:
> + privatekey_path: "/etc/pki/tls/private/ktls.key"
> + subject_alt_name:
> + - "DNS:{{ ansible_host }}"
> + - "IP:{{ ansible_default_ipv4.address }}"
> + register: csr
> + become: yes
> +
> +- name: Sign certificate with our CA
> + community.crypto.x509_certificate_pipe:
> + csr_content: "{{ csr.csr }}"
> + provider: ownca
> + ownca_path: "{{ ca_dir }}/ca-cert.pem"
> + ownca_privatekey_path: "{{ ca_dir }}/ca-cert.key"
> + ownca_not_after: +365d # valid for one year
> + ownca_not_before: "-1d" # valid since yesterday
> + delegate_to: localhost
> + register: certificate
> +
> +- name: Write certificate file on host
> + copy:
> + dest: "/etc/pki/tls/certs/ktls.pem"
> + content: "{{ certificate.certificate }}"
> + become: yes
> +
> +- name: Install new /etc/tlshd.conf
> + ansible.builtin.copy:
> + src: "{{ playbook_dir }}/roles/ktls/templates/tlshd.conf"
> + dest: "/etc/tlshd.conf"
> + owner: root
> + group: root
> + mode: 0644
> + become: yes
> +
> +- name: Enable and start tlshd
> + become: yes
> + ansible.builtin.systemd_service:
> + name: tlshd.service
> + enabled: true
> + state: reloaded
> diff --git a/playbooks/roles/ktls/templates/tlshd.conf b/playbooks/roles/ktls/templates/tlshd.conf
> new file mode 100644
> index 000000000000..63ee5b59a8bd
> --- /dev/null
> +++ b/playbooks/roles/ktls/templates/tlshd.conf
> @@ -0,0 +1,39 @@
> +#
> +# Copyright (c) 2022 Oracle and/or its affiliates.
> +#
> +# This file is part of ktls-utils.
> +#
> +# ktls-utils is free software; you can redistribute it and/or
> +# modify it under the terms of the GNU General Public License as
> +# published by the Free Software Foundation; version 2.
> +#
> +# This program is distributed in the hope that it will be useful,
> +# but WITHOUT ANY WARRANTY; without even the implied warranty of
> +# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
> +# General Public License for more details.
> +#
> +# You should have received a copy of the GNU General Public License
> +# along with this program; if not, write to the Free Software
> +# Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
> +# 02110-1301, USA.
> +#
> +# See tlshd.conf(5) for details.
> +#
> +
> +[debug]
> +loglevel=0
> +tls=0
> +nl=0
> +
> +[authenticate]
> +#keyrings= <keyring>;<keyring>;<keyring>
> +
> +[authenticate.client]
> +x509.truststore=/etc/pki/tls/certs/ca-cert.pem
> +x509.certificate=/etc/pki/tls/certs/ktls.pem
> +x509.private_key=/etc/pki/tls/private/ktls.key
> +
> +[authenticate.server]
> +x509.truststore=/etc/pki/tls/certs/ca-cert.pem
> +x509.certificate=/etc/pki/tls/certs/ktls.pem
> +x509.private_key=/etc/pki/tls/private/ktls.key
> diff --git a/scripts/bringup.Makefile b/scripts/bringup.Makefile
> index 0051bc3d5e0d..520e2993a7b1 100644
> --- a/scripts/bringup.Makefile
> +++ b/scripts/bringup.Makefile
> @@ -21,6 +21,11 @@ ifeq (y,$(CONFIG_KDEVOPS_SETUP_NFSD))
> KDEVOPS_BRING_UP_DEPS += nfsd
> endif # KDEVOPS_SETUP_NFSD
>
> +ifeq (y,$(CONFIG_KDEVOPS_SETUP_KTLS))
> +KDEVOPS_BRING_UP_DEPS += ktls
> +KDEVOPS_DESTROY_DEPS += ktls-destroy
> +endif # KDEVOPS_SETUP_KTLS
> +
> update_etc_hosts:
> $(Q)ansible-playbook $(ANSIBLE_VERBOSE) \
> -f 30 -i hosts playbooks/update_etc_hosts.yml
> diff --git a/scripts/ktls.Makefile b/scripts/ktls.Makefile
> new file mode 100644
> index 000000000000..977538041ae8
> --- /dev/null
> +++ b/scripts/ktls.Makefile
> @@ -0,0 +1,8 @@
> +ktls:
> + $(Q)ansible-playbook $(ANSIBLE_VERBOSE) --extra-vars=@./extra_vars.yaml \
> + -f 30 -i hosts playbooks/ktls.yml
> +
> +ktls-destroy:
> + $(Q)rm -rf $(TOPDIR)/ca
> +
> +PHONY += ktls ktls-destroy
> diff --git a/workflows/fstests/nfs/Kconfig b/workflows/fstests/nfs/Kconfig
> index 7e202778d286..7e8731dc4dc1 100644
> --- a/workflows/fstests/nfs/Kconfig
> +++ b/workflows/fstests/nfs/Kconfig
> @@ -54,11 +54,18 @@ config FSTESTS_NFS_SECTION_DEFAULT
> time of this writing, this makes the client autonegotiate an NFS
> version, starting with v4.2 if it's available.
>
> +config FSTESTS_NFS_SECTION_TLS
> + bool "Enable testing section: nfs_tls"
> + default n
> + depends on KDEVOPS_SETUP_KTLS
> + help
> + Enabling this will test with the xprtsec=tls mount option.
> +
> config FSTESTS_NFS_SECTION_V40
> bool "Enable testing section: nfs_v40"
> default n
> help
> - Enabling this will test NFSv4.0
> + Enabling this will test NFSv4.0.
>
> config FSTESTS_NFS_SECTION_V3
> bool "Enable testing section: nfs_v3"
> diff --git a/workflows/fstests/nfs/Makefile b/workflows/fstests/nfs/Makefile
> index 7a057532be67..0e5245920ee9 100644
> --- a/workflows/fstests/nfs/Makefile
> +++ b/workflows/fstests/nfs/Makefile
> @@ -9,6 +9,9 @@ FSTESTS_ARGS += fstests_nfs_server_host='$(FSTESTS_NFS_SERVER_HOST)'
> ifeq (y,$(CONFIG_FSTESTS_NFS_SECTION_DEFAULT))
> FSTESTS_ARGS += fstests_nfs_section_default=True
> endif
> +ifeq (y,$(CONFIG_FSTESTS_NFS_SECTION_TLS))
> +FSTESTS_ARGS += fstests_nfs_section_tls=True
> +endif
> ifeq (y,$(CONFIG_FSTESTS_NFS_SECTION_V40))
> FSTESTS_ARGS += fstests_nfs_section_v40=True
> endif
>
> ---
> base-commit: 2f7d9b13a7ac734e2fb40ed68e45150af9d727ef
> change-id: 20231212-ktls-5534fde5777c
>
> Best regards,
> --
> Jeff Layton <jlayton@kernel.org>
>
--
Chuck Lever
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH kdevops] ktls: allow setting up hosts with tlshd
2023-12-12 19:43 ` Chuck Lever
@ 2023-12-12 20:12 ` Jeff Layton
0 siblings, 0 replies; 4+ messages in thread
From: Jeff Layton @ 2023-12-12 20:12 UTC (permalink / raw)
To: Chuck Lever; +Cc: Luis Chamberlain, kdevops
On Tue, 2023-12-12 at 14:43 -0500, Chuck Lever wrote:
> On Tue, Dec 12, 2023 at 02:35:38PM -0500, Jeff Layton wrote:
> > Add a new option to the post-install "goals" phase to configure tlshd
> > for TLS handshake upcalls. This adds a new playbook to build a CA,
> > generate certs for the hosts, and then configure tlshd to use them.
> >
> > Finally, it also adds a new NFS fstests option to test RPC over TLS
> > (using xprtsec=mtls).
> >
> > Signed-off-by: Jeff Layton <jlayton@kernel.org>
> > ---
> > Makefile | 4 +
> > kconfigs/Kconfig.bringup.goals | 9 ++
> > playbooks/ktls.yml | 4 +
> > playbooks/roles/fstests/templates/nfs/nfs.config | 7 ++
> > .../roles/ktls/tasks/install-deps/debian/main.yml | 10 ++
> > playbooks/roles/ktls/tasks/install-deps/main.yml | 9 ++
> > .../roles/ktls/tasks/install-deps/redhat/main.yml | 15 +++
> > .../roles/ktls/tasks/install-deps/suse/main.yml | 9 ++
> > playbooks/roles/ktls/tasks/main.yml | 110 +++++++++++++++++++++
> > playbooks/roles/ktls/templates/tlshd.conf | 39 ++++++++
> > scripts/bringup.Makefile | 5 +
> > scripts/ktls.Makefile | 8 ++
> > workflows/fstests/nfs/Kconfig | 9 +-
> > workflows/fstests/nfs/Makefile | 3 +
> > 14 files changed, 240 insertions(+), 1 deletion(-)
> >
> > diff --git a/Makefile b/Makefile
> > index 895a0a67c705..0f6fa024f14c 100644
> > --- a/Makefile
> > +++ b/Makefile
> > @@ -114,6 +114,10 @@ ifeq (y,$(CONFIG_WORKFLOWS))
> > include workflows/Makefile
> > endif # CONFIG_WORKFLOWS
> >
> > +ifeq (y,$(CONFIG_KDEVOPS_SETUP_KTLS))
> > +include scripts/ktls.Makefile
> > +endif # CONFIG_KDEVOPS_SETUP_KTLS
> > +
> > ifeq (y,$(CONFIG_KDEVOPS_SETUP_NFSD))
> > include scripts/nfsd.Makefile
> > endif # CONFIG_KDEVOPS_SETUP_NFSD
> > diff --git a/kconfigs/Kconfig.bringup.goals b/kconfigs/Kconfig.bringup.goals
> > index 5df74d4bcb08..a2af3ffba499 100644
> > --- a/kconfigs/Kconfig.bringup.goals
> > +++ b/kconfigs/Kconfig.bringup.goals
> > @@ -56,6 +56,15 @@ config KDEVOPS_TRY_INSTALL_KDEV_TOOLS
> > most kernel developers might prefer to have installed on target
> > systems.
> >
> > +config KDEVOPS_SETUP_KTLS
> > + bool "Configure ktls on the hosts with self-signed CA"
> > + default n
> > + help
> > + Enabling this will have kdevops create a self-signed certificate
> > + authority, and configure tlshd on the hosts to use it. This is
> > + necessary for testing RPC over TLS, or some NVMe over fabrics
> > + configurations.
> > +
> > config KDEVOPS_SETUP_NFSD
> > bool "Set up the kernel nfs server"
> > default n
> > diff --git a/playbooks/ktls.yml b/playbooks/ktls.yml
> > new file mode 100644
> > index 000000000000..8b7044c7ef2d
> > --- /dev/null
> > +++ b/playbooks/ktls.yml
> > @@ -0,0 +1,4 @@
> > +---
> > +- hosts: all
> > + roles:
> > + - role: ktls
> > diff --git a/playbooks/roles/fstests/templates/nfs/nfs.config b/playbooks/roles/fstests/templates/nfs/nfs.config
> > index 60915f824764..e2265f3f3ee2 100644
> > --- a/playbooks/roles/fstests/templates/nfs/nfs.config
> > +++ b/playbooks/roles/fstests/templates/nfs/nfs.config
> > @@ -15,6 +15,13 @@ CANON_DEVS=yes
> > # Test with default mount options
> > [nfs_default]
> > {% endif %}
> > +{% if fstests_nfs_section_tls -%}
> > +
> > +# Test NFS with RPC over TLS
> > +[nfs_tls]
> > +TEST_FS_MOUNT_OPTS="-o xprtsec=mtls"
> > +MOUNT_OPTIONS="-o xprtsec=mtls"
> > +{% endif %}
> > {% if fstests_nfs_section_v40 -%}
> >
> > # Test NFSv4.0
> > diff --git a/playbooks/roles/ktls/tasks/install-deps/debian/main.yml b/playbooks/roles/ktls/tasks/install-deps/debian/main.yml
> > new file mode 100644
> > index 000000000000..704c394e0c49
> > --- /dev/null
> > +++ b/playbooks/roles/ktls/tasks/install-deps/debian/main.yml
> > @@ -0,0 +1,10 @@
> > +---
> > +- name: Install ktls dependencies
> > + become: yes
> > + become_method: sudo
> > + apt:
> > + name:
> > + - python3-cryptography
> > + - ktls-utils
> > + state: present
> > + update_cache: yes
> > diff --git a/playbooks/roles/ktls/tasks/install-deps/main.yml b/playbooks/roles/ktls/tasks/install-deps/main.yml
> > new file mode 100644
> > index 000000000000..ab343e8b05c6
> > --- /dev/null
> > +++ b/playbooks/roles/ktls/tasks/install-deps/main.yml
> > @@ -0,0 +1,9 @@
> > +---
> > +# tasks to install dependencies for pynfs
> > +- name: oscheck distribution ospecific setup
> > + import_tasks: tasks/install-deps/debian/main.yml
>
> Since this is a new set of install-deps, how about using
> include_tasks: instead?
>
>
Thanks! That seems to work just as well. I've incorporated that change
in tree for now.
> > + when: ansible_facts['os_family']|lower == 'debian'
> > +- import_tasks: tasks/install-deps/suse/main.yml
> > + when: ansible_facts['os_family']|lower == 'suse'
> > +- import_tasks: tasks/install-deps/redhat/main.yml
> > + when: ansible_facts['os_family']|lower == 'redhat'
> > diff --git a/playbooks/roles/ktls/tasks/install-deps/redhat/main.yml b/playbooks/roles/ktls/tasks/install-deps/redhat/main.yml
> > new file mode 100644
> > index 000000000000..0e1ab7505b3e
> > --- /dev/null
> > +++ b/playbooks/roles/ktls/tasks/install-deps/redhat/main.yml
> > @@ -0,0 +1,15 @@
> > +---
> > +- name: Install ktls dependencies
> > + become: yes
> > + become_method: sudo
> > + dnf:
> > + update_cache: yes
> > + name: "{{ packages }}"
> > + retries: 3
> > + delay: 5
> > + register: result
> > + until: result.rc == 0
> > + vars:
> > + packages:
> > + - python3-cryptography
> > + - ktls-utils
> > diff --git a/playbooks/roles/ktls/tasks/install-deps/suse/main.yml b/playbooks/roles/ktls/tasks/install-deps/suse/main.yml
> > new file mode 100644
> > index 000000000000..ce5935154038
> > --- /dev/null
> > +++ b/playbooks/roles/ktls/tasks/install-deps/suse/main.yml
> > @@ -0,0 +1,9 @@
> > +---
> > +- name: Install ktls dependencies
> > + become: yes
> > + become_method: sudo
> > + zypper:
> > + state: present
> > + name:
> > + - python3-cryptography
> > + - ktls-utils
> > diff --git a/playbooks/roles/ktls/tasks/main.yml b/playbooks/roles/ktls/tasks/main.yml
> > new file mode 100644
> > index 000000000000..1aa545835502
> > --- /dev/null
> > +++ b/playbooks/roles/ktls/tasks/main.yml
> > @@ -0,0 +1,110 @@
> > +- name: Import optional extra_args file
> > + include_vars: "{{ item }}"
> > + ignore_errors: yes
> > + with_first_found:
> > + - files:
> > + - "../extra_vars.yml"
> > + - "../extra_vars.yaml"
> > + - "../extra_vars.json"
> > + skip: true
> > +
> > +- name: Install dependencies
> > + import_tasks: install-deps/main.yml
> > +
> > +- name: Construct the path to the CA directory
> > + delegate_to: localhost
> > + set_fact:
> > + ca_dir: "{{ topdir_path }}/ca/{{ kdevops_host_prefix }}"
> > +
> > +- name: Create directory to hold the CA on local host
> > + delegate_to: localhost
> > + run_once: true
> > + ansible.builtin.file:
> > + path: "{{ ca_dir }}"
> > + state: directory
> > +
> > +- name: Create private key for CA
> > + delegate_to: localhost
> > + run_once: true
> > + community.crypto.openssl_privatekey:
> > + path: "{{ ca_dir }}/ca-cert.key"
> > +
> > +- name: Create certificate signing request (CSR) for CA certificate
> > + delegate_to: localhost
> > + run_once: true
> > + community.crypto.openssl_csr_pipe:
> > + privatekey_path: "{{ ca_dir }}/ca-cert.key"
> > + common_name: "kdevops {{ kdevops_host_prefix }} CA"
> > + use_common_name_for_san: false # since we do not specify SANs, don't use CN as a SAN
> > + basic_constraints:
> > + - 'CA:TRUE'
> > + basic_constraints_critical: true
> > + key_usage:
> > + - keyCertSign
> > + key_usage_critical: true
> > + register: ca_csr
> > +
> > +- name: Create self-signed CA certificate from CSR
> > + delegate_to: localhost
> > + run_once: true
> > + community.crypto.x509_certificate:
> > + path: "{{ ca_dir }}/ca-cert.pem"
> > + csr_content: "{{ ca_csr.csr }}"
> > + privatekey_path: "{{ ca_dir }}/ca-cert.key"
> > + provider: selfsigned
> > +
> > +- name: Create private key for new TLS certificate
> > + community.crypto.openssl_privatekey:
> > + path: "/etc/pki/tls/private/ktls.key"
> > + become: yes
> > +
> > +- name: Copy CA cert to all of the hosts
> > + ansible.builtin.copy:
> > + src: "{{ ca_dir }}/ca-cert.pem"
> > + dest: "/etc/pki/tls/certs/ca-cert.pem"
> > + owner: root
> > + group: root
> > + mode: 0644
> > + become: yes
> > +
> > +- name: Create certificate signing request (CSR) for new certificate
> > + community.crypto.openssl_csr_pipe:
> > + privatekey_path: "/etc/pki/tls/private/ktls.key"
> > + subject_alt_name:
> > + - "DNS:{{ ansible_host }}"
> > + - "IP:{{ ansible_default_ipv4.address }}"
> > + register: csr
> > + become: yes
> > +
> > +- name: Sign certificate with our CA
> > + community.crypto.x509_certificate_pipe:
> > + csr_content: "{{ csr.csr }}"
> > + provider: ownca
> > + ownca_path: "{{ ca_dir }}/ca-cert.pem"
> > + ownca_privatekey_path: "{{ ca_dir }}/ca-cert.key"
> > + ownca_not_after: +365d # valid for one year
> > + ownca_not_before: "-1d" # valid since yesterday
> > + delegate_to: localhost
> > + register: certificate
> > +
> > +- name: Write certificate file on host
> > + copy:
> > + dest: "/etc/pki/tls/certs/ktls.pem"
> > + content: "{{ certificate.certificate }}"
> > + become: yes
> > +
> > +- name: Install new /etc/tlshd.conf
> > + ansible.builtin.copy:
> > + src: "{{ playbook_dir }}/roles/ktls/templates/tlshd.conf"
> > + dest: "/etc/tlshd.conf"
> > + owner: root
> > + group: root
> > + mode: 0644
> > + become: yes
> > +
> > +- name: Enable and start tlshd
> > + become: yes
> > + ansible.builtin.systemd_service:
> > + name: tlshd.service
> > + enabled: true
> > + state: reloaded
> > diff --git a/playbooks/roles/ktls/templates/tlshd.conf b/playbooks/roles/ktls/templates/tlshd.conf
> > new file mode 100644
> > index 000000000000..63ee5b59a8bd
> > --- /dev/null
> > +++ b/playbooks/roles/ktls/templates/tlshd.conf
> > @@ -0,0 +1,39 @@
> > +#
> > +# Copyright (c) 2022 Oracle and/or its affiliates.
> > +#
> > +# This file is part of ktls-utils.
> > +#
> > +# ktls-utils is free software; you can redistribute it and/or
> > +# modify it under the terms of the GNU General Public License as
> > +# published by the Free Software Foundation; version 2.
> > +#
> > +# This program is distributed in the hope that it will be useful,
> > +# but WITHOUT ANY WARRANTY; without even the implied warranty of
> > +# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
> > +# General Public License for more details.
> > +#
> > +# You should have received a copy of the GNU General Public License
> > +# along with this program; if not, write to the Free Software
> > +# Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
> > +# 02110-1301, USA.
> > +#
> > +# See tlshd.conf(5) for details.
> > +#
> > +
> > +[debug]
> > +loglevel=0
> > +tls=0
> > +nl=0
> > +
> > +[authenticate]
> > +#keyrings= <keyring>;<keyring>;<keyring>
> > +
> > +[authenticate.client]
> > +x509.truststore=/etc/pki/tls/certs/ca-cert.pem
> > +x509.certificate=/etc/pki/tls/certs/ktls.pem
> > +x509.private_key=/etc/pki/tls/private/ktls.key
> > +
> > +[authenticate.server]
> > +x509.truststore=/etc/pki/tls/certs/ca-cert.pem
> > +x509.certificate=/etc/pki/tls/certs/ktls.pem
> > +x509.private_key=/etc/pki/tls/private/ktls.key
> > diff --git a/scripts/bringup.Makefile b/scripts/bringup.Makefile
> > index 0051bc3d5e0d..520e2993a7b1 100644
> > --- a/scripts/bringup.Makefile
> > +++ b/scripts/bringup.Makefile
> > @@ -21,6 +21,11 @@ ifeq (y,$(CONFIG_KDEVOPS_SETUP_NFSD))
> > KDEVOPS_BRING_UP_DEPS += nfsd
> > endif # KDEVOPS_SETUP_NFSD
> >
> > +ifeq (y,$(CONFIG_KDEVOPS_SETUP_KTLS))
> > +KDEVOPS_BRING_UP_DEPS += ktls
> > +KDEVOPS_DESTROY_DEPS += ktls-destroy
> > +endif # KDEVOPS_SETUP_KTLS
> > +
> > update_etc_hosts:
> > $(Q)ansible-playbook $(ANSIBLE_VERBOSE) \
> > -f 30 -i hosts playbooks/update_etc_hosts.yml
> > diff --git a/scripts/ktls.Makefile b/scripts/ktls.Makefile
> > new file mode 100644
> > index 000000000000..977538041ae8
> > --- /dev/null
> > +++ b/scripts/ktls.Makefile
> > @@ -0,0 +1,8 @@
> > +ktls:
> > + $(Q)ansible-playbook $(ANSIBLE_VERBOSE) --extra-vars=@./extra_vars.yaml \
> > + -f 30 -i hosts playbooks/ktls.yml
> > +
> > +ktls-destroy:
> > + $(Q)rm -rf $(TOPDIR)/ca
> > +
> > +PHONY += ktls ktls-destroy
> > diff --git a/workflows/fstests/nfs/Kconfig b/workflows/fstests/nfs/Kconfig
> > index 7e202778d286..7e8731dc4dc1 100644
> > --- a/workflows/fstests/nfs/Kconfig
> > +++ b/workflows/fstests/nfs/Kconfig
> > @@ -54,11 +54,18 @@ config FSTESTS_NFS_SECTION_DEFAULT
> > time of this writing, this makes the client autonegotiate an NFS
> > version, starting with v4.2 if it's available.
> >
> > +config FSTESTS_NFS_SECTION_TLS
> > + bool "Enable testing section: nfs_tls"
> > + default n
> > + depends on KDEVOPS_SETUP_KTLS
> > + help
> > + Enabling this will test with the xprtsec=tls mount option.
> > +
> > config FSTESTS_NFS_SECTION_V40
> > bool "Enable testing section: nfs_v40"
> > default n
> > help
> > - Enabling this will test NFSv4.0
> > + Enabling this will test NFSv4.0.
> >
> > config FSTESTS_NFS_SECTION_V3
> > bool "Enable testing section: nfs_v3"
> > diff --git a/workflows/fstests/nfs/Makefile b/workflows/fstests/nfs/Makefile
> > index 7a057532be67..0e5245920ee9 100644
> > --- a/workflows/fstests/nfs/Makefile
> > +++ b/workflows/fstests/nfs/Makefile
> > @@ -9,6 +9,9 @@ FSTESTS_ARGS += fstests_nfs_server_host='$(FSTESTS_NFS_SERVER_HOST)'
> > ifeq (y,$(CONFIG_FSTESTS_NFS_SECTION_DEFAULT))
> > FSTESTS_ARGS += fstests_nfs_section_default=True
> > endif
> > +ifeq (y,$(CONFIG_FSTESTS_NFS_SECTION_TLS))
> > +FSTESTS_ARGS += fstests_nfs_section_tls=True
> > +endif
> > ifeq (y,$(CONFIG_FSTESTS_NFS_SECTION_V40))
> > FSTESTS_ARGS += fstests_nfs_section_v40=True
> > endif
> >
> > ---
> > base-commit: 2f7d9b13a7ac734e2fb40ed68e45150af9d727ef
> > change-id: 20231212-ktls-5534fde5777c
> >
> > Best regards,
> > --
> > Jeff Layton <jlayton@kernel.org>
> >
>
--
Jeff Layton <jlayton@kernel.org>
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH kdevops] ktls: allow setting up hosts with tlshd
2023-12-12 19:35 [PATCH kdevops] ktls: allow setting up hosts with tlshd Jeff Layton
2023-12-12 19:43 ` Chuck Lever
@ 2023-12-13 6:11 ` Luis Chamberlain
1 sibling, 0 replies; 4+ messages in thread
From: Luis Chamberlain @ 2023-12-13 6:11 UTC (permalink / raw)
To: Jeff Layton; +Cc: Chuck Lever, kdevops
On Tue, Dec 12, 2023 at 02:35:38PM -0500, Jeff Layton wrote:
> Add a new option to the post-install "goals" phase to configure tlshd
> for TLS handshake upcalls. This adds a new playbook to build a CA,
> generate certs for the hosts, and then configure tlshd to use them.
>
> Finally, it also adds a new NFS fstests option to test RPC over TLS
> (using xprtsec=mtls).
>
> Signed-off-by: Jeff Layton <jlayton@kernel.org>
Reviewed-by: Luis Chamberlain <mcgrof@kernel.org>
All looks good to me.
Luis
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2023-12-13 6:11 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2023-12-12 19:35 [PATCH kdevops] ktls: allow setting up hosts with tlshd Jeff Layton
2023-12-12 19:43 ` Chuck Lever
2023-12-12 20:12 ` Jeff Layton
2023-12-13 6:11 ` Luis Chamberlain
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.