From: James Muir <muir.james.a@gmail.com>
To: Joe Lauer <joe@greenback.com>, ecryptfs@vger.kernel.org
Subject: Re: Max 26 concurrent ecryptfs mounts?
Date: Sun, 10 Apr 2016 07:59:32 -0400 [thread overview]
Message-ID: <570A4024.9090005@gmail.com> (raw)
In-Reply-To: <CAOgMywMKtc6Bzr88z97GHSeTTmj-rOZk7kCzDQgCoR2xZLCWuw@mail.gmail.com>
On 16-03-21 05:20 PM, Joe Lauer wrote:
> 2) Are there any workarounds? Any magic kernel settings I can tune to
> allow for more? Or can we actually mount a directory under a
> different account than root so that a new keyring is used as opposed
> for root.
You can increase the quota by writing to certain proc files. It is
documented in the kernel source: Documentation/security/keys.txt
quoting:
> Four new sysctl files have been added also for the purpose of controlling the
> quota limits on keys:
>
> (*) /proc/sys/kernel/keys/root_maxkeys
> /proc/sys/kernel/keys/root_maxbytes
>
> These files hold the maximum number of keys that root may have and the
> maximum total number of bytes of data that root may have stored in those
> keys.
>
> (*) /proc/sys/kernel/keys/maxkeys
> /proc/sys/kernel/keys/maxbytes
>
> These files hold the maximum number of keys that each non-root user may
> have and the maximum total number of bytes of data that each of those
> users may have stored in their keys.
>
> Root may alter these by writing each new limit as a decimal number string to
> the appropriate file.
-James M
prev parent reply other threads:[~2016-04-10 11:59 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2016-03-21 21:20 Max 26 concurrent ecryptfs mounts? Joe Lauer
2016-04-10 11:59 ` James Muir [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=570A4024.9090005@gmail.com \
--to=muir.james.a@gmail.com \
--cc=ecryptfs@vger.kernel.org \
--cc=joe@greenback.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.